Certificate Transparency Logs Can Reveal Unauthorized TLS Certs Issued for Your Domain
A valid, browser-trusted TLS certificate can be issued for your domain without your knowledge through DNS compromises, subdomain takeovers, or stale third-party access — and standard uptime or SSL monitors will never detect it. Certificate Transparency (CT), defined in RFC 6962, is a public, append-only, cryptographically verifiable record where every certificate authority must log certificates before browsers will trust them. Since 2018, Chrome, Safari, and other major browsers reject any publicly-trusted certificate that lacks a signed certificate timestamp proving it was logged, meaning every working certificate is effectively a public announcement. This architecture reverses the usual security asymmetry: instead of monitoring every CA or DNS provider, domain owners can simply watch the CT logs for any certificate bearing their domain name. Free tools like crt.sh allow anyone to search these logs without an account, making unauthorized certificate discovery accessible to any security team.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in