Would it be so crazy to have a standard javascript API that websites could use to store or remove certificates from the browser? With user validation of course.
I indeed don't understand why it's not done yet, everything would be so much easier !
Oh, yes, let's add more attack surface to what we already have. Because JavaScript interfaces are known for being well-thought and highly secure.
Doesn't this already exist? For instance, when I create an account on startssl.com, it seems to create a client certificate for me...
There are browser-side APIs to generate key pairs, but there is no real standard as the KEYGEN tag is not widely supported, so on the server side you need to implement virtually one method per browser type you are addressing. And then you want to store your private keys somewhere safe, which is implemented differently by OS/browser. Some browsers use the system keystore for storage, others like Firefox have their own implementation (NSS). We are not lacking implementations here, merely browser standards.
To answer your question: I do not think startssl supports local key generation for all OS/browser combinations, they probably (painfully) hardcoded the most common ones.
It's interesting too that KEYGEN is now listed in the WHATWG spec as deprecated. Apparently what little interest there was in trying to standardize this has already somewhat fizzled out.
FWIW, keygen's deprecation isn't a rejection of client-side encryption: it's a rejection of the design of the keygen feature to address those requirements.
I was curious about that, and that seems a fair reason, but it doesn't show much interest in client-side encryption if it has been rejected without favoring some new proposal.