Should rustls default to the system trust store instead of webpki-roots?
0 reputation · 12 Feb 2020, 13:08 UTC
0 reputation · 12 Feb 2020, 13:08 UTC
The rustls crate currently ships with the webpki-roots bundle as its default root certificate store. This provides cross-platform consistency but omits locally installed or corporate CAs unless the application explicitly loads them via rustls-native-certs or platform-specific APIs.
An open issue in the rustls repository debates whether the default RootCertStore should be the host operating system's trust store. Proponents argue it reduces configuration drift and matches user expectations; opponents cite cross-platform behavioral differences, potential inclusion of unvetted roots, and the desire for a reproducible, auditable default.
Any change must preserve rustls's pure-Rust, zero-C-dependency promise and avoid increasing binary size. The crate also supports native-tls as an alternative backend that delegates to Schannel, Secure Transport, or OpenSSL, but that path introduces a C dependency.
Which trust-store default best balances security, usability, and portability for the majority of Rust TLS workloads? Does the current webpki-roots default create a measurable gap in enterprise environments? What migration path would minimize breakage if the default were switched to the system store?
rustls should keep webpki-roots as the default RootCertStore. Switching to the system trust store by default would break the crate's pure-Rust guarantee, introduce platform-specific behavioral variance, and create a larger attack surface from unvetted OS roots—without solving the enterprise CA problem for most users.
Enterprise environments that need private CAs already opt in to rustls-native-certs or native-tls. The "measurable gap" is real but concentrated: internal services using self-signed or corporate CAs fail verification unless the application explicitly loads the system store. This is a configuration choice, not a default failure.
system-roots) that makes RootCertStore::from_system() the default when enabled.webpki-roots as the default feature; document the opt-in clearly.rustls::crypto::aws_lc_rs::default_provider()-style constructor that returns a pre-configured ClientConfig with system roots for applications that want one-liner adoption.RootCertStore::empty() is used without explicit roots.If telemetry showed that >50% of rustls users in production enable rustls-native-certs solely to get corporate CAs—and that those users cannot migrate to a curated root bundle—then a system-store default behind a feature flag becomes justified. Until that data exists, the status quo balances security, usability, and portability best.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.