# Putting certificate transparency to use

**URL:** <https://community.letsencrypt.org/t/putting-certificate-transparency-to-use/77445>\
**Category:** Server\
**Created:** [November 13, 2018, 11:42pm UTC](https://community.letsencrypt.org/t/putting-certificate-transparency-to-use/77445 "2018-11-13T23:42:22Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![DanCvrcek](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/dancvrcek/32/35672_2.png) [@DanCvrcek](https://community.letsencrypt.org/u/DanCvrcek)\
**Post date:** [November 13, 2018, 11:42pm UTC](https://community.letsencrypt.org/t/putting-certificate-transparency-to-use/77445/1 "2018-11-13T23:42:23Z")

</div>

[The following tool is used as an entry point for monitoring certificate expiration, which is useful for checking your servers are in good shape.]

People have realized that certificate transparency - logs of all issued certificates - can be used to find hidden domains. So far, all sources required some level of programming.

This time, you can just keep typing domain names and see what you can find.

> **[Certificate expiry monitoring, KeyChest for HTTPS, TLS, Letsencrypt expiry and...](https://keychest.net/)**
>
> KeyChest - certificate expiry monitor, server status checker for TLS, HTTPS, Letsencrypt, with free cloud service. Automatic monitoring of subdomain servers as they are set up.

If you feel geeky, you can start with “\>” and search with domain name parts reversed. For example, if you want to find what’s under [teslamotors.com](http://teslamotors.com), you type “\>[com.teslamotors.cn](http://com.teslamotors.cn)” … etc.

You can also have a look at this 50s video before you try for yourself.

https://player.vimeo.com/video/300546272?app_id=122963

---

<div class="post-metadata">

**Author:** ![stevenzhu](https://sea3.discourse-cdn.com/letsencrypt/user_avatar/community.letsencrypt.org/stevenzhu/32/18864_2.png) [@stevenzhu](https://community.letsencrypt.org/u/stevenzhu)\
**Post date:** [November 14, 2018, 12:51am UTC](https://community.letsencrypt.org/t/putting-certificate-transparency-to-use/77445/2 "2018-11-14T00:51:14Z")

</div>

If you want to just do domain search… I think crt.sh has done a great job so far (despite the huge backlog and server scaling issues)

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/letsencrypt/original/3X/c/a/ca6c06ea1ea201324bba7048c6841ce60236468d.png) [@system](https://community.letsencrypt.org/u/system)\
**Post date:** [December 14, 2018, 1:00am UTC](https://community.letsencrypt.org/t/putting-certificate-transparency-to-use/77445/3 "2018-12-14T01:00:01Z")

</div>

This topic was automatically closed 30 days after the last reply. New replies are no longer allowed.
