An update on upki
Summary
Ubuntu's Canonical team provides an in-depth update on upki, a Linux PKI project using CRLite-based revocation data to secure system utilities and runtimes. The post covers architecture, how to try the early code, and upcoming steps including performance benchmarking and a path toward production deployment, with CT enforcement and Merkle Tree Certificates as future directions.