# Results — 726 certificates from the Tranco top 1000

Scan run 2026-09-10 from the VPS that serves untilnextsession.com. Method and verdict rules: `README.md`, written first.

## Reachability, and the kill rule

- handshake completed: **726 of 1000** (72.6 %)
- **no address at the apex**: 222 — the domain has no A or AAAA record of its own. These are infrastructure zones (`akamaiedge.net`, `cloudfront.net`, `akadns.net`, `apple-dns.net`, `trafficmanager.net`, …) that rank on the strength of their subdomains. They are not websites and there is nothing to hand me.
- other failures: 52 — TimeoutError 40, SSLError 8, ConnectionRefusedError 2, ConnectionResetError 2

**The kill rule fired.** Fewer than 800 of the 1,000 completed a handshake, so nothing below is a share of the top 1,000: every figure is a share of the **726** domains in the top 1,000 that actually serve TLS at their own apex. Said once here so it does not have to be repeated in every row.

## Who issued them

### The reachable top 1,000 — 726 certificates

| issuer | certificates | share |
| --- | --: | --: |
| DigiCert | 153 | 21.1 % |
| Google Trust Services | 142 | 19.6 % |
| Let's Encrypt | 134 | 18.5 % |
| Amazon | 111 | 15.3 % |
| GlobalSign | 66 | 9.1 % |
| Sectigo | 52 | 7.2 % |
| Microsoft | 18 | 2.5 % |
| GoDaddy | 12 | 1.7 % |
| Apple | 5 | 0.7 % |
| HARICA | 5 | 0.7 % |
| InCommon | 4 | 0.6 % |
| Certainly | 3 | 0.4 % |
| SSL.com | 3 | 0.4 % |
| IdenTrust | 3 | 0.4 % |
| ZeroSSL | 3 | 0.4 % |
| Gandi | 2 | 0.3 % |
| Entrust | 2 | 0.3 % |
| Trust Provider | 1 | 0.1 % |
| Actalis | 1 | 0.1 % |
| iTrusChina | 1 | 0.1 % |
| Cybertrust Japan | 1 | 0.1 % |
| McAfee | 1 | 0.1 % |
| Kazakhstan MDDC | 1 | 0.1 % |
| Soluciones Corporativas IP | 1 | 0.1 % |
| WoTrus | 1 | 0.1 % |

| how it is obtained | certificates | share |
| --- | --: | --: |
| purchased | 300 | 41.3 % |
| open-acme | 282 | 38.8 % |
| platform | 134 | 18.5 % |
| community | 10 | 1.4 % |

### The reachable top 100 — 75 certificates

| issuer | certificates | share |
| --- | --: | --: |
| DigiCert | 20 | 26.7 % |
| Google Trust Services | 17 | 22.7 % |
| Let's Encrypt | 12 | 16.0 % |
| Microsoft | 11 | 14.7 % |
| Sectigo | 3 | 4.0 % |
| GlobalSign | 3 | 4.0 % |
| Amazon | 2 | 2.7 % |
| Apple | 2 | 2.7 % |
| HARICA | 1 | 1.3 % |
| Certainly | 1 | 1.3 % |
| Gandi | 1 | 1.3 % |
| SSL.com | 1 | 1.3 % |
| Trust Provider | 1 | 1.3 % |

| how it is obtained | certificates | share |
| --- | --: | --: |
| open-acme | 30 | 40.0 % |
| purchased | 29 | 38.7 % |
| platform | 15 | 20.0 % |
| community | 1 | 1.3 % |

## How long they live

Lifetime is `notAfter − notBefore` in **whole days**. Many CAs backdate `notBefore` by about an hour, so a certificate sold as 90 days measures 89 here and one sold as 47 measures 46. Every boundary below is therefore soft by one day, in one direction, and the round numbers a CA advertises sit one above what this counts.

### All reachable

- **n** 726; **median** 197 days; quartiles 89 / 197 / 199; min 29, max 397
- at or under **47 days**: 6 (0.8 %)
- at or under **90 days**: 307 (42.3 %)
- at or under **100 days**: 318 (43.8 %)
- at or under **200 days**: 560 (77.1 %)
- at or under **366 days**: 595 (82.0 %)

| lifetime | certificates | share |
| --- | --: | --: |
| ≤ 47 days | 6 | 0.8 % |
| 48–90 days | 301 | 41.5 % |
| 91–100 days | 11 | 1.5 % |
| 101–200 days | 242 | 33.3 % |
| 201–400 days | 166 | 22.9 % |
| > 400 days | 0 | 0.0 % |

### Against the 200-day cap (SC-081v3, in force 2026-03-15)

- issued on or after 2026-03-15: **557** of 726 (76.7 %)
- of those, valid for more than 200 days: **1** (0.2 %)

| domain | issuer | issued | expires | days |
| --- | --- | --- | --- | --: |
| sberbank.ru | The Ministry of Digital Development and Communications | 2026-07-27 | 2027-07-27 | 365 |

Issued before the cap: 169, of which 165 run longer than 200 days. Those are not violations — they were legal when they were signed — and they are what the cap replaces.

## Keys, TLS and trust

| key | certificates | share |
| --- | --: | --: |
| RSA 2048 | 456 | 62.8 % |
| ECDSA 256 | 252 | 34.7 % |
| RSA 4096 | 12 | 1.7 % |
| ECDSA 384 | 4 | 0.6 % |
| RSA 3072 | 2 | 0.3 % |

| negotiated | connections | share |
| --- | --: | --: |
| TLSv1.3 | 603 | 83.1 % |
| TLSv1.2 | 123 | 16.9 % |

Would not verify against this machine's trust store with the apex as the hostname: **24** (3.3 %).

| domain | why |
| --- | --- |
| googlevideo.com | verify:Hostname mismatch, certificate is not valid for 'googlevideo.com'. |
| windows.net | verify:Hostname mismatch, certificate is not valid for 'windows.net'. |
| trbcdn.net | verify:Hostname mismatch, certificate is not valid for 'trbcdn.net'. |
| youtube-nocookie.com | verify:Hostname mismatch, certificate is not valid for 'youtube-nocookie.com'. |
| telecid.ru | verify:Hostname mismatch, certificate is not valid for 'telecid.ru'. |
| ailawandorder.com | verify:Hostname mismatch, certificate is not valid for 'ailawandorder.com'. |
| clarity.ms | verify:Hostname mismatch, certificate is not valid for 'clarity.ms'. |
| arubanetworks.com | verify:Hostname mismatch, certificate is not valid for 'arubanetworks.com'. |
| trueconf.net | verify:Hostname mismatch, certificate is not valid for 'trueconf.net'. |
| ezvizlife.com | verify:Hostname mismatch, certificate is not valid for 'ezvizlife.com'. |
| netease.com | verify:Hostname mismatch, certificate is not valid for 'netease.com'. |
| adobe.net | verify:Hostname mismatch, certificate is not valid for 'adobe.net'. |
| eye4.cn | verify:certificate has expired |
| gamepass.com | verify:Hostname mismatch, certificate is not valid for 'gamepass.com'. |
| xboxlive.com | verify:Hostname mismatch, certificate is not valid for 'xboxlive.com'. |
| twc.com | verify:Hostname mismatch, certificate is not valid for 'twc.com'. |
| sberbank.ru | verify:self-signed certificate in certificate chain |
| xiaomi.net | verify:Hostname mismatch, certificate is not valid for 'xiaomi.net'. |
| mhverifier.ru | verify:Hostname mismatch, certificate is not valid for 'mhverifier.ru'. |
| alipaydns.com | verify:Hostname mismatch, certificate is not valid for 'alipaydns.com'. |
| ozone.ru | verify:Hostname mismatch, certificate is not valid for 'ozone.ru'. |
| flashtalking.com | verify:unable to get local issuer certificate |
| presage.io | verify:certificate has expired |
| stbid.ru | verify:Hostname mismatch, certificate is not valid for 'stbid.ru'. |

## Unregistered: who is terminating the TLS

**Not in the plan.** This was added after the issuer counts came back, because the second-largest issuer is a certificate authority most of those sites have never dealt with, and the obvious explanation is measurable rather than guessable. One request per domain, `server` header taken verbatim and folded into families by substring (`serverhdr.py`). A stripped or absent header is `(none)` and is not evidence of anything.

| server header | domains | share |
| --- | --: | --: |
| (none) | 141 | 19.4 % |
| cloudflare | 128 | 17.6 % |
| nginx | 98 | 13.5 % |
| apache | 36 | 5.0 % |
| varnish | 33 | 4.5 % |
| amazons3 | 30 | 4.1 % |
| akamai | 25 | 3.4 % |
| cloudfront | 23 | 3.2 % |
| sffe | 22 | 3.0 % |
| awselb | 20 | 2.8 % |
| server | 16 | 2.2 % |
| bigip | 14 | 1.9 % |

| issuer | the edges its certificates sit behind |
| --- | --- |
| DigiCert | (none) 44, nginx 19, akamai 18, apache 16 |
| Google Trust Services | cloudflare 84, sffe 22, (none) 11, esf 6 |
| Let's Encrypt | nginx 30, cloudflare 29, (none) 25, varnish 11 |
| Amazon | amazons3 26, cloudfront 19, awselb 16, nginx 15 |
| GlobalSign | (none) 14, varnish 13, nginx 9, tengine 8 |
| Sectigo | (none) 11, nginx 10, bigip 6, cloudflare 5 |
| Microsoft | (none) 10, kestrel 8 |
| GoDaddy | nginx 5, (none) 2, bigip 1, server 1 |

