Skip to content

Archive

PKI

53 articles
Cybersecurity 13 Sep 2026 7 min read

Certificate Transparency Turns Issuance Into Observable Evidence

Certificate Transparency Turns Issuance Into Observable Evidence A certificate authority can issue a perfectly valid TLS certificate for the wrong organization. The signature can verify, the chain can terminate at a trusted root, the hostname can match, and the certificate can still represent an issuance event the domain operator never intended. Certificate Transparency, commonly abbreviated CT, changes that failure from a largely private event into observable evidence. Publicly trusted certificate authorities submit certificate material to append-only logs, and clients can require evidence that a certificate has been recorded in suitable logs. Domain operators and security services can then watch those logs for names they control.

Cybersecurity 13 Sep 2026 6 min read

Certificate Transparency Turns Certificate Issuance Into an Observable Event

A certificate can be valid in every cryptographic sense and still be a security incident for the organization named in it. The issuing certificate authority may have followed its validation process, the signature may verify, and browsers may accept the chain. If the certificate was requested through a compromised account, an unintended validation path, or an infrastructure mistake, none of those properties establish that the domain operator expected it to exist.

Cybersecurity 13 Sep 2026 8 min read

Certificate Revocation Is a Distributed Freshness Problem

Certificate Revocation Is a Distributed Freshness Problem A private key can be exposed at 10:00, its certificate can be revoked at 10:15, and some clients can still face a harder question at 10:16: do they possess current enough evidence to reject it? That gap is easy to miss when revocation is described as a property attached to a certificate. X.509 certificates are signed objects with validity periods; changing the certificate after issuance would invalidate its signature. Revocation therefore lives outside the certificate itself. A relying party needs separate status information, needs that information to be sufficiently recent, and needs a policy for cases in which status cannot be obtained.

Cybersecurity 12 Sep 2026 7 min read

Use Certificate Transparency as a Detection Signal

A TLS certificate can be valid in every cryptographic sense and still be operationally unexpected. A forgotten staging host may receive a certificate through an automated pipeline. A vendor may issue for a delegated subdomain that the central security team did not know existed. More seriously, an attacker who gains control of a DNS validation path or a certificate-authority account may obtain a certificate for a name they should not control.

Cybersecurity 12 Sep 2026 6 min read

Certificate Transparency Turns Issuance Into an Observable Event

A public TLS certificate can be perfectly valid and still be operationally alarming. A certificate authority may have followed its validation rules, the signature chain may verify, and browsers may accept the credential without complaint. Yet the organization named in that certificate may never have intended the hostname to exist. That gap matters because certificate issuance is an authorization event with security consequences. Certificate Transparency makes much of that event visible. Publicly trusted certificate authorities submit certificate information to append-only logs, giving domain operators and the wider ecosystem a record that can expose unexpected issuance soon after it occurs.