Duplicates in CT logs. Precertificate vs. Leaf certificate

Your first and third question were already answered, so I'll take your second one:

For you, yes they are required. There's no way for you to get a certificate from Let's Encrypt (and most other certificate authorities) without them.

For Let's Encrypt, no, they don't necessarily have to submit them. But if they didn't, everyone would be forced to set up OCSP stapling or compile and install an extra extension into their Apache and nginx servers to comply with Google Chrome's new Certificate Transparency requirements, or their sites would not work in recent versions of Google Chrome.

That's a lot of work, which is why most CAs, including Let's Encrypt, have gone the precertificate/SCT route, so end users don't have to do anything they didn't do before to comply with these new requirements.

1 Like