3 ms·
Actually creating client side certificates is quite easy if you use the <keygen> tag. See http://www.w3.org/2005/Incubator/webid/spec/tls/#certificate-creation
by bblfish 11y ago
Actually creating client side certificates is quite easy if you use the <keygen> tag. See http://www.w3.org/2005/Incubator/webid/spec/tls/#certificate-creation http://www.w3.org/2005/Incubator/webid/spec/tls/#certificate...
Sadly some browser vendors have been threatening to remove that functionality rather than trying to improve it. But see the work by the Technical Architecture Group There is also this document now produced by the TAG.
https://github.com/w3ctag/client-certificates https://github.com/w3ctag/client-certificates
- martindale 11y agoI have been trying to find a way to use the `<keygen>` tag in production for a very long time, but I am consistently thwarted by the browsers simply not supporting it well enough. Where does the generated private key go? How do I sign things with it again? It's never clear, and browser support is terribly inconsistent.