Podcast
Root Causes 202 : What Is Certificate Transparency?


Hosted by
Tim Callan
Chief Compliance Officer
Jason Soroko
Fellow
Original broadcast date
January 27, 2022
Certificate Transparency (CT) is essential to monitoring the public SSL certificates that are issued. In this episode we explain what CT logs are, how they work, and the uses we can put them to.
Podcast Transcript
Lightly edited for flow and brevity.
I have set of certs. I’m using public root, ah, ah, certs and because of that, they are in the CT log and maybe it reveals information about like the structure of my network. Something that might help an attacker who was planning some kind of attack. They understand what to look for. If they managed to penetrate me and they’re moving around laterally, what sorts of things are they trying to discover? There’s no getting around that. I mean, it’s part of transparency. One solution, of course, is don’t use public certs. If you make that private CA, private certs have no place in CT logs. They certainly aren’t logged by public CAs, and other people shouldn’t log them, and if you don’t log them, then that’s fine, it’s not a problem, and then that visibility doesn’t exist. And that seems to me the most straightforward answer that covers most of these cases where this objection occurs.

