Earlier quoted context omitted.
In addition, it might be a good idea to think about a system that can update/rotate your keys across all of your servers on the fly in case the third-party service you're using to manage the keys to the kingdom is compromised or assumed to be compromised.
Sorry to hijack this, but this is absurd. I really must have missed the story here -- people pay for a third party service to manage their private keys? ... Err. That's so illogical it's making my brain hurt to even work out why I would need to explain how illogical it is... I can't even come up with a good analogy for how wrong that whole idea is, fortunately I don't have to though since no one that has mastered 'ss…
Not to me, I felt exactly the same way.
I simply cannot fucking believe that somebody would "outsource" something as sensitive as this. Then again, I don't run my services on other people's computers either. My servers are either in our cages in datacenters or in buildings that we own, they're locked down as much as I can get them (DISA STIGs, etc.), we encrypt the hell outta data, we have strict security policies, etc.
I really can't imagine doing something this crazy but clearly I'm in the minority.