Today I published an update on the #Canonical supported #upki project, which brings browser-grade Public Key Infrastructure to Linux through the efficient #CRLite data format, with the core revocation engine now functional and available to test!

Beyond current progress, this post explores broader integration, performance, and future capabilities like Certificate Transparency enforcement and Merkle Tree.

This is all part of the effort to increase the resilience of #Ubuntu machines by default, but I hope it has a wider benefit on the Linux ecosystem going forward!

https://discourse.ubuntu.com/t/77063

#CertificateTransparency #PKI #Cryptography

An update on upki

Last year, I announced that Canonical had begun supporting the development of upki, a project that will bring browser-grade Public Key Infrastructure (PKI) to Linux. Since then, development has been moving at pace thanks to the tireless work of Dirkjan and Joe. In this post, I’ll explore the progress we’ve made, how you can try an early version, and where we’re going next. Architecture & Progress As a reminder, upki’s primary goal is to provide a reliable, privacy-preserving, and efficient cer...

Ubuntu Community Hub
Firefox: Schneller und sicherer surfen dank CRLite

Ein neues System für Zertifikatssperrlisten: Firefox 142 führt CRLite ein. Die lokale, komplette Prüfung widerrufener Zertifikate ist sicherer und schneller.

heise online

CRLite is a fascinating piece of technology by Mozilla to handle revocations on the WebPKI, in a privacy-friendly and bandwidth ~friendy approach: it uses a new compact data-structure called Clubcards (basically Ribbon filters (enhanced Bloom filters) with partitionning): https://hacks.mozilla.org/2025/08/crlite-fast-private-and-comprehensive-certificate-revocation-checking-in-firefox/

#RustLang #WebPKI #revocation #CRLite #clubcard #Firefox

CRLite: Fast, private, and comprehensive certificate revocation checking in Firefox – Mozilla Hacks - the Web developer blog

Firefox is now the first and the only browser to deploy fast and comprehensive certificate revocation checking that does not reveal your browsing activity to anyone (not even to Mozilla). ...

Mozilla Hacks – the Web developer blog
Fast, private and secure (pick three): Introducing #CRLite in #Firefox
https://blog.mozilla.org/en/firefox/crlite/
Fast, private and secure (pick three): Introducing CRLite in Firefox | The Mozilla Blog

We are pleased to announce that Firefox 142 will begin production usage of our brand new certificate revocation system known as CRLite. CRLite makes your b

Το #Firefox_CRLite ενισχύει την ασφάλεια και το απόρρητο χωρίς συμβιβασμούς

Η #Mozilla εισήγαγε ένα νέο #σύστημα_ανάκλησης πιστοποιητικών στον #Firefox_142 που ονομάζεται #CRLite. Ο κατασκευαστής του προγράμματος περιήγησης δήλωσε ότι το CRLite κάνει την #περιήγηση πιο γρήγορη, πιο #ιδιωτική και πιο #ασφαλή.

https://www.techne.gr/ams/to-firefox-crlite-enischyei-tin-asfaleia-kai-to-aporrito-choris-symvivasmoys.193/

Το Firefox CRLite ενισχύει την ασφάλεια και το απόρρητο χωρίς συμβιβασμούς

Η Mozilla εισήγαγε ένα νέο σύστημα ανάκλησης πιστοποιητικών στον Firefox 142 που ονομάζεται CRLite. Ο κατασκευαστής του προγράμματος περιήγησης δήλωσε ότι το CRLite κάνει την περιήγηση πιο γρήγορη, πιο ιδιωτική και πιο ασφαλή. Ως ένα μικρό...

Techne
🚀 Firefox steigert Sicherheit & Geschwindigkeit beim Surfen mit CRLite! Kein externer Abruf mehr nötig – alle widerrufenen Zertifikate werden lokal geprüft. Mehr Schutz, mehr Privatsphäre, schnellere Ladezeiten. Zukunft fürs Web? 🔒⚡ #Firefox #CRLite #InternetSicherheit https://www.heise.de/news/Firefox-Schneller-und-sicherer-surfen-dank-CRLite-10550596.html
#newz
Firefox: Schneller und sicherer surfen dank CRLite

Ein neues System für Zertifikatssperrlisten: Firefox 142 führt CRLite ein. Die lokale, komplette Prüfung widerrufener Zertifikate ist sicherer und schneller.

heise online

I'll be attending the Real World Crypto Symposium in Toronto in two weeks time (#RWC), and after that, I'm once again co-organizing the Open Source Cryptography Workshop. (#OSCW2024)

I’ll also be real happy to talk about the new developments with the #Sunlight #CertificateTransparency log design, Let’s Encrypt’s new ACME Renewal Information (#ARI) draft specification, #CRLite, Rustls… all that stuff.

https://insufficient.coffee/2024/03/14/rwc-and-oscw-2024/

Attending Real World Crypto and the Open Source Cryptography Workshop 2024

I’ll be attending the Real World Crypto Symposium in Toronto in two weeks time, and after that, I’m once again co-organizing the Open Source Cryptography Workshop.

Insufficient.Coffee