SSL certificate stuff (ie. PKI) is IMO dead. NSA killed it. Back to the roots: hashed pw over MITM-safe sessions (SRP, SPEKE etc, ie. PAKE). cu Uenal