5 ms·
Would it be so crazy to have a standard javascript API that websites could use to store or remove certificates from the browser? With user validation of course.
by odc 11y ago
Would it be so crazy to have a standard javascript API that websites could use to store or remove certificates from the browser? With user validation of course.
- realusername 11y agoI indeed don't understand why it's not done yet, everything would be so much easier !
- dozzie 11y agoOh, yes, let's add more attack surface to what we already have. Because JavaScript interfaces are known for being well-thought and highly secure.
- yrro 11y agoDoesn't this already exist? For instance, when I create an account on startssl.com, it seems to create a client certificate for me...
- nicolas314 11y agoThere are browser-side APIs to generate key pairs, but there is no real standard as the KEYGEN tag is not widely supported, so on the server side you need to implement virtually one method per browser type you are addressing. And then you want to store your private keys somewhere safe, which is implemented differently by OS/browser. Some browsers use the system keystore for storage, others like Firefox have their own implementation (NSS). We are not lacking implementations here, merely browser standards. To answer your question: I do not think startssl supports local key generation for all OS/browser combinations, they probably (painfully) hardcoded the most common ones.
- WorldMaker 11y agoIt's interesting too that KEYGEN is now listed in the WHATWG spec as deprecated. Apparently what little interest there was in trying to standardize this has already somewhat fizzled out.
- gsnedders 11y agoFWIW, keygen's deprecation isn't a rejection of client-side encryption: it's a rejection of the design of the keygen feature to address those requirements.
- WorldMaker 11y agoI was curious about that, and that seems a fair reason, but it doesn't show much interest in client-side encryption if it has been rejected without favoring some new proposal.
- yrro 11y agoThanks for the info!