Rustls 0.23.44 Released With ML-DSA Certificates Enabled By Default

Written by Michael Larabel in Programming on 7 September 2026 at 05:59 AM EDT. 1 Comment
PROGRAMMING
Rustls as the modern TLS library implementation written in the Rust programming language is out with a new feature release. This morning's Rustls 0.23.44 release enables post-quantum secure ML-DSA certificates by default.

The headline feature of Rustls 0.23.44 is enabling post-quantum secure ML-DSA certificates by default with the aws-lc-rs crypto provider. ML-DSA certificates aren't supported in the public web PKI but can be used with private certificate hierarchies. Module-Lattice-Based Digital Signature Algorithm (ML-DSA) continues seeing nice adoption as a replacement to the likes of RSA and ECDSA while boasting fast key generation / signing / verification speeds and being secure against quantum computer attacks.

Rustls gets ML-DSA by default


The other notable change in this new release is the SSL key log file now being restricted to read-only by the owner (owner-only permissions).

Downloads and more details on this updated Rust TLS library via GitHub.
Related News
About The Author

Michael Larabel is the principal author of Phoronix.com and founded the site in 2004 with a focus on enriching the Linux hardware experience. Michael has written more than 20,000 articles covering the state of Linux hardware support, Linux performance, graphics drivers, and other topics. Michael is also the lead developer of the Phoronix Test Suite, Phoromatic, and OpenBenchmarking.org automated benchmarking software. He can be followed via Twitter, LinkedIn, or contacted via MichaelLarabel.com.

Popular News This Week