> But I have to say, the core problem this proposal faces would seem to be lack of demand on the part of folks who consume client certificates.
Agreed. In our experience, client certs are deployed from an enterprise PKI, and the receiving consumers assume valid issuance. I'm not aware of any of our customers (the few that use client certs) who also use a public CA, or even more than one. Added the trans list. _______________________________________________ TLS mailing list TLS@ietf.org https://www.ietf.org/mailman/listinfo/tls