> The whole purpose of private keys is that they're private.
> Personally, if someone issues me a private key, I'll burn it right
> there and then.

Really? So when you work in an organisation, and they issue you with a smartcard or similar certificate for authentication, you "burn it right there and then"?

> The only private key I trust is one I generate myself.

But oddly enough, organisation (or partner org or whatever doesn't trust you)

> WHOA there's a big problem....

No, not really.

I think you need to reread what the purpose of this PKI is for.


