What we (initially) wanted to do
Use PKC as stronger auth for some web apps
This means X.509 and its huge infrastructure
at least in theory scalable for Musers
Popularize client certs by
Making them easy, hassle-free to get
Providing them for free, but with decent identity guarantees
PGP has had the solution for years: the web of trust
How can we merge the PGP WoT and the X.509
hierachy?