NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
crates.io · #123 most downloaded on crates.io
Mozilla's CA root certificates for use with webpki
Last release 2 months ago
18 Jul 2026
Ships fairly regularly
a new release about every 6 weeks
Rarely documented
notes for 10 of 59 stable releases
Nothing withdrawn
no release was ever pulled
10 years old
62 releases · first in 2016
Add "Telia EC TLS Root CA v3" and "Telia RSA TLS Root CA v3" - https://bugzilla.mozilla.org/show_bug.cgi?id=2047804
Changes:
Full Changelog: v/1.0.8...v/1.0.9
One column per quarter.
Remove SecureSign Root CA12 root; see https://bugzilla.mozilla.org/show_bug.cgi?id=2031105
SecureSign Root CA12 root; see https://bugzilla.mozilla.org/show_bug.cgi?id=2031105SecureSign Root CA12 root by @ctz in #124Full Changelog: v/1.0.7...v/1.0.8
For their April 2026 root store changes, Mozilla has made more changes than usual:
For their April 2026 root store changes, Mozilla has made more changes than usual:
These changes are part of Mozilla’s ongoing root store maintenance under the Mozilla Root Store Policy (MRSP), including §7.4 (Root CA Lifecycles) and §7.5.3 (Transition Plans). They reflect a combination of lifecycle-based transitions, CA operator requests, and alignment with intended certificate usage, including retiring older or less suitable root certificates, enforcing clear separation of trust purposes (e.g., TLS vs. S/MIME), and reducing unnecessary trust surface in the Web PKI ecosystem. Collectively, these actions help to ensure that root certificates are relied upon only for their intended and actively maintained use cases, or are retired in accordance with established distrust timelines.
This removes:
See their announcement for more details.
Full Changelog: v/1.0.6...v/1.0.7
"e-Szigno TLS Root CA 2023" added, see https://bugzilla.mozilla.org/show_bug.cgi?id=1873057
"e-Szigno TLS Root CA 2023" added, see https://bugzilla.mozilla.org/show_bug.cgi?id=1873057
Full Changelog: v/1.0.5...v/1.0.6
Removes the following trust anchors which have passed their distrust-after-last-issuance dates:
Removes the following trust anchors which have passed their distrust-after-last-issuance dates:
Full Changelog: v/1.0.4...v/1.0.5
https://bugzilla.mozilla.org/show_bug.cgi?id=1994866 tracks the voluntary removal of:
https://bugzilla.mozilla.org/show_bug.cgi?id=1994866 tracks the voluntary removal of:
Full Changelog: v/1.0.3...v/1.0.4
Addition of "OISTE Server Root RSA G1" & "OISTE Server Root ECC G1": https://bugzilla.mozilla.org/show_bug.cgi?id=1988913 .
Addition of "OISTE Server Root RSA G1" & "OISTE Server Root ECC G1": https://bugzilla.mozilla.org/show_bug.cgi?id=1988913.
Add "TrustAsia TLS ECC Root CA" and "TrustAsia TLS RSA Root CA" https://bugzilla.mozilla.org/show_bug.cgi?id=1972384
Full Changelog: v/1.0.1...v/1.0.2
Remove Chunghwa Telecom "ePKI Root Certification Authority". See the upstream issue for details.
Remove Chunghwa Telecom "ePKI Root Certification Authority". See the upstream issue for details.
Full Changelog: v/1.0.0...v/1.0.1
After 51 releases over about nine years, this is the first stable release of the webpki-roots and webpki-root-certs crates.
After 51 releases over about nine years, this is the first stable release of the webpki-roots and webpki-root-certs crates.
The 1.0.0 release is functionally equal to the 0.26.10 release. We will make a 0.26.11 release that uses 1.0.0 using the semver trick.
Full Changelog: v/0.26.10...v/1.0.0
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →