{"id":3159,"date":"2016-11-07T15:12:29","date_gmt":"2016-11-07T15:12:29","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3159"},"modified":"2023-04-10T16:30:37","modified_gmt":"2023-04-10T20:30:37","slug":"firefox-certificate-transparency","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/firefox-certificate-transparency\/","title":{"rendered":"Firefox Will Support Certificate Transparency"},"content":{"rendered":"<h2>Certificate Transparency just took a huge step forward.<\/h2>\n<p>Mozilla has made a big announcement: \u201cCT is coming to Firefox.\u201d Certificate Transparency, abbreviated as CT, is an incredibly important tool for improving safety for publicly-trusted SSL certificates.<\/p>\n<p>So far, all Mozilla has said is that Firefox will support Certificate Transparency. Its actual policy \u2013 including the criteria for log inclusion, and if\/when SSL certificates will need to support CT \u2013 has not been formed.<\/p>\n<p>Google, whose engineers invented Certificate Transparency, recently made a major announcement: A year from now (October 2017), <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-certificate-transparency-2017\/\">Chrome will be requiring all SSL certificates support CT<\/a>. Chrome has supported, but in most cases not required, CT for over a year. Other browsers have yet to do so because the system was still being perfected.<\/p>\n<p>For those who are unfamiliar, Certificate Transparency is a new-ish addition to our industry. It is a system where Certificates Authorities (CAs) submit their issued certificates to publicly-searchable servers known as \u201clogs.\u201d These logs provide a way for anyone to search for and monitor issued certificates. As the name suggests, the goal is to provide transparency into a CA\u2019s issuance practices.<\/p>\n<p>It is important to know what certificates are being issued because it allows the community \u2013 including users and software that relies on publicly-trusted SSL (web browsers) \u2013 to spot non-compliance and mis-issuance. CT has already been used to spot multiple cases of CA malfeasance and has helped strengthen the security of Web PKI (the formal name for the entire system that comprises CAs and publicly-trusted SSL Certificates).<\/p>\n<p>Without CT, the only way to know what certificates a CA is issuing is to stumble across them on the internet. Projects like <a href=\"https:\/\/censys.io\/\" rel=\"nofollow\">censys.io<\/a> have collected millions of certificates by conducting internet-wide scans of servers, but that method will always be incomplete. By getting the information directly from the source (the CAs themselves), CT provides better oversight.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<p>The Certificate Transparency system is very similar to the CA system. CT logs can be operated by anyone (like CAs), and those logs can be valid sources for browsers provided they follow the necessary policies and practices (like Root Programs).<\/p>\n<p>Mozilla is known for running an extremely transparent Root Program. It operates the program publicly on its\u00a0<a href=\"https:\/\/groups.google.com\/forum\/#!forum\/mozilla.dev.security.policy\" rel=\"nofollow\">mozilla.dev.security.policy mailing list<\/a> and on the <a href=\"https:\/\/bugzilla.mozilla.org\/buglist.cgi?component=CA%20Certificates&amp;product=mozilla.org&amp;bug_status=__open__\" rel=\"nofollow\">Bugzilla bug-tracking site<\/a>. Recent incidents, like the discussion of how to respond to WoSign\u2019s mis-issuances, received over 400 comments.<\/p>\n<p>Gervase Markham, a member of Mozilla\u2019s CA team who started the discussion topic about Certificate Transparency, said at this point Mozilla is\u00a0trying \u201cto work out the scope of the policy, not what the policy will be.\u201d<\/p>\n<p>If you have any thoughts on what Mozilla should consider, <a href=\"https:\/\/groups.google.com\/forum\/#!topic\/mozilla.dev.security.policy\/VJYX1Wnnhiw\" rel=\"nofollow\">you can share them in the discussion thread<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Certificate Transparency just took a huge step forward. Mozilla has made a big announcement: \u201cCT is coming to Firefox.\u201d Certificate Transparency, abbreviated as CT, is an incredibly important tool for&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3160,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[187,151,131,192,136],"class_list":["post-3159","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-certificate-transparency","tag-firefox","tag-google","tag-mozilla","tag-ssl","post-with-tags"],"views":13548,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/Mozilla-MWC-2014-Booth.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3159","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3159"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3159\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3160"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3159"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3159"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3159"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}