3 ms·
I have no knowledge of how the CAs maintain the CT logs. What is the process for a CA to rebuild the CT log, if one exists? Is it something like what is illust
by vivegi 3y ago
I have no knowledge of how the CAs maintain the CT logs.
What is the process for a CA to rebuild the CT log, if one exists? Is it something like what is illustrated below?
Let CA1, CA2, CA3 and CA4 be different certificate authorities. The set enumerated alongside each CA is the set of certificates logged into its CT log.
CA1 : {c1, c2, c3}
CA2 : {c2, c3'}
CA3 : {c1, c2}
CA4 : {c1, c3}
Suppose CA2 is where an issue was detected with certificate c3 (the anomalous cert is denoted by c3') and CA2 trusts CA3 and CA4, then the set {c1, c2, c3} can be constructed after verifying the CT logs of CA3 and CA4 and merging their logs.
Is that kind of how it would work or would CA2 just truncate its log and restart from this point forward?
- detaro 3y agoThe broken log will just be replaced by a new one.
- agwa 3y agoThere's no merging or rebuilding. You just nuke the bad log, and certificates continue to work because they are present in other logs. (If all the logs used by a certificate go bad, then you'll have a bad time. This hasn't happened in 5 years of mandatory CT.) The log operator may choose to stand up a replacement log. The new log will have a different key, URL, and name from the old log. It's for all intents and purposes a completely different log.
- vivegi 3y agoThanks. So, the consequence is that browser vendors and other who utilize CT should ignore this log and use whatever is stood up as its replacement. That makes sense.