cert-governance · severity info

Certificate blast radius

Distribution of how many DNS names a single newly issued certificate covers, including wildcards.

Measured every Sunday · last updated

How it is measured

bulk read of a public CT log — nothing is probed. For each certificate in the same 24h window cert-validity-window samples, the number of DNS names it covers, banded: single / small (2–9) / large (10–99) / sprawling (100+). A wildcard certificate is reported as wildcard regardless of count, because its reach is unbounded. Population unit: certificate; segmented by CA.

Why it matters

How many doors one private key opens. A leaked key, a botched renewal or a revocation takes every name on the certificate with it, so the count is the blast radius — and the per-CA cut shows which issuers' customers are concentrating risk that way. A wildcard is the sharpest version: it covers subdomains that did not exist when it was issued, including the forgotten ones that turn up in a takeover story.

Limits of this measurement

A composition, not a verdict. A CDN or platform serving a thousand tenants from one certificate is making a sound operational choice, and none of these states is published as a failure. Read alongside the issuing-CA cut rather than on its own: the distribution largely reflects what kind of customers a CA serves. Counts come from the SAN list as logged; a certificate re-issued with the same names appears once per issuance.

The base rate

Measured over the full population of certificates, from public bulk sources.

All certificates n=43,849
1 name: 48.98%2–9 names: 13.27%10–99 names: 0.41%100+ names: 0.04%wildcard (unbounded): 37.29%
1 name · 48.98%2–9 names · 13.27%10–99 names · 0.41%100+ names · 0.04%wildcard (unbounded) · 37.29%

Every segment

Pick one to see the citable answer, with its trend and methodology.

Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.