Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Are those certificate logs indexed? It’d be super handy to know where they are and how to use them


https://crt.sh is a popular search engine for them, and there are other tools (like Censys) that also expose this data.


Setting up a wildcard search for your domains with crt.sh's rss feeds into slack is a great way to stay alerted on certificates issued on your domains.


I built an alerting service to do exactly that for you.

https://ctadvisor.lolware.net/


It depends what you mean by the word "indexed".

The logs are publicly accessible services, here is Google's information on logs they trust (e.g. in Chrome) and you can find equivalent information for Apple (for Safari)

https://www.certificate-transparency.org/known-logs

But, a CT log is a very high availability service, designed to present a very narrowly defined API (RFC 6962) to the world, it is not tailored to be user friendly.

A sibling post mentions crt.sh, which is a web site (and associated services including a Postgres) that consumes the data from the logs. If you're curious and just want to poke around, maybe satisfy yourself that your own certificate is indeed logged you should play with https://crt.sh/




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: