This looks like a very smart solution to the self-signed certificate problem for web browsers. It is a much better compromise than the mess Mozilla has made in Firefox 3 and leads to fewer false alerts. As a consequence it is much less likely to desensitise users so that real security issues get ignored. I hope something like this becomes the default in Firefox.