Forum Discussion

Dennis-Scherrer's avatar
Dennis-Scherrer
Brass Contributor
Oct 16, 2020

Key Generation in Edge Browser <keygen>

For code signing, or document signing, or e-mail signing or login on small selection of restricted website a personal certificate is needed. 

When an individual wants to buy such a personal certificate, comes it to the question how the personal key will be generated. For sure: generating the key on the client side does not mean that it is much more secure as to generate it on the pki side. There're pros and cons.

But, when Microsoft follows Googles approach (turned off key generation in Chrome) I don't have the choice - in the Microsoft on-for-all devices Browser. I need to switch to Firefox and come back to Edge - well mid be not a failure in preserve my private key. 

I image that there´re good reasons for Googles decision, but the audience for Edge is different. So I welcome a discussion about this feature.

If you don´t what I exactly mean, here´s an example at step 5 https://support.globalsign.com/digital-certificates/digital-certificates-life-cycle/how-order-new-client-certificate or here https://support.comodo.com/index.php?/Knowledgebase/Article/View/244/0/which-browser-can-i-use-to-signup-for-a-code-signing-certificate or this "Browser-based Installation" is nice documented https://support.globalsign.com/personal-sign-email/browser-installation-client-certificates 

Looking forward to your comments,

Dennis

    • Dennis-Scherrer's avatar
      Dennis-Scherrer
      Brass Contributor

      Great research, thank you HotCakeX 

      That does not change the requirement for a - let me call it - client side key generation.

      It is not a solution for indivuduals.

      • HotCakeX's avatar
        HotCakeX
        MVP
        True but those companies knowing that, they should use alternative technologies and there are better alternative technologies. asking individuals not to use Chromium based features (that are the most popular ones) for something like that is absurd.
        instead of forcing people to use only a specific browser (which also is thinking about getting rid of that feature), they better think about using other ways to provide their service.

Resources