cert-governance · severity medium
Certificate crypto
Share of certificates using a weak key or signature (SHA-1, or a sub-2048-bit RSA key).
Measured every Wednesday · last updated
How it is measured
Tier 2; key type and size, plus signature algorithm. Denominator: has_web.
Why it matters
The "not everything is broken" control — a near-solved problem, published because a dispassionate source reports the good news too.
Limits of this measurement
the rule must key on the algorithm, not the number. < 2048 bits is weak only for RSA; EC keys are strong at 256/384/521 bits, and the signature_algorithm field describes the issuer's signature, not the subject key. Getting this wrong produced a false 30% weak rate before it was fixed — the canonical example of a wrong-rule bug in this project.
The base rate
Two independent populations. The global, domain-anchored figure is unbiased; the company-anchored figures are built by matching company names to domains and skew toward more digitally-mature firms. Both are published, so the gap is visible.
By company size band
Company-anchored cuts (national registries with a size proxy), split by size band. Right-hand figure is the share not meeting the control.
Every segment
Pick one to see the citable answer for a company like yours, with its trend and methodology.
Show the remaining 61 segments
Slices below 100 measured members are withheld rather than shown with a wide interval — an absent country or issuer means too little data, not zero failures. Licensed CC BY 4.0. Machine-readable data per segment: append .json or .csv to its URL.