We’re planning to submit certificates to CT logs, which we think is the most important part: being transparent and open about the certificates we issue, and allowing the public to research and analyze them. If we provide SCTs, it would be via OCSP, definitely not by X.509v3 extension. But we’re not yet sure if we’ll provide SCTs via OCSP at launch. In particular, necessary support for OCSP extensions seems to be absent from Golang. However, subscribers who want to provide SCTs with their certificates should be able to fetch them directly from the CT logs and provide them via TLS extension.
jsha
2
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Apt repository and SCT support | 3 | 3252 | September 2, 2015 | |
| Generate a certificate without Certificate Transparency | 18 | 4273 | December 10, 2019 | |
| [Google Chrome] Announcement: Requiring Certificate Transparency in 2017 | 2 | 3056 | October 25, 2016 | |
| How to deploy Certificate Transparency via OCSP Stapling? | 1 | 2137 | January 29, 2017 | |
| Certificate Transparancy not working in Chrome? | 12 | 4918 | January 27, 2016 |