@rdh I'm friends with the main person behind SSL/TLS (Christopher Allen) who was opposed to CAs. There's an alternate system that was in the work called SPKI/SDSI (pronounced "spooky/sudsy"). There are alternate solutions, but they aren't well known because they aren't the ones that took off.