Is there no way to not let developers access private keys for certificates?

Question asked by adam.bonney127913 on Feb 12, 2018

As private keys are functionally credentials, it seems moderately ridiculous that developers have access to any certificate installed on the platform for use in processes? That's the same as giving them production passwords?