smtp servers shouldn't have been doing this anyway...
the pki separation is good.
the pki separation is good.
For a client cert issued by web pki, all you know is that they've somehow obtained a cert for some name, you don't know if it's legit or not, since it doesn't come from connecting to the name. So kind of useless for trust.