Let’s Encrypt just outlined a real engineering roadmap for “post‑quantum Web PKI,” and it’s more interesting than a simple algorithm swap. The headline: they’re planning to use MTC (Merkle Tree Certificates) as the main approach. Timeline-wise, they expect to stand up a test environment for issuing MTC sometime later in 2026, then build a production‑ready setup in 2027. Importantly, ongoing certificate requests and renewals for current certs won’t be abruptly interrupted—this is a phased migration. Why MTC instead of “just replace X.509 with PQ signatures”? Post‑quantum schemes can bring bigger keys and signatures. For example, ML‑DSA‑44 is roughly ~2,420 bytes for signatures and ~1,312 bytes for public keys. If you naïvely balloon the TLS handshake payload, you could push per‑connection data past 10KB—hurting success rates and latency. MTC solves this by batching certificates into a Merkle tree: one signature can cover many certs. Browsers use “Landmarks” metadata so authentication stays lightweight. It also reshapes Certificate Transparency by embedding it into the issuance flow. Next: infra, ACME, revocation + ops tooling. Existing certs won’t be impacted—ACME automation teams should track PLANTS discussions. #LetsEncrypt #PostQuantum #WebPKI #MTC #ACME #TLS
Want to learn more? Visit Explore the world, stay updated on travel insights and international affairs, and discover authentic stories from real life
评论
发表评论