Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

CT doesn't seem that transparent. crt.sh only shows the certificate for one of my domains, despite them all having certs issued by the same CA on the same day. Go figure.


I'm assuming we're talking about CAs other than Let's Encrypt? In which case this is expected; not many CAs currently submit all their certificates to CT logs. It's only mandatory for EV certificates. The biggest source for Google's CT log servers is probably Googlebot, so unless your site is publicly available and crawlable, this is nothing unusual.


Interesting. Are you comfortable with mentioning the domain name(s) here?

And for the record, here is the millionth LE cert in all its glory: https://crt.sh/?id=14392504


> Are you comfortable with mentioning the domain name(s) here?

Not to just anyone, no. The certificates aren't all in service for HTTPS, which might explain some of it, but I don't know.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: