Home

Chrome Root Program

Chrome Quantum-resistant Root Program

Frequently Asked Questions

Does Chrome support use of ML-DSA certificates?

Yes. Beginning in Chrome 150, Chrome supports ML-DSA in private PKI hierarchies, making it possible to test non-MTC post-quantum X.509 certificates locally or within enterprise environments.

Why does Chrome not support ML-DSA in the Chrome Quantum-resistant Root Store?

Post-quantum cryptographic algorithms such as ML-DSA feature significantly larger key and signature sizes than classical algorithms (like RSA or ECDSA). In a traditional PKI model using X.509 certificates, sending heavy, serialized chains of post-quantum signatures and Certificate Transparency (CT) proofs during every TLS handshake creates severe bandwidth penalties and increases connection latency across the web.

Instead of traditional X.509 chains, Chrome uses Merkle Tree Certificates (MTCs) developed in the IETF PLANTS working group:

When will MTCs be usable in Chrome?

Chrome's rollout of Merkle Tree Certificates spans three distinct phases: