2 ms·
CT significantly pre-dates the recent Symantec issues, but yes, it does provide an excellent tool for providing evidence of misissuance [0] [1] - and that's the
by aeijdenberg 10y ago
CT significantly pre-dates the recent Symantec issues, but yes, it does provide an excellent tool for providing evidence of misissuance [0] [1] - and that's the crux of it - in order for a certificate to be considered valid in a CT world, it must present proof that it has been publicly logged.
[0] https://security.googleblog.com/2015/09/improved-digital-certificate-security.html https://security.googleblog.com/2015/09/improved-digital-cer...
[1] http://searchsecurity.techtarget.com/news/450411573/Certificate-Transparency-snags-Symantec-CA-for-improper-certs http://searchsecurity.techtarget.com/news/450411573/Certific...
[2]