One hub, thirty-one lists
The European Union publishes a list of lists. Each member state, plus Iceland, Liechtenstein, Norway and an archived United Kingdom entry, publishes its own — naming the providers it supervises and the services they are trusted for.
Nothing here is drawn from a document we did not retrieve. Every circle is a file that answered.
Forty-three pointers is not forty-three countries
The hub carries 43 pointers, and that is the number usually quoted. It is not a count of countries. 11 of them point at a human-readable PDF of a list that is already there in machine-processable form, and one points at the hub itself.
The small squares are those PDFs. They matter for the arithmetic: a fault in one list out of forty-three sounds like a rounding error, and the same fault out of thirty-one does not.
One of them has never answered
Ireland's trusted list is declared by the hub and cannot be retrieved by a strict client. The server sends one certificate where two are needed: the intermediate that links it to a trusted root is missing, so verification fails before the file is read.
The certificate does carry a pointer to the missing intermediate. A client willing to go and fetch it — a browser, and as it turns out a content-delivery network too — completes the chain and shows no problem at all. A client that only trusts what the server actually sent gets nothing. We asked from a second vantage point to be sure, and it answered there: the same endpoint, the same moment, two different verdicts.
One is published without transport security at all
Slovakia's pointer is declared over plain http://, and answers there.
The same host over HTTPS presents a certificate for a different name, so the encrypted
path is the one that fails.
This is not the scandal it first looks like. The list carries its own XAdES signature, so its integrity does not depend on the transport. But a client configured to refuse plain HTTP — an increasingly ordinary policy — cannot fetch a national trusted list at all.
There is a second hub, and no edge between them
The Americas publish a regional list of lists in the same ETSI format, under the same standard, covering Argentina, Brazil, Paraguay and Uruguay. Chile appears too — not through the regional hub, but through Argentina's own national list.
Neither hub mentions the other. Not a broken link: no link. A client that knows how to read one has no path to the other, and nothing in either document suggests the other exists.
Four copies, three of them expired
The regional list is served from four addresses across three states. All four answer. All four carry a signature block. Three are byte-for-byte identical at sequence 7, whose declared next update passed 110 days ago; the fourth, in Brazil, is sequence 8 and current.
A signature proves who wrote a document. It does not say whether the document is still the one you should be reading. The only field that separates the current copy from the lapsed ones is the one no rule requires anybody to check.
And then the islands
Some states publish a trusted list that no hub points at. Switzerland, Ukraine, the United Kingdom's live list, Moldova, Serbia. They are reachable, current, and structurally invisible: you find them only if you already know the address.
Ukraine's was reissued the day before this measurement — the freshest list anywhere in the graph, and one nothing points at. Moldova's carries no provider section at all; its single pointer goes back to Brussels. Russia's exists and refuses us specifically, which from one vantage point we cannot distinguish from refusing everyone.
Every one of these lists is somebody's legal obligation to publish. Not one of them is anybody's obligation to check.
That is the finding. The defects are individually small and mostly easy to fix — a missing intermediate, a stale mirror, an unencrypted pointer. What is not small is that they persisted long enough for a first look to find them, in infrastructure whose entire purpose is to be relied upon.