Max,I could imagine a brief document that suggests that a client who wishes to obscure the ID of the cert of interest can make requests for multiple certs,
or that the client just use CRLs. I do worry that a client might not knowvalid serial numbers for other certs from the CA in question and, as a result, might have a hard time producing queries that were consistent i this regard.
In any case, I am not enthusiastic about any changes to the base protocol,as opposed to guidance on how to use the protocol in a more privacy-preserving fashion.
Steve
Note Well: Messages sent to this mailing list are the opinions of the senders and do not imply endorsement by the IETF.