>  I am sure this has been discussed before but here goes. Why are there
> not gpg certificate authorities that will verify someones identity? If
> there are places like thawte why not the same thing for openpgp?

Thawte once did signing of PGP keys (although I've been successful only in
signing my RSA key with them, not the D-H).=20

The problem is more social than technical - to have working CAs, they must
be CAs that most people in the web of trust trust. This leads to two
problems: how to gain the trust, and, more technical - how many people who
use PGP you know actually manage the trust database?

