SSL Certificate Transparency (CT) is a public system in which all issued SSL certificates are logged in searchable, cryptographically secured logs. This allows anyone to verify which certificates have been issued for a domain, including by unauthorized or malfunctioning certificate authorities. Browsers such as Chrome require CT for publicly trusted certificates. This article explains exactly what CT does, how it works, and what it means for website administrators.
What exactly is Certificate Transparency
Certificate Transparency is a standard that ensures every SSL/TLS certificate issuance becomes publicly visible in independent logs. In the past, certificate authorities (CAs) could issue certificates without the domain owner being aware of it. This previously led to incidents in which certificates were wrongly issued for well-known domains, which could be exploited for phishing or man-in-the-middle attacks.
With CT, every new certificate is added to one or more public logs. These logs are append-only: once data has been added, it can no longer be removed or altered. This makes the system reliable and verifiable for everyone, from security researchers to domain owners themselves.
How the system works
When a certificate authority issues an SSL certificate, it sends the certificate data to one or more CT logs. The log returns what is known as a Signed Certificate Timestamp (SCT), cryptographic proof that the certificate has been registered. This SCT is then delivered along with the certificate, for example embedded in the certificate itself or via a TLS extension.
Modern browsers check, when establishing a secure connection, whether valid SCTs are present. If this proof is missing, the browser may display a warning or mark the connection as untrusted. This way, CT is automatically enforced without a website visitor noticing anything, as long as the certificate has been issued correctly.
Why this matters for your website
For domain owners, CT offers the ability to see whether certificates have been unexpectedly issued for their domain. This is relevant, for example, if someone gains access to part of your infrastructure and requests a certificate without your knowledge. By monitoring CT logs, you’ll quickly notice this and can take action, such as revoking the unwanted certificate.
In addition, CT is now a strict requirement from major browsers for publicly trusted certificates. A certificate without valid CT proof simply won’t be recognized as secure. This means that as a website administrator, you don’t need to do much yourself: as long as your certificates are issued through a recognized CA, logging happens automatically.
Checking CT logs yourself
You can easily check which certificates are listed in CT logs for your own domain. There are online search services where you can search by domain name and immediately see which certificates were issued when, by which CA, and with what validity period. This is useful for detecting outdated or unknown certificates.
Look up your domain name
Use a CT log search service and enter your domain name to see all registered certificates.
Check the issuing party
If you don’t recognize the certificate authority or the validity period seems off, investigate further.
Repeat this periodically
Check your CT logs regularly, especially for domains with multiple subdomains or changing administrators.
Take action on discrepancies
If you find an unknown certificate, contact your hosting provider or CA to have the certificate revoked.
If you manage your email and website with the same provider, it’s also wise to pay attention to the security of your business email, since email traffic is often secured separately from website traffic. If you’re considering switching to a provider that handles this properly by default, check out the options for switching to Tandata.
Frequently Asked Questions
Do I need to configure anything myself for Certificate Transparency?
No, CT is automatically handled by the certificate authority and the browser. You don’t need to configure anything as a website administrator.
Can I see which certificates have been issued for my domain?
Yes, you can use public CT log search services to search by domain name and view all registered certificates.
What happens if a certificate isn’t in a CT log?
Modern browsers will then not trust the certificate and will display a warning or block the connection.
Does Certificate Transparency affect my website’s speed?
No, the SCT check happens extremely fast during the setup of the secure connection and is not noticeable to visitors.
Does Certificate Transparency also apply to free SSL certificates?
Yes, free certificates from recognized CAs are also logged in CT logs, just like paid certificates.
Conclusion
Certificate Transparency ensures that SSL certificates are publicly verifiable, which helps expose misuse and unauthorized certificate issuance sooner. As a website administrator, you don’t need to do much, as long as your certificates are issued through a recognized CA. Want this handled automatically, including free SSL and reliable issuance? Check out our web hosting or the knowledge base for more background information.