Entrust White Paper Sample
Creating cryptographic keys is a simple matter; many common software applications and operating systems have the ability to do this. Obtaining a certificate for a key from an internal commercial or open-source software certification authority (CA) is also a simple matter.
Even obtaining a certificate from a “publicly trusted” certification authority may be easier than you might expect, as some publicly trusted SSL CAs operate lax controls over the authorization of certificate requests.