4 ms·
That's not quite how CT works. The client doesn't (currently) need to have any access to the CT logs themselves. Generally, a 'pre' certificate is submitted to
by nickf 4y ago
That's not quite how CT works. The client doesn't (currently) need to have any access to the CT logs themselves.
Generally, a 'pre' certificate is submitted to a number of logs by the CA. The log returns a signed timestamp. These SCTs (signed certificate timestamps) are embedded in the final certificate provided to the subscriber - and the browser can verify those.
(The SCTs can also be stapled, and not signed into the certificate itself).