NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #643 most downloaded on crates.io
rustls-platform-verifier supports verifying TLS certificates in rustls with the operating system verifier
Last release 15 days ago
24 Sep 2026
Release timing varies
gaps range from 1 weeks to 6 months
Some releases are documented
notes for 11 of 19 stable releases
Nothing withdrawn
no release was ever pulled
3 years old
19 releases · first in 2024
The biggest improvement to functionality in this release is proper support for revocation on Android. As OCSP moves to deprecation, more CAs are exclu…
This version contains Windows and Android bugfixes, but its headline feature is a migration to an improved distribution strategy for the Android component of the crate, which must be included by Gradle for Android application/library builds. If you don't build for Android, no need to worry these changes don't affect you. But if you do, please continue reading to understand the required migration steps and benefits. 0.7.1 requires the Android migration to be performed once manually.
The biggest improvement to functionality in this release is proper support for revocation on Android. As OCSP moves to deprecation, more CAs are exclusively using CRLs to distribute revocation data. Previously this failed to work on Android without workarounds since by default the network fetches for this were blocked. As of 0.2.0 of rustls-platform-verifier-android, this works again as expected. We now bundle an Android App manifest with the library, which Android Studio merges into the main manifest of the app being built.
As of this release, we have stopped bundling pre-compiled .aar artifacts and a local Maven repository inside each release of rustls-platform-verifier-android. Instead, all future (and past!) Maven artifacts are now hosted on GitHub under the maven-archive branch. The branch's structure creates a remote Maven repository that Gradle can download and synchronize with just like any other. Importantly, this now means that the Android library can be downloaded and resolved independently of cargo's own downloads.
0.2.0 of the Android component is exclusively distributed through this new mechanism, but the 0.1.0 and 0.1.1 releases were also backported to the new repository. This means that no matter what version of rustls-platform-verifier you are using, its possible to migrate your Gradle build configuration to the more modern approach. Once again we have included out-of-the-box Gradle and Kotlin script snippets to configure the repository. See our README guide for more info.
Full Changelog: v/0.7.0...v/0.7.1
One column per month.
The reason this release is semver-incompatible is the upgrade from jni 0.21 to 0.22, which should only affect Android targets (and substantially reuse
The reason this release is semver-incompatible is the upgrade from jni 0.21 to 0.22, which should only affect Android targets (and substantially reuse dependency duplication). Additionally there are several fixes for behavior on Windows.
Do not permanently attach JVM threads by @complexspaces in #185
This version should fix the docs.rs build -- see #181 .
This version should fix the docs.rs build -- see #181.
Full Changelog: v/0.6.0...v/0.6.1
Avoid implicit reliance on the default crypto provider
Adapt to changes in rustls error API.
The headline of this release is server compatibility improvements.
The headline of this release is server compatibility improvements.
It removes an edge case where a failure to load any certificates on Linux/BSD platforms would result in silently turning the lack of certificate roots into "no signature algorithms". During the initialization of a TLS session with a server this caused rustls to send an empty supported signature list in the ClientHello.
Full Changelog: v/0.5.1...v/0.5.2
Change the way we interact with the rustls API to avoid semver hazards: unfortunately changes in rustls 0.23.24 broke older rustls-platform-verifier r
Change the way we interact with the rustls API to avoid semver hazards: unfortunately changes in rustls 0.23.24 broke older rustls-platform-verifier releases due to downcasting of a no-longer compatible error wrapper. rustls 0.23.25 now exposes the required variant directly, which should avoid similar issues in the future. (For more details, see #163.)
The upgrade to jni 0.21 contained some Android-only breaking changes -- API changes should not affect other platforms.
These intend to replace tls_config and tls_config_with_provider , which are now deprecated.
new_with_extra_roots() fn now accepts impl IntoIterator<Item = pki_types::TrustAnchor<'static>> in place of Vec<pki_types::CertificateDer<'static>> to better harmonize with the other platforms.winapi with windows-sys - the latter is a 1st party Microsoft crate with better on-going support.BuilderVerifierExt and ConfigVerifierExt traits which provide with_platform_verifier() methods for easier rustls client configuration. These intend to replace tls_config and tls_config_with_provider, which are now deprecated.new_with_extra_roots API by @stormshield-gt in #145Full Changelog: v/0.3.4...v/0.4.0
Fix an error in the handling of allowed EKUs on Windows; see #126
Full Changelog: v/0.3.3...v/0.3.4
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →