Given the fact that this document is a 'best practices' sort of thing rather than actually defining some sort of protocol, I find the venue of an RFC (even TFS incorrectly marks this sort of thing as a 'standard) questionable.If they were looking for a techncial solution to actually enforce some of what is prescribed, basically it is describing the precise sorts of things x509 has baked in.