demo.mtcs.dev — TAI & MTCs Not Enabled

WebPKI Fallback Served

Your browser connected without negotiating TLS Trust Anchor IDs (trust_anchors extension) or did not advertise a matching Merkle Tree Certificate (MTC) landmark group ID. To prevent SSL connection errors on standard browsers, the server served a standard Let’s Encrypt WebPKI certificate instead of the compact Landmark-Relative MTC.

How to Enable Trust Anchor IDs (TAI) & MTCs in Chrome

  1. Enable TLS Trust Anchor IDs: Open chrome://flags/#tls-trust-anchor-ids in a new tab and set TLS Trust Anchor IDs to Enabled.
  2. Enable Verify MTCs: Open chrome://flags/#verify-mtcs and set Verify MTCs to Enabled.
  3. Relaunch Chrome: Click the Relaunch button at the bottom of the flags page.
  4. Ensure PKI Metadata is Up to Date: Open chrome://components, locate PKI Metadata (or PKI Metadata Fastpush), and click Check for update so your browser has the latest MTC landmark group trust anchors.
  5. Reload this page: Reload https://demo.mtcs.dev/ (or open in a new Incognito window / flush sockets at chrome://net-internals/#sockets to establish a new TLS connection). Once TAI is negotiated, this page will automatically display the full MTC certificate dashboard!

Command-line alternative: Launch Chrome directly with:
google-chrome --enable-features=TLSTrustAnchorIDs,VerifyMTCs https://demo.mtcs.dev/

Fallback Certificate (No TAI Match)

Standalone MTC

Served when client does not send trust_anchors or does not advertise 11129.11.99.1.1.1.542

Proof Subtree [173120, 173121) · 0 node(s) inclusion proof
Cosigner Signatures 2 signature(s)
11129.11.99.1 (CA, 2420 B ML-DSA-44)
11129.11.99.2 (Mirror, 2420 B ML-DSA-44)

cactus-cli cert text (Standalone Fallback — demo.mtcs.dev-standalone.crt)

Merkle Tree Certificate
  serial:     281474976883776 (log number 1, entry index 173120)
  version:    v3
  issuer:     trustAnchorID=11129.11.99.1
  not before: 2026-09-15T20:15:33Z
  not after:  2026-09-22T20:15:33Z
  subject:    CN=demo.mtcs.dev
  spki alg:   ecPublicKey (1.2.840.10045.2.1)
  spki hash:  095d8cfe152fd7a7a4d1ba1fc795312aee492953615962570071d8e03d221911 (sha-256)
  extensions:
    2.5.29.17 subjectAltName  DNS:demo.mtcs.dev
  MTC proof:
    form:            standalone (cosigner-signed subtree)
    subtree:         [173120, 173121)
    inclusion proof: 0 node(s)
    signatures:      2
      - cosigner 11129.11.99.1 (2420-byte signature)
      - cosigner 11129.11.99.2 (2420-byte signature)