Reference
Sources
Nothing on this site asserts a requirement without a source you can open and read yourself.
Source hierarchy
How we weigh evidence
Tier 1 — Normative primary sources
RFCs, FIPS publications, CA/Browser Forum requirements and ballots, root-program policies.
Tier 2 — Official explanatory sources
Working-group drafts, browser and CA announcements, government guidance.
Tier 3 — Expert analysis
Named practitioner and research commentary, clearly attributed and labelled as interpretation.
Tier 4 — Signals
Mailing lists, incident reports and industry reporting used to detect change, never to assert it.
Currently cited
Primary sources behind tracked developments
Standards body · CA/Browser Forum
CA/Browser Forum — Ballot SC-081v3 (certificate lifetime reduction)Supports: Public TLS certificate validity capped at 200 days · last verified 2026-08-01
Standards body · IETF
RFC 9773 — Automated Certificate Management Environment (ACME) Renewal InformationSupports: ACME Renewal Information (ARI) published as RFC 9773 · last verified 2026-07-22
Government · NIST
FIPS 203 / 204 / 205Supports: NIST finalizes ML-KEM, ML-DSA and SLH-DSA · last verified 2026-07-30
Standards body · IETF
RFC 9162 — Certificate Transparency Version 2.0Supports: Certificate Transparency v2 (RFC 9162) Merkle tree auditing · last verified 2026-07-12
Standards body · IETF
IETF PLANTS working group — Merkle Tree Certificates draftSupports: Merkle Tree Certificates explored in IETF PLANTS · last verified 2026-07-28