tells you how to use StartSSL, which generates the key in your browser.
Whoops, your private key is now known to another server on this internet
Pardon my ignorance, but I thought the in-browser certificate creation process avoids sending the private key.https://developer.mozilla.org/en-US/docs/Web/HTML/Element/ke...
http://www.jroller.com/whoami/entry/browser_generated_certif... (2006)