WIP: How did PKI become a joke?

tl;dr

If your system asks you to both upload a certificate and a private key, or it generates a CSR (certificate signing request) and also gives you the private key, you’re doing PKI wrong…

Also don’t laugh - but this commentary is directly opposed to goals of US national security, but I’ve lived through that being used inappropriately. - signed, Mark

Terms

The Beef…

Any system that requires you to both upload the private key material, as well as the certificate is doing PKI wrong. This is because in a PKI system, the private key material is truly private to the system that will use it. If you generate this material on your laptop then upload it, well, your laptop and any virus or MDM also saw that key. Moreover, most truly secure systems such as the TPM or an HSM do not export this material. This means that if you upload this key, it’s not likely to be hardware backed.

The Culprits

The Heros

The Anti-Heros

Recommendations

Internal Use Only Certificates

The scheme to extend a certificate is pretty common. All that needs be done is an issuance of a new OID (Object Identifier) and my proposal is for two new OIDs

Key Generation Indicators