cert-governance · severity info
Certificate blast radius
Distribution of how many DNS names a single newly issued certificate covers, including wildcards.
Measured every Sunday · last updated
How it is measured
bulk read of a public CT log — nothing is probed. For each certificate in the same 24h window cert-validity-window samples, the number of DNS names it covers, banded: single / small (2–9) / large (10–99) / sprawling (100+). A wildcard certificate is reported as wildcard regardless of count, because its reach is unbounded. Population unit: certificate; segmented by CA.
Why it matters
How many doors one private key opens. A leaked key, a botched renewal or a revocation takes every name on the certificate with it, so the count is the blast radius — and the per-CA cut shows which issuers' customers are concentrating risk that way. A wildcard is the sharpest version: it covers subdomains that did not exist when it was issued, including the forgotten ones that turn up in a takeover story.
Limits of this measurement
A composition, not a verdict. A CDN or platform serving a thousand tenants from one certificate is making a sound operational choice, and none of these states is published as a failure. Read alongside the issuing-CA cut rather than on its own: the distribution largely reflects what kind of customers a CA serves. Counts come from the SAN list as logged; a certificate re-issued with the same names appears once per issuance.
The base rate
Measured over the full population of certificates, from public bulk sources.
Every segment
Pick one to see the citable answer, with its trend and methodology.
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.