30 September 2026
Feisty Duck’s Cryptography & Security Newsletter is a periodic dispatch bringing you commentary and news surrounding cryptography, security, privacy, SSL/TLS, and PKI. It's designed to keep you informed about the latest developments in this space. Enjoyed every month by more than 50,000 subscribers. Written by Ivan Ristić.

Practical TLS and PKI Training Taught by Scott Helme and designed by Ivan Ristić, this practical training course will take you through everything you need to know to deploy secure servers and design secure web applications. With freshly updated materials, including post-quantum cryptography. Nov 16-19th, US timezones. Join us!
With the groundwork for the post-quantum migration of key establishment behind us, browser vendors are increasing their efforts on the remaining parts: post-quantum authentication. (If you haven’t been following the events surrounding post-quantum migration, our newsletter from two months ago has a quick recap. Read it before continuing here.)
We already know that Web PKI is switching to Merkle Tree Certificates (MTCs). This new technology, which unifies traditional X.509 certificates with Certificate Transparency, is being developed at the IETF Plants Working Group. In February, Google published its deployment plan, which ends, roughly, with MTC certificates in production by the end of 2027.
When it comes to the mechanics of issuance and deployment, ACME will be doing the heavy lifting, and this is deeply embedded in Chrome’s Quantum-resistant Root Program Policy. This shouldn’t come as a surprise to anyone, as we already know that all certificates will be limited to a lifetime of only 47 days in March 2029. Nobody wants to manually rotate their certificates every month. Thus, in the MTC Web PKI, ACME plays a significant role, alongside ACME Renewal Information (ARI, specified in RFC 9773), which can be used to enforce early rotation. Automation all the way.
ACME is definitely necessary, as in the short term we may end up deploying up to 4 certificates. In the foreseeable future, we'll still need RSA and ECDSA certificates to keep existing user agents happy. MTC itself creates two new certificate types: one “slow” that’s available immediately at issuance, and a “fast” certificate that becomes available later, typically a couple of hours. We definitely can’t be doing these things manually.
Chrome’s current policy for MTCs allows subscriber certificates valid for up to 47 days, but if you read the details, you see that the expectation is that there will be a main CA cosigner (equivalent to a root certificate of today) that’s capped to issuing 7-day subscriber certificates. Issuance beyond that, and up to 47 days, has to be done via separate optional cosigners.
However, it looks like there will definitely be a 7-day hard limit, judging from what Apple said in their advance warning about their post-quantum plans, published about a week ago: “Capped at 7 days”.
As the regular readers of this newsletter will know, we’re fans of short-lifetime certificates. In the right hands, they solve revocation in the best way we currently know how. That said, we have to acknowledge they allow a very small margin of error. With 47-day certificates rotated at 30 days, you have two weeks to fix problems. With 7-day certificates, rotated at 4 days, you get only 3 days. If the problem happens on a weekend, that reduces to a day or so.
For this to work, the infrastructure and the automation have to be rock solid. In addition, virtually everyone will need robust continuous monitoring to detect a variety of new failure modes quickly enough to fix problems before downtime occurs.
This subscription is just for the newsletter; we won't send you anything else.
We use our purpose-built news aggregation platform, Feisty Duck News, to curate this newsletter. In the past month, we reviewed 3,454 news articles, selected 583 as on-topic, and promoted 58 to the front page. Despite the automation, 39 out of 58 entries were added manually. In the end, only 27 articles made it into this newsletter.
Looking to hire? Promote your open roles via our classifieds section. Early-bird discount available, please get in touch. Applying? Please them know you found the position through our newsletter. Your support helps us grow!
We use Claude to help us create the short news section.
Designed by Ivan Ristić, the author of SSL Labs, Bulletproof TLS and PKI, and Hardenize, our course covers everything you need to know to deploy secure servers and encrypted web applications.
Remote and trainer-led, with small classes and a choice of timezones.
Join over 3,000 students who have benefited from more than a decade of deep TLS and PKI expertise.