IT lexicon Security Certificate Transparency

Certificate Transparency

Security På svenska → Updated: 2026-05-27

Public append-only logs of all issued TLS certificates. Lets domain owners detect mis-issued certificates against their domain. Launched after the DigiNotar incident in 2011, RFC 6962 (2013). Chrome has required CT logging since 2018.

CT logs are operated by Google, Cloudflare, Let's Encrypt and others. The CA receives a Signed Certificate Timestamp (SCT) as proof of logging, embedded in the cert or delivered via OCSP. Tools: crt.sh is a search engine over all logs — useful for recon (what subdomains exist?). Domain monitoring: services like Facebook CT Monitor, Cert Spotter notify on a new cert for your domain. Wildcard certs show up too. Failed CT logging blocks new certs in Chrome.

← Back to the lexicon