Discuz! Board

 找回密碼
 立即註冊
搜索
熱搜: 活動 交友 discuz
查看: 2|回復: 0

What is Certificate Transparency and how does it work?

[複製鏈接]

1

主題

1

帖子

5

積分

新手上路

Rank: 1

積分
5
發表於 14:19:14 | 顯示全部樓層 |閱讀模式
Not everything is as safe as it seems on the Internet, but Certificate Transparency (CT) is a positive thing. Chances are you've interacted with CT without realizing it, especially if you've ever received a warning about a website's security certificate. So what is Certificate Transparency and how does it fit into the overall privacy protection landscape?

Designed to prevent fraudulent SSL certificates from being issued, this system works by registering and monitoring all certificates in a public, verifiable record. As you explore further, you will learn how this mechanism improves web security and ensures accountability for certificate authorities.

Table of contents

What is Certificate Transparency?
How does certificate transparency work?
Benefits of Certificate Transparency
What are pre-certifications and why are they useful?
What is Certificate Transparency?
Certificate Transparency is a public log that aims to mobile app development service improve the security of the SSL/TLS certificate ecosystem by allowing anyone to audit certificates in real time. CT prevents unauthorized certificates from being issued and detects any incorrectly issued certificates. It significantly reduces the risk of undetected certificate errors by providing a mechanism for continuous external audit of the certificate system.

At its core, Certificate Transparency involves maintaining comprehensive “application-only” logs (logs that only allow additions, no changes, or deletions) of issued SSL/TLS certificates. These Certificate Transparency logs are publicly available and verifiable, ensuring that any organization can verify the certificates at any time. This accountability helps identify unauthorized certificates and mitigate man-in-the-middle (MITM) attacks that could otherwise compromise secure communications.




How does certificate transparency work?
Certificate Transparency requires CAs to submit newly issued certificates to CT logs. These public logs are tamper-proof, meaning any attempt to change, delete, or revoke records can be easily detected. Each log entry is timestamped and cryptographically signed, providing a secure and verifiable way to track the issuance of certificates.

Once a certificate is logged, it receives a Signed Certificate Timestamp (SCT) – proof that the certificate has been logged. Web servers then use these SCTs to demonstrate to connecting clients that their certificates are transparent and part of the public record. Clients, such as web browsers, can check these SCTs against logs, ensuring that the certificate is legitimate and that it was not issued maliciously or in error.

Here's a quick step-by-step overview of how CT works:

Create a pre-certificate : The Certification Authority (CA) creates a pre-certificate containing the same information that subsequent SSL/TLS certificates will contain.
Send to log server : The pre-certificate is sent to a trusted log server.
Log Server Response : The Certificate Transparency log server accepts the precertificate and responds with a “signed certificate timestamp (SCT)”. This SCT is essentially a promise from the CT log server to add the certificate to its log within a certain period of time, known as the Maximum Merge Delay (MMD).
回復

使用道具 舉報

您需要登錄後才可以回帖 登錄 | 立即註冊

本版積分規則

Archiver|手機版|自動贊助|z

GMT+8, 10:24 , Processed in 0.040111 second(s), 18 queries .

抗攻擊 by GameHost X3.4

Copyright © 2001-2021, Tencent Cloud.

快速回復 返回頂部 返回列表
一粒米 | 中興米 | 論壇美工 | 設計 抗ddos | 天堂私服 | ddos | ddos | 防ddos | 防禦ddos | 防ddos主機 | 天堂美工 | 設計 防ddos主機 | 抗ddos主機 | 抗ddos | 抗ddos主機 | 抗攻擊論壇 | 天堂自動贊助 | 免費論壇 | 天堂私服 | 天堂123 | 台南清潔 | 天堂 | 天堂私服 | 免費論壇申請 | 抗ddos | 虛擬主機 | 實體主機 | vps | 網域註冊 | 抗攻擊遊戲主機 | ddos |