You can. It's called Javascript and there are libraries to do public key encryption.
But yes, here you are right, the cert is generated by the server in this case.
But yes, here you are right, the cert is generated by the server in this case.
it's exactly equivalent from a security perspective, unless you read every line of Javascript, in which case you might as well read the openssl manual instead and generate the CSR yourself.
(note that there's a rarely used <input> keygen type, but to sign the CSR you'd need programmatic access to the private key, again defeating any security properties).