#ThibGNo, right. By reading the spec, though, I got the idea that a server could conceivably be very “dumb” and defer stuff to the client. And in particular the client could hold the signing keys, in which case the client could just refuse to sign a “suspended” attribute.