Releases: rustls/webpki-roots
Release list
1.0.9
Changes:
- Add "Telia EC TLS Root CA v3" and "Telia RSA TLS Root CA v3" - https://bugzilla.mozilla.org/show_bug.cgi?id=2047804
- Add "SECOM TLS ECC Root CA 2024" and "SECOM TLS RSA Root CA 2024" - https://bugzilla.mozilla.org/show_bug.cgi?id=1943001
- Remove "Atos TrustedRoot 2011" - https://bugzilla.mozilla.org/show_bug.cgi?id=2017374
What's Changed
- Take webpki-root-certs lockfile update by @weifanglab in #125
- 1.0.9: upstream updates by @ctz in #126
New Contributors
- @weifanglab made their first contribution in #125
Full Changelog: v/1.0.8...v/1.0.9
1.0.8
- Remove
SecureSign Root CA12root; see https://bugzilla.mozilla.org/show_bug.cgi?id=2031105
What's Changed
- Test MSRV with 1.70 by @ctz in #122
- Take semver-compatible dependency updates by @djc in #123
- 1.0.8: remove
SecureSign Root CA12root by @ctz in #124
Full Changelog: v/1.0.7...v/1.0.8
1.0.7
For their April 2026 root store changes, Mozilla has made more changes than usual:
These changes are part of Mozilla’s ongoing root store maintenance under the Mozilla Root Store Policy (MRSP), including §7.4 (Root CA Lifecycles) and §7.5.3 (Transition Plans). They reflect a combination of lifecycle-based transitions, CA operator requests, and alignment with intended certificate usage, including retiring older or less suitable root certificates, enforcing clear separation of trust purposes (e.g., TLS vs. S/MIME), and reducing unnecessary trust surface in the Web PKI ecosystem. Collectively, these actions help to ensure that root certificates are relied upon only for their intended and actively maintained use cases, or are retired in accordance with established distrust timelines.
This removes:
- CN=Certigna O=Dhimyotis
- CN=COMODO Certification Authority O=COMODO CA Limited
- CN=DigiCert Assured ID Root CA O=DigiCert Inc OU=www.digicert.com
- CN=DigiCert Global Root CA O=DigiCert Inc OU=www.digicert.com
- CN=DigiCert High Assurance EV Root CA O=DigiCert Inc OU=www.digicert.com
- CN=FIRMAPROFESIONAL CA ROOT-A WEB O=Firmaprofesional SA
- CN=GTS Root R2 O=Google Trust Services LLC
- CN=QuoVadis Root CA 2 O=QuoVadis Limited
- CN=QuoVadis Root CA 3 O=QuoVadis Limited
- CN=Secure Global CA O=SecureTrust Corporation
- CN=SecureTrust CA O=SecureTrust Corporation
- CN=SwissSign Gold CA - G2 O=SwissSign AG
- CN=TeliaSonera Root CA v1 O=TeliaSonera
- CN=Trustwave Global Certification Authority O=Trustwave Holdings, Inc.
- CN=Trustwave Global ECC P256 Certification Authority O=Trustwave Holdings, Inc.
- CN=Trustwave Global ECC P384 Certification Authority O=Trustwave Holdings, Inc.
- O=certSIGN OU=certSIGN ROOT CA
See their announcement for more details.
What's Changed
- Take semver-compatible dependency updates by @djc in #116
- Take semver-compatible dependency updates by @djc in #117
- Take semver-compatible updates by @ctz in #118
- Prepare 1.0.7 by @djc in #120
- Update dependencies by @djc in #119
Full Changelog: v/1.0.6...v/1.0.7
1.0.6
"e-Szigno TLS Root CA 2023" added, see https://bugzilla.mozilla.org/show_bug.cgi?id=1873057
What's Changed
- Update dependencies by @djc in #111
- Trigger CI workflow on merge groups by @djc in #113
- webpki-roots: 1.0.6 by @ctz in #115
Full Changelog: v/1.0.5...v/1.0.6
1.0.5
Removes the following trust anchors which have passed their distrust-after-last-issuance dates:
- Entrust Root Certification Authority - EC1
- Entrust Root Certification Authority - G2
- Entrust Root Certification Authority
- AffirmTrust Commercial
- AffirmTrust Networking
- AffirmTrust Premium
- AffirmTrust Premium ECC
What's Changed
- ccadb: add CertificateMetadata::test_website_revoked field by @djc in #110
- webpki-root[s|-certs]: 1.0.4 -> 1.0.5 by @cpu in #112
Full Changelog: v/1.0.4...v/1.0.5
1.0.4
CommScope removal
https://bugzilla.mozilla.org/show_bug.cgi?id=1994866 tracks the voluntary removal of:
- CommScope Public Trust ECC Root-01
- CommScope Public Trust ECC Root-02
- CommScope Public Trust RSA Root-01
- CommScope Public Trust RSA Root-02
What's Changed
Full Changelog: v/1.0.3...v/1.0.4
1.0.3
Addition of "OISTE Server Root RSA G1" & "OISTE Server Root ECC G1": https://bugzilla.mozilla.org/show_bug.cgi?id=1988913.
What's Changed
1.0.2
- Add "TrustAsia TLS ECC Root CA" and "TrustAsia TLS RSA Root CA" https://bugzilla.mozilla.org/show_bug.cgi?id=1972384
- Add "SwissSign RSA TLS Root CA 2022 - 1" https://bugzilla.mozilla.org/show_bug.cgi?id=1845047
What's Changed
Full Changelog: v/1.0.1...v/1.0.2
1.0.1
Remove Chunghwa Telecom "ePKI Root Certification Authority". See the upstream issue for details.
What's Changed
Full Changelog: v/1.0.0...v/1.0.1
1.0.0
After 51 releases over about nine years, this is the first stable release of the webpki-roots and webpki-root-certs crates.
The 1.0.0 release is functionally equal to the 0.26.10 release. We will make a 0.26.11 release that uses 1.0.0 using the semver trick.
What's Changed
Full Changelog: v/0.26.10...v/1.0.0