This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Radar · Go · Archive · Week 33 · Aug 11 – 17, 2025

x/crypto/x509roots/fallback: export certificate bundle

Worth knowingecosystem

What changed
A new golang.org/x/crypto/x509roots/fallback/bundle package was added that exposes the NSS trust store root certificates as a read‑only sequence of Root values.
Production impact
The source does not say.
Try it
Import the package and iterate over bundle.Roots() to list the DER‑encoded certificates.
Source
github.com/golang/go/issues/69898

Understand it, then run it

The Go standard library can verify TLS certificates, but it needs a list of trusted root certificates. On Linux the list comes from the NSS trust store, and Go ships a copy of that list inside the x/crypto/x509roots package. Before this change that list was only used internally; you could not access it from your own code. Now a new golang.org/x/crypto/x509roots/fallback/bundle package exposes the bundle as a read‑only sequence of Root values, so you can read the DER bytes of each root certificate.

Written by gpt-oss-20b from the linked source · claims checked against the sources · archive, not individually reviewed