Skip to main content
  1. Tags/

CRLite

2026


An update on upki

·1521 words·8 mins

This post provides an update on the Canonical-supported upki project, which brings browser-grade Public Key Infrastructure to Linux through the efficient CRLite data format, with the core revocation engine now functional and available to test.

Beyond current progress, this post explores broader integration, performance, and future capabilities like Certificate Transparency enforcement and Merkle Tree Certificates.

2025


Addressing Linux's Missing PKI Infrastructure

·1274 words·6 mins
Announcing work on upki, a universal tool for Linux and other Unix-like operating systems for handling X.509 certificate revocation lists in system utilities.