Certificate Transparency: crt.sh ok, but still not working?

If you want to track progress on the first method mentioned by @Osiris, you can subscribe to this GitHub issue:

Once this has been implemented and deployed, you’ll benefit from this starting with your next renewal, no other changes necessary.

Browsers currently do not mandate or enforce Certificate Transparency in general, with only a small number of exceptions for CAs with a bad track record (Let’s Encrypt not being one of those :wink:), so I would personally not invest too much time in trying to get SCT delivery via TLS extension to work. By the time Google (and others) decide to enforce CT for all CAs (which I’m sure would be announced with significant lead time), I have no doubt that embedded SCT receipts will have landed.