Radar · Go · Archive · Week 33 · Aug 11 – 17, 2025
x/crypto/x509roots/fallback: export certificate bundle
Worth knowingecosystem
- What changed
- A new
golang.org/x/crypto/x509roots/fallback/bundlepackage was added that exposes the NSS trust store root certificates as a read‑only sequence ofRootvalues. - Production impact
- The source does not say.
- Try it
- Import the package and iterate over
bundle.Roots()to list the DER‑encoded certificates. - Source
- github.com/golang/go/issues/69898
Understand it, then run it
The Go standard library can verify TLS certificates, but it needs a list of trusted root certificates. On Linux the list comes from the NSS trust store, and Go ships a copy of that list inside the x/crypto/x509roots package. Before this change that list was only used internally; you could not access it from your own code. Now a new golang.org/x/crypto/x509roots/fallback/bundle package exposes the bundle as a read‑only sequence of Root values, so you can read the DER bytes of each root certificate.
Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed