avoid needing coordination between all relying parties (RPs). But it doesn't cover coordination by the subscribers (e.g. TLS servers) yet, which is what the next point was about: I think this is beyond the scope of the document. I do not see how it introduces new problems. It enables some automation of trust store updates, that is all.