Further, I want to emphasize that TAM should be able to pass bare public keys and not require them to be PKIX-wrapped certs. There are lots of use cases where keys are more appropriate than a cert, and the semantics will be much clearer.
--Paul Hoffman, Director --VPN Consortium