Matthew McPherrin
SRE at Let's Encrypt, though these toots are my own.
Have you ever needed to make sure your website has an expired or revoked certificate? No, that's not a problem people have. But we do, because CAs have to run test sites with them.
I just wrote a blog post post about this problem, and our new tool that we use to host ours:
Huh, that’s a message I haven’t seen before
Firefox's new "security alert" and "no connection" error page illustrations are pretty great
We've issued our first short-lived (6 day) certificate! https://letsencrypt.org/2025/02/20/first-short-lived-cert-issued/
Of all the things I didn’t expect to ever happen, iOS Safari actually got a certificate viewer in 18.4! https://webkit.org/blog/16574/webkit-features-in-safari-18-4/#connection-security
Chrome has published version 1.6 of their root store policy.
Notably, this contains a timeline for deprecating use of the TLS Client Auth extended-key-usage inside the PKIs included in their program.
If you currently use TLS Client Auth from a publicly trusted CA, you may need to take action.
> ... certificates issued on or after June 15, 2026 MUST include the extendedKeyUsage extension and only assert an extendedKeyUsage purpose of id-kp-serverAuth.
Firefox's telemetry has data on how many times a CA is used to successfully validate certificates. This is a pretty good measure for how "big" a CA is. The data is hard to view in Mozilla's site, so I've made a script to combine a few data sources and graph it! https://github.com/mcpherrinm/cert-count
@cybeej@infosec.exchange Internet Security Research Group is the name of the organization that runs Let's Encrypt (ie, in #3 position)
Inspired by the classic xeyes program, I made a thing:
ssh teyes.fly.dev
Or go install github.com/mcpherrinm/teyes@latest && teyes
Give your mouse a wiggle over the terminal!
I'll be speaking at the Ontario Cryptography Day!
https://ontario-crypto-day.github.io/
Where: University of Waterloo Davis Centre (DC) 1301 and 1302
When: Friday, June 6, 2025, from 10am to approx. 4:30pm
I hope anyone in the area interested in cryptography is able to attend. It's a free event, but registration is required.


