The authors wish to acknowledge the Public Key Infrastructure Group at Microsoft, members of the Public Key Infrastructure (PKIX) Working Group within the IETF, and panel members (Joan Feigenbaum, Paul Kocher, Michael Myers, and Ron Rivest) at Financial Cryptography '98 for their valuable contributions to this paper.