WebPKI Observatory — Cryptographic Posture

The cryptographic posture data for this digest focuses on root certificate algorithm distribution, key size compliance with current standards, and adherence to algorithm deprecation timelines across the 335 trusted roots. Aging roots using SHA-1 or 1024-bit RSA represent legacy technical debt, while the transition to newer hierarchies using SHA-256 and 2048-bit or stronger keys reflects ongoing infrastructure modernization. The gap between roots trusted in stores and roots actively issuing creates a reservoir of dormant cryptographic material that could be activated without additional trust decisions.

Return to WebPKI Observatory