> A different approach is to have Bob's service provider, as specified
> in his username, be his keyserver [...]
> Of course, now Alice needs to authenticate example.com.  A DNS
> solution (DNSSEC or DNSCurve) seems elegant

Apologies if this has already been mentioned, but here's a draft of how to
use DANE in conjunction with S/MIME that looks similar to what you're


