# RootCerts.com — LLM-full.txt Domain: https://rootcerts.com Generated from the same content index that powers the site search and command palette. # RootCerts.com — LLM.txt Domain: https://rootcerts.com Purpose: An open, editorial reference that tracks the standards, technologies, and operational practices behind digital certificates, PKI, automation, and post-quantum security. Audience: PKI engineers, platform teams, security architects, compliance officers, developers, and executives who need to understand what changed, how it works, and what to do next. What you will find here: - Today feed: a high-signal summary of current digital-trust developments and deadlines. - Certificate Atlas: every major certificate type explained side-by-side (subject, issuer, validity, protocols, failure modes, PQC implications). - Use cases: where certificates are used (TLS, mTLS, code signing, email, IoT/OT, SPIFFE, etc.). - Management model: an eight-stage operating model for certificate lifecycle, ownership, and renewal. - 47-Day TLS Center: timeline, workload calculator, and action plan for the CA/B Forum short-lived certificate transition. - Standards Radar: ballots, RFCs, and regulatory updates with impact and effective dates. - Post-Quantum Center: PQC algorithms, size/cost estimates, migration timelines, and a crypto-agility readiness assessment. - Newsroom: curated industry digest articles. - Tools: interactive visualizers and labs (trust chain, Merkle proofs, lifecycle, workload calculator, readiness assessment). - Glossary: plain-language PKI vocabulary. - Sources: the evidence hierarchy and references used across the site. How to use this site: - Use the command palette (⌘K / Ctrl+K or “/”) to jump to any page, tool, or term. - Each page has its own metadata, structured data, and canonical URL. - Content is grouped into three pillars: Understand (what it is), Change (what is changing), and Operate (how to run it). Editorial policy: - Claims are tied to a source tier: standards body, root program, government, certification authority, or research. - Effective dates, ballot numbers, and RFCs are cited where possible. - The site does not sell certificates; it explains how the ecosystem works. For a complete machine-readable index of pages, tools, and concepts, see https://rootcerts.com/llm-full.txt. --- # Full content index Total entries: 52 ## Tools (5) Title: Trust Chain Visualizer Kind: Tool URL: https://rootcerts.com/tools/trust-chain-visualizer Summary: Build a chain from leaf to root and watch path building fail the way real clients fail. --- Title: Merkle Proof Lab Kind: Tool URL: https://rootcerts.com/tools/merkle-proof-lab Summary: Generate real SHA-256 inclusion proofs and see how Certificate Transparency verifies them. --- Title: Certificate Lifecycle Lab Kind: Tool URL: https://rootcerts.com/tools/lifecycle-lab Summary: Model ownership gaps across environments and see where renewal quietly breaks. --- Title: 47-day renewal workload calculator Kind: Tool URL: https://rootcerts.com/change/47-day-tls Summary: Estimate renewal events, FTE hours and risk exposure at each lifetime step. --- Title: Crypto-agility readiness assessment Kind: Tool URL: https://rootcerts.com/pqc Summary: Score your ability to change algorithms without a redesign. --- ## Developments (5) Title: Public TLS certificate validity capped at 200 days Kind: Development URL: https://rootcerts.com/change/standards Status: effective Date: 2026-03-15 Summary: Public TLS certificates issued on or after 15 March 2026 may not exceed 200 days. Two further reductions are already scheduled. --- Title: ACME Renewal Information (ARI) published as RFC 9773 Kind: Development URL: https://rootcerts.com/change/standards Status: published Date: 2025-06-01 Summary: ACME servers can now tell clients when to renew, so renewals can be rescheduled by the CA during mass-revocation events. --- Title: NIST finalizes ML-KEM, ML-DSA and SLH-DSA Kind: Development URL: https://rootcerts.com/change/standards Status: published Date: 2024-08-13 Summary: The first principal post-quantum standards are final. NIST advises organizations to inventory quantum-vulnerable cryptography and plan migration now. --- Title: Certificate Transparency v2 (RFC 9162) Merkle tree auditing Kind: Development URL: https://rootcerts.com/change/standards Status: published Date: 2021-12-01 Summary: CT logs use binary Merkle trees so any client can verify that a certificate was logged without downloading the log. --- Title: Merkle Tree Certificates explored in IETF PLANTS Kind: Development URL: https://rootcerts.com/change/standards Status: experimental Date: 2025-02-01 Summary: An emerging construction that integrates certificate issuance with a public log to cut the overhead of large PQC signatures and very short lifetimes. --- ## Certificate types (9) Title: TLS server Kind: Certificate type URL: https://rootcerts.com/learn Summary: Hostname or IP address — issued by Publicly trusted intermediate CA. ≤ 200 days today, 47 days from 2029 --- Title: S/MIME Kind: Certificate type URL: https://rootcerts.com/learn Summary: Mailbox address and/or person — issued by Publicly trusted S/MIME CA. Typically 1–3 years by profile --- Title: Code signing Kind: Certificate type URL: https://rootcerts.com/learn Summary: Legal organization identity — issued by Publicly trusted code-signing CA. 1–3 years, with timestamping --- Title: Document signing Kind: Certificate type URL: https://rootcerts.com/learn Summary: Person or organization — issued by Qualified or publicly trusted CA. 1–3 years --- Title: Internal TLS Kind: Certificate type URL: https://rootcerts.com/learn Summary: Internal hostname or service name — issued by Private CA (Microsoft CA, private hierarchy, CLM-hosted). Policy defined, hours to years --- Title: Device identity Kind: Certificate type URL: https://rootcerts.com/learn Summary: Device serial, IMEI, or asset identifier — issued by Private device CA. Months to device lifetime --- Title: Workload identity Kind: Certificate type URL: https://rootcerts.com/learn Summary: SPIFFE ID or service account — issued by Mesh or platform CA. Minutes to hours --- Title: IoT and OT Kind: Certificate type URL: https://rootcerts.com/learn Summary: Device or module identity — issued by Manufacturer or operator CA. Often the operational life of the device --- Title: Payments Kind: Certificate type URL: https://rootcerts.com/learn Summary: Merchant, terminal, or scheme participant — issued by Scheme-operated CA. Scheme-defined --- ## Use cases (8) Title: Websites and APIs (TLS) Kind: Use case URL: https://rootcerts.com/use Summary: How does a browser or client decide this server is who it claims to be? --- Title: Mutual TLS between services Kind: Use case URL: https://rootcerts.com/use Summary: How do two services authenticate each other without shared secrets? --- Title: Code signing Kind: Use case URL: https://rootcerts.com/use Summary: Did this binary come from the publisher it claims, unchanged? --- Title: Document signing Kind: Use case URL: https://rootcerts.com/use Summary: Can this document be proven authentic years later, to a regulator? --- Title: Secure email (S/MIME) Kind: Use case URL: https://rootcerts.com/use Summary: Was this message really sent by that person, and can only the recipient read it? --- Title: Devices, IoT and OT Kind: Use case URL: https://rootcerts.com/use Summary: How does a device prove its identity on first boot and for fifteen years after? --- Title: Workloads and machine identity Kind: Use case URL: https://rootcerts.com/use Summary: What is the identity of a container that lives for ninety seconds? --- Title: Private PKI Kind: Use case URL: https://rootcerts.com/use Summary: When should we run our own hierarchy instead of buying public trust? --- ## Practices (8) Title: Discovery — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Find every certificate, including the ones nobody declared. --- Title: Inventory and ownership — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Give every certificate a system, an owner and an expiry consequence. --- Title: Issuance — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Make the compliant path the easiest path. --- Title: Deployment — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Get the new certificate into every place the old one lives. --- Title: Renewal — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Renew early, repeatedly, and without human scheduling. --- Title: Revocation and mass replacement — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Be able to replace a large population in 24 hours. --- Title: Automation and observability — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Turn certificates into a monitored, self-healing system. --- Title: Crypto agility — certificate management Kind: Practice URL: https://rootcerts.com/manage Summary: Change algorithm, key size or issuer without a redesign. --- ## Articles (5) Title: The first 47-day step lands in March 2026: 200-day maximum lifetimes Kind: Article URL: https://rootcerts.com/news Status: approved Date: 2026-01-14 Summary: Ballot SC-081 reduces the maximum TLS certificate lifetime to 200 days in March 2026 — the first of three reductions ending at 47 days in 2029. --- Title: Shorter validation reuse is the change most teams have not modelled Kind: Article URL: https://rootcerts.com/news Status: approved Date: 2026-01-08 Summary: Certificate lifetime gets the attention, but the collapse of domain validation reuse periods changes who has to be involved in renewal, and how often. --- Title: Why your private hierarchy is the right place to pilot ML-DSA Kind: Article URL: https://rootcerts.com/news Status: effective Date: 2025-12-18 Summary: You control every relying party in a private PKI, which removes the single biggest blocker to post-quantum signature deployment. --- Title: The outage was not expiry — it was a chain the client could not build Kind: Article URL: https://rootcerts.com/news Status: effective Date: 2025-12-02 Summary: A recurring failure shape: the server certificate is valid, but an intermediate is missing or a cross-signed path is no longer accepted by older clients. --- Title: Weekly root signal — week 3, 2026 Kind: Article URL: https://rootcerts.com/news Status: effective Date: 2026-01-16 Summary: Lifetime reduction preparation dominates; PQC hybrid key exchange continues to expand quietly across CDNs and browsers. --- ## Glossarys (12) Title: ACME Kind: Glossary URL: https://rootcerts.com/glossary Summary: A protocol (RFC 8555) for automated proof of control, certificate ordering, issuance, and renewal. --- Title: ARI Kind: Glossary URL: https://rootcerts.com/glossary Summary: ACME Renewal Information (RFC 9773): a CA-supplied suggested renewal window that clients poll. --- Title: Certificate Transparency Kind: Glossary URL: https://rootcerts.com/glossary Summary: Append-only public logs of issued certificates, verifiable with Merkle inclusion and consistency proofs. --- Title: Crypto agility Kind: Glossary URL: https://rootcerts.com/glossary Summary: The ability to change cryptographic algorithms, keys, and protocols without redesigning systems. --- Title: Harvest now, decrypt later Kind: Glossary URL: https://rootcerts.com/glossary Summary: Capturing encrypted traffic today to decrypt once a quantum computer becomes available. --- Title: Inclusion proof Kind: Glossary URL: https://rootcerts.com/glossary Summary: The sibling hashes needed to recompute a Merkle root and prove one record is in the tree. --- Title: Intermediate CA Kind: Glossary URL: https://rootcerts.com/glossary Summary: A CA certificate signed by a root and used for day-to-day issuance, keeping roots offline. --- Title: Machine identity Kind: Glossary URL: https://rootcerts.com/glossary Summary: The credential that lets a workload, device, or service authenticate itself — usually a certificate. --- Title: ML-KEM Kind: Glossary URL: https://rootcerts.com/glossary Summary: The NIST-standardized module-lattice key encapsulation mechanism, FIPS 203. --- Title: Path building Kind: Glossary URL: https://rootcerts.com/glossary Summary: The client-side process of assembling a chain from a presented leaf to a trusted root. --- Title: SCT Kind: Glossary URL: https://rootcerts.com/glossary Summary: Signed Certificate Timestamp: a log's promise to include a certificate, required by browsers. --- Title: Trust store Kind: Glossary URL: https://rootcerts.com/glossary Summary: The set of root certificates a client trusts, governed by a root program. ---