One hub, thirty-one lists
The European Union publishes a list of lists. Each member state, plus Iceland, Liechtenstein, Norway and an archived United Kingdom entry, publishes its own — naming the providers it supervises and the services they are trusted for.
Nothing here is drawn from a document we did not retrieve. Every circle is a file that answered.
Forty-three pointers is not forty-three countries
The hub carries 43 pointers, and that is the number usually quoted. It is not a count of countries. 11 of them point at a human-readable PDF of a list that is already there in machine-processable form, and one points at the hub itself.
The small squares are those PDFs. They matter for the arithmetic: a fault in one list out of forty-three sounds like a rounding error, and the same fault out of thirty-one does not.
One of them had never answered — until this morning
Ireland's trusted list is declared by the hub, and for twenty-five consecutive observations a strict client could not retrieve it. The server sent one certificate where two are needed: the intermediate linking it to a trusted root was missing, so verification failed before the file was ever read.
The operator was told. On the twenty-sixth observation the intermediate was there, the chain verified, and the list came down clean. That is the outcome this instrument exists to produce, and it is the reason a series matters more than a snapshot: the defect and its repair are both in the record, and neither is a screenshot.
One is published without transport security at all
Slovakia's pointer is declared over plain http://, and answers there.
The same host over HTTPS presents a certificate for a different name, so the encrypted
path is the one that fails.
This is not the scandal it first looks like. The list carries its own XAdES signature, so its integrity does not depend on the transport. But a client configured to refuse plain HTTP — an increasingly ordinary policy — cannot fetch a national trusted list at all.
There is a second hub, and no edge between them
The Americas publish a regional list of lists in the same ETSI format, under the same standard, covering Argentina, Brazil, Paraguay and Uruguay. Chile appears too — not through the regional hub, but through Argentina's own national list.
The two hubs do not mention each other. Not a broken link: no link. A client that knows how to read one has no path to the other.
But the disconnection is not symmetrical, and that took a second bloc to see. The
Pacific Alliance — Chile, Colombia, Mexico, Peru — publishes four lists in the same
format that do declare a pointer out, and it names an
ec.europa.eu address as the list of lists for territory
“AP”. It redirects to the European one. Four Latin American states have
been declaring Brussels as their own regional hub since 2019, and Brussels has never
pointed back.
Four copies, three of them expired
The regional list is served from four addresses across three states. All four answer. All four carry a signature block. Three are byte-for-byte identical at sequence 7, whose declared next update passed 110 days ago; the fourth, in Brazil, is sequence 8 and current.
A signature proves who wrote a document. It does not say whether the document is still the one you should be reading. The only field that separates the current copy from the lapsed ones is the one no rule requires anybody to check.
And then the islands — and a hub nobody arrives at
Some states publish a trusted list that no hub points at: Switzerland, the United Kingdom's live list, Serbia, North Macedonia, and Ukraine's national list — which was reissued the day before this measurement and is the freshest list anywhere in the graph. They are reachable and structurally invisible: you find them only if you already know the address.
We had Moldova and Ukraine in that group, and we were wrong. The European Union publishes a second list of lists, for mutual-recognition agreements, and it points at both. The first list of lists does not mention the second, so a crawl that starts at the famous hub — which is every crawl — never arrives. Ukraine appears twice and the EU points at the other one: a separate, EU-facing list with ten providers rather than the national list's twenty-one.
What states publish when they publish no list
Most of the world does not publish a trusted list at all. What it publishes instead is a root certificate: the anchor itself, offered for download, with no statement about who else the state vouches for. Thirteen root distribution points from twelve states are drawn here as diamonds — from Argentina, India and Japan to Qatar, Russia, Taiwan and the United States — and two of them, Vietnam's and Bangladesh's, fail TLS validation to a strict client from both of our vantages. The defect that opened this page wearing a different flag.
They are deliberately joined to nothing. A trusted list is a claim about others; a root is a claim about yourself, and no pointer graph connects the two. Counting them together with the lists would produce a bigger number and a worse one.
One state sits between the two categories. South Korea publishes a genuine machine-readable national list — but as a sequence-numbered Microsoft-format certificate trust list and a JSON register, not as the European XML. It is drawn dashed, in its own population, because its register mixes test and development hierarchies in with the production ones — twelve of forty-two — and no status field marks which is which: only the names betray them.
SchemeTerritory to read.Every one of these lists is somebody's legal obligation to publish. Not one of them is anybody's obligation to check.
That is the finding. The defects are individually small and mostly easy to fix — a missing intermediate, a stale mirror, an unencrypted pointer. What is not small is that they persisted long enough for a first look to find them, in infrastructure whose entire purpose is to be relied upon.