> And is it safe to say that the validation criteria are those
> identified by
> the UseKeyWith (rePolicy)? (Presuming my confusion in this
> outstanding
> email is corrected [1].)
>
> [1] http://lists.w3.org/Archives/Public/www-xkms/2002Dec/0084.html
They are the validation criteria identified by the services own
interpretation of UseKeyWith.
So if the client thinks that DNA blood samples are necessary to do
S/MIME
then it requires them. If on the other hand it does not think that a
valid cert signature is required then the client may well have problems.
We are not specifying the policy. However the actions of the service are
likely to be constrained by a contractual relationship that causes the
service to interpret policy in a manner that is consistent with
intersubjectively established industry norms.
Phill