6 ms·
There is no reason for the CA to ever see the private key. All they need is a CSR. This approach is fundamentally broken.
by jackalope 12y ago
There is no reason for the CA to ever see the private key. All they need is a CSR. This approach is fundamentally broken.