http://www.whatwg.org/specs/web-apps/current-work/#the-keygen-element Since the PKI community at large seems to ignore the client-side of PKI in browsers, the HTML 5 designers apparently didn't find any other solution but adopting the 15 year old Netscape hack known as <keygen>. Anders