From CSR to Attested Certificate: How TPM-Gated Issuance Actually Works
Standard PKI signs a CSR when someone with credentials asks nicely. TPM-attested issuance signs a CSR when a specific TPM proves it deserves the certificate. This is the full end-to-end architecture — nonce to CA to audit row.