Certificates & Proofs / Merkle Tree Workshop

What you will do: Add certificate leaves and build a SHA-256 Merkle tree, generate an inclusion proof for one leaf, verify it and tamper with it, compare handshake sizes, then simulate a Certificate Transparency log.

Worked example: Load 8 sample certs and Build Merkle Tree, generate an inclusion proof for one leaf, then press Auto-Tamper and Verify Tampered: one flipped character makes the computed root diverge and verification fails.

Runtime and privacy: The cryptographic exercise runs in this browser. Review the site privacy terms before entering sensitive material; use synthetic inputs for learning and evaluation.

Browse all Crypto Lab tools · Learn with Merkle Tree Certificates

For your role

Developer / Engineer
Load 8 sample certs or add your own Subject CN leaves, Build Merkle Tree, then walk Inclusion Proof, Verify Proof, Size Comparison and CT Log: the proof for one leaf is the structure a Merkle Tree Certificate carries.
Researcher / Academic
Run the Merkle Tree Certificates Known Answer Tests panel, then use the Size Comparison step to measure a proof against an ML-DSA-44 signature on the same leaf.
Curious Explorer
Add a few certificate names, build the tree at Slow speed, and click a node: you can see how one small proof shows that a certificate is in the tree without listing all the others.

Step 1: Build Tree

Add certificate leaves and build a Merkle tree with SHA-256 hashing.

Interactive Merkle Tree Builder

Add certificate leaves, then build the tree to see SHA-256 hashes computed at each level. Tap (or hover, or focus with the keyboard and press Enter) on any node to see its full hash.

Certificate Leaves (4)

www.example.com
ML-DSA-44
api.example.com
ML-DSA-44
mail.example.org
ML-DSA-65
shop.acme.io
ML-DSA-44
Algorithm:
Build speed:

Merkle Tree Certificates Known Answer Tests

FIPS 180-4 · FIPS 204

Click Run validation tests to run 4 use-case scenarios. Evidence in this set: NIST ACVP-Server reference sample — Expected values copied from the public NIST ACVP-Server repository with immutable source identity.; Functional round-trip — Output produced by an implementation is consumed by the same or paired implementation..

Reference samples from the public NIST ACVP-Server repository · FIPS 180-4 · FIPS 204 · Generated keys are for educational use only.

Try it

Build the tree from 8 leaves and generate an inclusion proof. How many hashes does the proof carry?

Next step

Turn it into a plan: Infrastructure Modernization Planner

This tool practises the Merkle Tree Certificates module, phase 6 (Infrastructure & Performance); Infrastructure Modernization Planner produces a deliverable of that phase.

Next in Certificates & Proofs