ParentFull threadjackalope·There is no reason for the CA to ever see the private key. All they need is a CSR. This approach is fundamentally broken.View on HN