#webpki
PSA: if you're shipping a CLI tool in Rust, please give an option to use the system certificate store. Most Rust libraries for network stuff will just use the Mozilla webpki list by default.
February 8, 2025 at 12:01 AM
19% of all WebPKI certificates issued yesterday included an SCT from the Geomys Tuscolo Certificate Transparency log 🤯
CT Log Usage Dashboard
Measured by counting embedded SCTs in trusted leaf certificates, using Censys data.
sctdata.geomys.org
September 9, 2026 at 8:54 PM
If you're not a browser, you have two options:

1. run your own PKI, convincing e.g. non-profit CAs to maintain roots for you
2. keep up with the WebPKI, e.g. by accepting serverAuth now

The freakout actually proves some ecosystems are not ready for (2) so should not be piggy-backing on the WebPKI.
June 17, 2025 at 1:57 PM
Fiddling with x509-limbo this morning for rustls-webpki (github.com/C2SP/x509-li...).

Between Wycheproof, BoGo, BetterTLS and x509-limbo there's no shortage of excellent cryptography/TLS test frameworks these days.
Add CRL verification support to rustls-webpki, fixup CRL test case by cpu · Pull Request #441 · C2SP/x509-limbo
👋 Hi folks, One of the features that distinguishes the Rusts fork of webpki from its predecessor is support for revocation checking with CRLs. This branch updates the x509-limbo harness to take adv...
github.com
May 24, 2025 at 4:43 PM
Latest #rustlang reqwest v0.12.9 out now! 🦀

- Certificate revocation lists
- webpki roots without a rustls provider
- No more caching of system proxy settings
- and more 🚀

github.com/seanmonstar/...
Release v0.12.9 · seanmonstar/reqwest
What's Changed Add tls::CertificateRevocationLists support (by @ksenia-vazhdaeva in #2433) Add crate features to enable webpki roots without selecting a rustls provider (by @stevefan1999-personal ...
github.com
October 28, 2024 at 5:21 PM
Cloudflare is launching an experiment with Chrome to evaluate fast, scalable, and quantum-ready Merkle Tree Certificates, all without degrading performance or changing WebPKI trust relationships. https://cfl.re/43HH6EG
Keeping the Internet fast and secure- introducing Merkle Tree Certificates
Cloudflare is launching an experiment with Chrome to evaluate fast, scalable, and quantum-ready Merkle Tree Certificates, all without degrading performance or changing WebPKI trust relationships.
cfl.re
October 28, 2025 at 3:00 PM
imagine if everyone only did webpki for the rest of time. horrifying
May 19, 2023 at 6:32 PM
oh cool, the webpki CAs were whining about how few EV certs they sell nowadays, this is gonna make up for that dip and then some
September 26, 2026 at 2:42 AM
Government-run CAs in the WebPKI ecosystem often represent a conflict between trust and security. My latest post explores this, diving into examples of predictable failures and systemic issues that persist. What does this mean for the future of certificate trust? unmitigatedrisk.com?p=911
Government CAs and the WebPKI: Trust is Often the Opposite of Security | UNMITIGATED RISK
unmitigatedrisk.com
December 2, 2024 at 3:35 AM
Ryan Hurst published an AMAZINGLY clear deep-dive into the "WebPKI" (certificates and more)

rmhrisk.github.io/classical-we...
A Deep Dive on the Classical WebPKI
rmhrisk.github.io
August 5, 2026 at 6:23 PM
Just upgraded my Cert Spotter subscription to monitor Certificate Transparency for all Geomys domains. Your business probably should, too!

It's good to know we'll get notified if any CA is compromised and/or mis-issues a certificate, but also funding @agwa.name's work benefits all the WebPKI.
Cert Spotter - Certificate Transparency Monitor - Detect Security and Availability Problems
Skip to content
sslmate.com
October 2, 2025 at 11:11 AM
Several large public resolvers including Google Public DNS and several European ISPs have adopted opportunistic ADoT (Authoritative DNS-over-TLS) and use it with our servers. There's no way to ENFORCE using ADoT yet but we're keeping an eye on it. We have valid WebPKI certs + DANE TLSA for it.
May 4, 2025 at 7:06 PM
#Cloudflare recently announced Merkle Tree Certificates (MTCs), a proposal brought to the Internet Engineering Task Force (IETF) that fundamentally redesigns the #WebPKI to enable a performance-neutral transition to Post-Quantum (PQ) cryptography. #infoq www.infoq.com/news/2025/11...
Cloudflare Proposes Merkle Tree Certificates to Solve Post-Quantum TLS Performance Issue
Cloudflare's innovative Merkle Tree Certificates (MTCs) revolutionize WebPKI, enabling a seamless transition to Post-Quantum (PQ) cryptography without performance penalties. By minimizing TLS handshak...
www.infoq.com
November 11, 2025 at 10:13 AM
WebPKI incidents prove preparation and transparency matter. My post on turning crises into resilience, with WebPKI lessons for context. Interested?
Incident Response Done Right: A CA’s Guide to Resilience | UNMITIGATED RISK
unmitigatedrisk.com
February 27, 2025 at 1:31 AM
The WebPKI is something we all rely on every day, and most people do not even know it exists. What is interesting is that even those who do often do not understand it as well as they think they do.

To help more people understand how it works, I put together the WebPKI Observatory.
WebPKI Observatory — Certificate Authority Trust Ecosystem Analysis
Quantitative analysis of 96 trusted CAs: market share, concentration risk, compliance incidents, distrust history, and root program governance. Updated daily.
webpki.systematicreasoning.com
March 17, 2026 at 6:43 AM
> blockchains are a 40 years old idea and already used widely

yes, exactly. to steal phrasing from @zmanian.bsky.social :

> Crypto means Ralph Merkle, Whit Diffie and David Chaum. Crypto means cryptocurrency. The "crypto means webpki" people got lost on a side quest.
April 28, 2023 at 9:52 PM
If WebPKI CA drama is your thing, here you go. bugzilla.mozilla.org/show_bug.cgi...
1950144 - DigiCert: Threat of legal action to stifle Bugzilla discourse
UNCONFIRMED (nobody) in CA Program - CA Certificate Root Program. Last updated 2025-02-26.
bugzilla.mozilla.org
February 26, 2025 at 6:20 PM
finally sat down and looked at MTCs and like ... why didnt we do this for webpki years ago? its a much simpler system and makes for smaller handshakes even for classic cryptography algorithms
March 1, 2026 at 10:25 PM
Our authoritative DNS nameservers now support DNS-over-TLS (DoT) with authentication via DANE TLSA and/or WebPKI. This allows DNS resolvers to make queries via securely encrypted connections. We're already seeing lots of DoT encrypted connections from multiple DNS providers.
November 5, 2023 at 4:45 AM
aws-smithy-http-client fixing all of the dependencies to specific versions is pretty anti-social tbh. What do you mean I can't silence the high-severity advisory because it's locked rustls-webpki to a specific patch version
May 29, 2026 at 5:12 AM
I'm working on a new idea for a conference talk,

Everything you learned about SSL is deprecated.

I'd love some feedback on it!

gist.github.com/toddhgardner...
Abstract for a new talk on WebPKI in 2026
Abstract for a new talk on WebPKI in 2026. GitHub Gist: instantly share code, notes, and snippets.
gist.github.com
December 19, 2025 at 7:26 PM
New paper(!) on the "clubcard" data structure that we're using for WebPKI revocation checks in Firefox.

A clubcard is a membership test for an r element subset of an n element set. Size is ~1.13 log(n choose r) bits. Or (better!) ~1.13 Σ log(n_i choose r_i) where i indexes blocks of a partition.
Clubcards for the WebPKI: smaller certificate revocation tests in theory and practice (John M. Schanck) ia.cr/2025/610
April 8, 2025 at 6:46 PM
Das Kunzsche Lemma: Jedes Problem in der Informatik lässt sich auf ein Problem der WebPKI zurückführen.
September 10, 2026 at 9:53 AM
This morning, a serious WebPKI incident surfaced: a tiny CA misissued certificates for 1.1.1.1 - Cloudflare’s DNS service.

With BGP hijacks happening regularly, those certs could enable full man-in-the-middle attacks.

👇
September 3, 2025 at 10:23 PM
450,000+ certificates are issued every hour across the WebPKI. But raw volume doesn't tell you which CAs actually matter.

Matthew McPherrin recently shared Mozilla's Firefox telemetry data showing actual CA usage vs the Certificate Transparency issuance numbers I usually track.

👇
June 16, 2025 at 6:07 PM