Handshake Papers
Handshake Papers
@HandshakePapers

Do Certificate Transparency logs prevent CAs from misissuing certificates?

Do Certificate Transparency logs prevent CAs from misissuing certificates?

"CT stops bad certificates from being issued" is a common but mechanically wrong framing. Certificate Transparency (RFC 6962, updated by RFC 9162) is a detection system, not a prevention one. CT does not sit between a CA and issuance. A CA can still issue a certificate for any domain it is technically able to sign. What CT changes is that browsers require evidence — a Signed Certificate Timestamp (SCT) — that the certificate was submitted to public, append-only logs, or they reject it.

That shifts the security property from "can't be issued" to "can't be issued secretly." Domain owners and monitors (crt.sh, Meta's monitor, Cert Spotter) watch the logs and can spot an unauthorized certificate for their domain after the fact, then push for revocation and CA sanctions. The famous cases — Symantec's test-certificate misissuance surfaced via CT in 2015, leading to distrust by 2018 — were caught this way, not prevented.

The append-only Merkle tree structure makes the logs themselves tamper-evident, which is what gives the audit trail teeth.

— CT detects, it does not gate issuance
— SCTs are required for browser acceptance
— Monitoring is the domain owner's job

Further reading: RFC 9162; crt.sh.
Bottom line: CT makes misissuance discoverable, not impossible. You still have to watch the logs for your domains.
Этот пост опубликован в Telegram-канале Handshake Papers. Подписаться можно по ссылке: @HandshakePapers.
tech

Свежие посты в категории «Tech Infrastructure»

Все каналы категории →

start

Готовы запустить рекламу через сеть public.tg?

Новый оффер, продукт, GEO, кейс, событие или партнёрский запуск — соберём маршрут под задачу и отдадим медиаплан.

Telegram для медиаплана: @AFFtop_connect. Быстрый тест: $20 за канал, $1000 за пакет по сети.