Re: PKIX Profile for IKE - CA Certificates & IKE Identification Certificates

I propose that we
explicitly define the various types of CA, their roles w/r/t IKE,
and certification hierarchies.
My feeling is that this kind of detail should *not* be in the spec. It duplicates definitions from PKIX and the PKIX Roadmap, and introduces synonyms for terms already there. I think the IKE PKI profile should only discuss what's different, not repeat.

