# I want to create a certificate transparency server

**URL:** <https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892>\
**Category:** Client dev\
**Created:** [September 17, 2020, 8:20am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892 "2020-09-17T08:20:59Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![syuu\_22397](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/syuu_22397/32/40573_2.png) [@syuu\_22397](https://community.letsencrypt.org/u/syuu_22397)\
**Post date:** [September 17, 2020, 8:20am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/1 "2020-09-17T08:20:59Z")

</div>

I’m thinking of creating a certificate transparency server.  
I’m thinking of making the OS with CentOS or Debian.  
How do I create a detailed certificate transparency server?

---

<div class="post-metadata">

**Author:** ![griffin](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/griffin/32/50204_2.png) [@griffin](https://community.letsencrypt.org/u/griffin)\
**Post date:** [September 17, 2020, 8:23am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/2 "2020-09-17T08:23:22Z")

</div>

Not exactly sure. What’s your goal compared to something like [https://crt.sh](https://crt.sh)?

---

<div class="post-metadata">

**Author:** ![syuu\_22397](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/syuu_22397/32/40573_2.png) [@syuu\_22397](https://community.letsencrypt.org/u/syuu_22397)\
**Post date:** [September 17, 2020, 8:31am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/3 "2020-09-17T08:31:59Z")

</div>

I create a certificate transparency server and publish it for myself.  
It may not make much sense, but I’m thinking about that.  
In terms of functionality, I would like to create something similar to [https://crt.sh](https://crt.sh).

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [September 17, 2020, 8:34am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/4 "2020-09-17T08:34:10Z")

</div>

Hi @syuu_22397

> [@syuu\_22397](#):
>
> I would like to create something similar to [https://crt.sh](https://crt.sh).

then this forum is the wrong place.

That's not a Letsencrypt relevant question.

Thanks!

---

<div class="post-metadata">

**Author:** ![syuu\_22397](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/syuu_22397/32/40573_2.png) [@syuu\_22397](https://community.letsencrypt.org/u/syuu_22397)\
**Post date:** [September 17, 2020, 8:38am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/5 "2020-09-17T08:38:34Z")

</div>

When I saw that Let’s Encrypt was used to create a certificate transparency server, I thought it was related to Let’s Encrypt.  
excuse me.

---

<div class="post-metadata">

**Author:** ![JuergenAuer](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/juergenauer/32/26491_2.png) [@JuergenAuer](https://community.letsencrypt.org/u/JuergenAuer)\
**Post date:** [September 17, 2020, 8:58am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/6 "2020-09-17T08:58:55Z")

</div>

> [@syuu\_22397](#):
>
> When I saw that Let’s Encrypt was used to create a certificate transparency server

Letsencrypt doesn't run something like crt.sh.

crt.sh is a Certificate monitor, that checks certificate logs.

Letsencrypt runs an own certificate log. But who should fill your (private) certificate log?

PS: "Certificate transparency server" isn't defined.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [September 17, 2020, 9:24am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/7 "2020-09-17T09:24:09Z")

</div>

I have a little bit of experience making my own log aggregator, similar to crt.sh.

It requires an enormous amount of disk space and bandwidth, to say the least. I don’t actually store the certificates, just the domain names, and the date when I first observed them. Otherwise, I would easily go broke paying for the infrastructure.

The basic principle is:

- Download [https://www.gstatic.com/ct/log\_list/log\_list.json](https://www.gstatic.com/ct/log_list/log_list.json)
- For each active log in that list, use an RFC6962 client to scan the entire log, and copy each DER-encoded certificate, along with any data you want to index, into your database.
- Every few minutes or so, check each log whether there have been any new entries. If so, scan the log again, starting from the index you scanned upto last time.
- You’re done! Make a web frontend to query your database.

I used [https://github.com/google/certificate-transparency-go](https://github.com/google/certificate-transparency-go) to help me, but there’s probably some other options. I noticed it’s quite CPU-intensive for some reason, but I didn’t really look into why, and didn’t want to write an RFC6962 client by myself just to be more efficient.

---

<div class="post-metadata">

**Author:** ![syuu\_22397](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/syuu_22397/32/40573_2.png) [@syuu\_22397](https://community.letsencrypt.org/u/syuu_22397)\
**Post date:** [September 17, 2020, 10:05am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/8 "2020-09-17T10:05:59Z")

</div>

Is it possible to tell me more about how to do it if possible?

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [September 17, 2020, 10:21am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/9 "2020-09-17T10:21:26Z")

</div>

Probably not? It’s not a terribly common project, so it’s not like people have written it up in a step-by-step way that you can just download and run.

I mean, I can show you all the parts to the little aggregator I created 3 years ago. [The log scanning and database insertion program](https://github.com/ausdomainledger/scanner) (which is the important bit), the [web API](https://github.com/ausdomainledger/web), the [HTML frontend](https://github.com/ausdomainledger/fe) and the [actual live thing](https://ausdomainledger.net/?q=%25.gov.au).

All of crt.sh [is open source as well](https://github.com/crtsh).

But I don’t think it’s the case that you can download either and be up and running in a hot minute. Best to start simple.

Or forget about the whole thing, and figure out a different way to achieve your objectives. For example, there is raw database access to the crt.sh database available, which is a very powerful free resource.

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [September 17, 2020, 10:44am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/10 "2020-09-17T10:44:13Z")

</div>

> [@syuu\_22397](#):
>
> When I saw that Let’s Encrypt was used to create a certificate transparency server

I think this needs to be corrected. It isn't the case that "Let's Encrypt was used to create a certificate transparency server." Rather, ISRG (who operates the Let's Encrypt service) also runs a certificate transparency server. That's the only connection between the two--they're independent services run by the same organization.

As a second point, crt.sh is **not** a certificate transparency server; it's an aggregator. They collect transparency information from the actual transparency logs, and give you a searchable front-end for it.

Why do you want to do this? Is it just as a hobby project, just to do it? If so, well, you've got a lot to figure out on your own, and your apparent request for detailed, step-by-step instructions doesn't seem entirely consistent. Or do you think you actually need it for some purpose? If so, what purpose?

---

<div class="post-metadata">

**Author:** ![syuu\_22397](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/syuu_22397/32/40573_2.png) [@syuu\_22397](https://community.letsencrypt.org/u/syuu_22397)\
**Post date:** [September 17, 2020, 11:05am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/11 "2020-09-17T11:05:24Z")

</div>

I’m thinking of adding certificate transparency to the certificate authority I run.

---

<div class="post-metadata">

**Author:** ![\_az](https://avatars.discourse-cdn.com/v4/letter/_/22d042/32.png) [@\_az](https://community.letsencrypt.org/u/_az)\
**Post date:** [September 17, 2020, 11:13am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/12 "2020-09-17T11:13:05Z")

</div>

Do you know if you will run your own log, or submit your certificates to logs operated by third-parties?

You can find a guide to running a CT log [here](https://github.com/google/certificate-transparency-go/blob/master/trillian/docs/ManualDeployment.md).

But a better first step might be getting your CA to publish certificates to an existing log.

---

<div class="post-metadata">

**Author:** ![syuu\_22397](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/syuu_22397/32/40573_2.png) [@syuu\_22397](https://community.letsencrypt.org/u/syuu_22397)\
**Post date:** [September 17, 2020, 11:32am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/14 "2020-09-17T11:32:21Z")

</div>

> [@\_az](#):
>
> Do you know if you will run your own log, or submit your certificates to logs operated by third-parties?

Submitting a certificate to a log run by a third party can seem very difficult, but what does it really look like?

---

<div class="post-metadata">

**Author:** ![danb35](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/danb35/32/70869_2.png) [@danb35](https://community.letsencrypt.org/u/danb35)\
**Post date:** [September 17, 2020, 11:47am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/15 "2020-09-17T11:47:01Z")

</div>

> [@syuu\_22397](#):
>
> I’m thinking of adding certificate transparency to the certificate authority I run.

Again, why? If it's a matter of clearing browser warnings, that will only happen if it's in a trusted log. And unless you're operating a publicly-trusted CA (which seems doubtful), public CT logs won't accept your certs. If you **are** somehow running a trusted CA that isn't yet logging certs, it looks like there's a standard API for submission. Here's a short script that demonstrates it:

> <https://gist.github.com/rraptorr/2efaaf21caaf6574e8ff>

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [October 17, 2020, 11:47am UTC](https://community.letsencrypt.org/t/i-want-to-create-a-certificate-transparency-server/133892/16 "2020-10-17T11:47:12Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
