Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

What Is Certificate Transparency (CT)?

Certificate Lifecycle Management

Certificate Transparency (CT) is an open framework, defined in RFC 9162, that requires publicly trusted TLS certificates to be logged in public, append-only, cryptographically verifiable logs so that mis-issued or fraudulent certificates can be detected quickly.

Certificate Transparency requires every publicly trusted TLS certificate to be recorded in a public CT log before browsers will accept it. This lets domain owners, security researchers, and monitoring services detect certificates issued for their domain without their knowledge, closing the detection gap that let past CA compromises go unnoticed for months.

Key Takeaways

  • CT is defined in RFC 9162 and requires a Signed Certificate Timestamp (SCT) as proof of logging before major browsers will trust a public TLS certificate.
  • CT logs are append-only and cryptographically verifiable using a Merkle tree structure, meaning no entry can be silently altered or removed once logged.
  • CT was created largely in response to CA compromises like DigiNotar in 2011, where fraudulent certificates went undetected until real damage was done.
  • Domain owners can monitor CT logs for any certificate issued for their domain, catching mis-issuance or unauthorized certificates within hours instead of months.
  • Major browsers, including Chrome, require CT compliance (a valid SCT) for any publicly trusted TLS certificate, effectively making it mandatory for public-facing sites.

How Does a Certificate Transparency Log Work?

  1. A Certificate Authority submits a newly issued certificate, or a pre-certificate, to one or more CT logs.
  2. The log adds the certificate as a new leaf in a Merkle tree structure and returns a Signed Certificate Timestamp (SCT).
  3. The CA embeds the SCT in the final certificate (or delivers it via OCSP stapling or a TLS extension).
  4. When a browser connects to the site, it checks for a valid SCT, confirming the certificate was properly logged.
  5. Anyone, including domain owners and researchers, can query the public log to see every certificate ever issued for a given domain.

Why Was Certificate Transparency Created?

Certificate Transparency emerged largely in response to real CA compromises, most notably the 2011 DigiNotar breach, in which attackers issued fraudulent certificates for major domains that went undetected for weeks. Before CT, there was no reliable way for a domain owner to know if a CA, anywhere in the world, had issued an unauthorized certificate for their domain. CT logs close that blind spot by making every issuance publicly visible and permanently recorded.

How Can Organizations Monitor CT Logs for Their Own Domains?

  • Use a CT monitoring service that watches public logs and alerts on any new certificate issued for a monitored domain.
  • Query CT log search tools directly during incident response to confirm whether an unexpected certificate was legitimately issued.
  • Integrate CT monitoring into a broader certificate lifecycle management platform so mis-issuance alerts sit alongside expiration and renewal tracking.

What can Certificate Transparency Not Protect Against?

CT detects mis-issuance after the fact; it does not prevent a CA from issuing a fraudulent certificate in the first place. It also cannot stop an attacker from using a validly issued certificate they should not have obtained through social engineering or a compromised validation process. CT’s value is speed of detection, turning what used to be a months-long blind spot into something that can surface within hours of issuance.

How Encryption Consulting Helps

How Encryption Consulting HelpsCertSecure Manager includes Certificate Transparency log monitoring alongside expiration tracking, alerting your team the moment an unexpected certificate is issued for a domain you own. Backed by ISO/IEC 27001:2022 and SOC 2 certified practices.

Frequently Asked Questions

Is Certificate Transparency mandatory?

Major browsers, including Chrome, require a valid Signed Certificate Timestamp for any publicly trusted TLS certificate to be accepted, which makes CT logging mandatory in practice for any certificate intended for public-facing use.

Can a certificate be removed from a CT log once it is added?

No. CT logs are append-only and built on a cryptographically verifiable Merkle tree structure, meaning entries cannot be silently altered or deleted once added. This immutability is central to CT’s value as a detection mechanism.

What triggered the creation of Certificate Transparency?

CT was developed largely in response to real CA compromises, most notably the 2011 DigiNotar breach, where attackers issued fraudulent certificates for major domains that went undetected for an extended period, exposing users to undetected man-in-the-middle risk.

How quickly can an organization detect a mis-issued certificate using CT?

With active CT log monitoring in place, an organization can typically detect a newly issued certificate for its domain within hours of issuance, compared to the months it could previously take without any public issuance record to check against.

Monitor Every Certificate Issued for Your Domains

Take the next stepCertSecure Manager combines Certificate Transparency log monitoring with full lifecycle management, so mis-issued certificates are caught within hours, not months. See CertSecure Manager in action.