How long for LE certs to show up on crt.sh?

I am not sure this is really a problem or I am just being impatient, but just in case ...

I am wondering how long it should take from certificate issuance by LE until the certificate shows up on https://crt.sh. I was under the vague impression that this should be on the order of 1-2 days based on some of the documents I read about certificate transparency logs. I admit that I'm a little hazy on how the certificate logs make it to where crt.sh has access to them.

The reason I ask is that one of the certificates at our site, https://www.atd.net, renewed on Friday (December 29th) and it has not appeared yet on crt.sh; I would have thought that after 5 days it would be there but it does not seem to be. I wouldn't normally say anything but it seems like a lot of people use crt.sh as an authoritative source for certificate info so I'm just curious as to the normal delay time there. If 5 days is a normal delay time, that's fine with me; I just want to know what to expect.

1 Like

Hello @kenh1, welcome to the Let's Encrypt community. :slightly_smiling_face:

There is https://accounts.censys.io/login as well to check issued certificates, however you must create an account (free).

1 Like

@kenh1 Fair question. crt.sh reliability has been poor this past year. Usually within 24 hours is expected but there have been longer delays for various reasons.

There are other suppliers of CT lists though such as search.censys.io which is very prompt but requires an account. A free account gives (I think) 250 queries / month through their UI

There is also a service below which has been very quick every time I have used it this year but that has not been often (I have been using censys mostly). You will find your cert on both of these

https://ui.ctsearch.entrust.com/ui/ctsearchui

3 Likes

Here is what I see https://search.censys.io/search?resource=certificates&sort=RELEVANCE&per_page=25&virtual_hosts=EXCLUDE&q=www.atd.net
And the issued certificate https://search.censys.io/certificates/db7621491789def30c01f6cf38cb69aff9f11eba00f58fa50b8349b8597e012e

1 Like

crt.sh has had some problems lately, so I'm not surprised it's behind.

I put together a list of other CT search resources in this thread for people (which others are free to update and improve):

7 Likes

Great list @petercooperjr

I wasn't sure how to note this in your wiki but the censys.io free account only allows access to the API for 60 days now. They just announced this last month. The free account still allows 250 queries / month using their website UI. The UI allows complex searches but comes with the matching learning curve :slight_smile:

3 Likes

Thanks for the info, and the pointer to other CT log search tools! Glad to know it's not just me.

6 Likes

You can see the crt.sh backlog, if any, at crt.sh | monitored-logs.

6 Likes

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.