{"id":3204,"date":"2016-11-21T14:55:12","date_gmt":"2016-11-21T14:55:12","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3204"},"modified":"2020-08-25T09:21:33","modified_gmt":"2020-08-25T13:21:33","slug":"certificate-transparency","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/certificate-transparency\/","title":{"rendered":"Everything You Need to Know About Certificate Transparency"},"content":{"rendered":"<h2>What Certificate Transparency is and how it makes SSL more secure.<\/h2>\n<p>Recently we\u2019ve been covering a lot of news about Certificate Transparency, namely that <a href=\"https:\/\/www.thesslstore.com\/blog\/google-chrome-certificate-transparency-2017\/\">Google is about to mandate it in October 2017<\/a> and that <a href=\"https:\/\/www.thesslstore.com\/blog\/firefox-certificate-transparency\/\">Mozilla has announced it will support it<\/a>.<\/p>\n<p>So what exactly is Certificate Transparency? Let\u2019s start from the top.<\/p>\n<p>SSL certificates help keep your visitors secure. They provide encryption and server authentication which are crucial to securing communication with your website\u2019s servers. SSL certificates indicate to an end user that they are communicating with the legitimate server hosting that site, and not an imposter.<\/p>\n<p>However, the SSL ecosystem is incredibly complex, and as an industry, we have to ensure strict practices are followed in order to keep things working properly. In the past, there have been deviations from these practices that have threatened to compromise the SSL industry as a whole.<\/p>\n<p>The issue is that SSL has an incredibly complex threat model\u2014which is a description of the possible attacks that a system is vulnerable to. This means that multiple mechanisms are needed to ensure the SSL ecosystem is optimally secure. Certificate Transparency is one of those mechanisms\u2014it attempts to address a specific threat: <strong>misissuance<\/strong>.<\/p>\n<p>Misissuance occurs when a Certificate Authority (CA) issues an SSL certificate improperly. This may mean that the CA included incorrect information in the certificate, issued the certificate to someone who did not represent the organization or domain, or was even compromised.<\/p>\n<p>Certificate Transparency (CT) is a mechanism which helps domain owners and industry watch dogs detect misissuance. It is a publically-available log of certificates that have been issued. This log lists all the certificate\u2019s information so that it can be inspected by anyone with an interest. In practice there are multiple logs, which is needed due to the scale of the SSL ecosystem \u2013 millions of certificates are issued each year. Each log has to follow defined standards on what and how it stores the certificates.<\/p>\n<p>Organizations and people can then search the logs (or set up automatic notifications) to see what SSL certificates exist for the sites they own.\u00a0 This means that CT is not \u201cautomatic\u201d in the traditional sense. Even if all SSL certificates were immediately logged after issuance, the domain owner would still need to be looking for certificates in the logs to spot any that may be misissued.<\/p>\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n<h2>Searching CT Logs<\/h2>\n<p>Now, when I say someone needs to search the logs, I don\u2019t mean they have to go line by line looking through everything. There are multiple services that make it easy for an organization to do this. Websites like <a href=\"https:\/\/crt.sh\">crt.sh<\/a> support advanced searching criteria so you can look at only what is relevant to you. Other services allow you to set up notifications, so you can be alerted as soon as a new potential match occurs. Most of these tools search all the CT logs that exist.<\/p>\n<p>It\u2019s important to understand that Certificate Transparency only allows detection of misissued certificates after the fact. CT cannot prevent misissuance. It also cannot work autonomously. The legitimate domain holder needs to be looking at the log information in order to know if there are any misissued certificates out there.<\/p>\n<p>It may also be difficult to know if misissuance is occurring if there is a disorganized certificate provisioning system in place. For instance, a large university which delegates sub-domains to different departments or projects may have a hard time knowing if an issued certificate is legitimate or not if they do not have well-defined practices.<\/p>\n<p>Before CT existed, there was still the possibility that a domain owner could become aware of misissuance. But there would have to be evidence of abuse or other obvious signs, which could take weeks \u2013 or in the high-profile compromise of the CA DigiNotar, <a href=\"http:\/\/www.meegoexperts.com\/2011\/09\/diginotar-security-breach-means-qt-users\/\" rel=\"nofollow\">it took a month<\/a> for their missuance to be detected. This means there was an entire month that users could have been phished, snooped on, or otherwise attacked by those misissued certificates. Attentive organizations like Google and Facebook have used CT to minimize that detection window to just a few hours.<\/p>\n<p>But I must stress \u2013 you need to be looking in the logs for CT to be of any use for you.<\/p>\n<h2>How do Certificates Get Logged?<\/h2>\n<p>SSL Certificates are primarily added to logs in two ways. When a certificate is issued, the issuing CA has the choice to log it. This is the best method because it means certificates are being logged by the source. In some situations CAs are required to log \u2013 Google requires all EV SSL Certificates to be logged to receive the green address bar. And, as we mentioned earler, in October 2017 Google will require all SSL certificates to be logged. But, for the time being, logging is still optional for the majority of issued certificates. A few CAs log all the certificates they issue \u2013 Symantec, StartSSL, and Let\u2019s Encrypt \u2013 the rest only log certificates when required.<\/p>\n<p>The other primary source of logged certificates come from \u201cweb crawlers.\u201d When Google\u2019s search engine indexes a page, it also logs any SSL certificates it finds. Usually certificates are seen and logged by Google within a few days, however Google cannot automatically see every certificate. If a certificate is not used on a public network, or it\u2019s used on a sub-domain that is not indexed, then those certificates remain unlogged and unknown.<\/p>\n<h2>How CT improves security<\/h2>\n<p>One of the unfortunate downsides of the CA system is the ability for one irresponsible CA to negatively impact the entire ecosystem.<\/p>\n<p>A CA is allowed to issue a certificate for any existing website (this is a generalization, but its accurate for the most part), so even an organization with tight policies on certificate issuance can still be negatively affected. This was the case with the breach of the Dutch CA, DigitNotar. In 2011, DigiNotar was hacked and the attacker had the ability to issue certificates for any domain he wanted without proper authorization. The attacker issued certificates for various Google services. As an organization, Google has very strong security practices. Google is always on the cutting edge of SSL\/TLS practices \u2013 it created Certificate Transparency \u2013 but that could not protect it from DigiNotar.<\/p>\n<p>Computers that support the SSL\/TLS protocol have a \u201croot store\u201d (or \u201ctrust store\u201d) which lists the CAs that they trust. From the computer\u2019s perspective, this root store tells them what CAs are allowed to issue certificates. Because computers can\u2019t think for themselves they are not able to recognize misissuance on their own. There are other security mechanisms that can help computers with this. But if a certificate has been issued by a root that is trusted, by default most computers will automatically trust it.<\/p>\n<p>You can see how that could cause catastrophic consequences for the entire industry. One large enough mis-issuance, were it to affect a high-profile website and victimize enough internet users\u2014could even potentially undermine SSL as we know it.<\/p>\n<p>Certificate Transparency can help mitigate this problem.<\/p>\n<p>That\u2019s why it\u2019s so exciting to see companies like Google and Mozilla pushing the initiative forward to the point where CT becoming mandatory for all CAs is no longer a matter of if\u2014but when.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>What Certificate Transparency is and how it makes SSL more secure. Recently we\u2019ve been covering a lot of news about Certificate Transparency, namely that Google is about to mandate it&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3205,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[17],"tags":[164,187,131,192,136,161],"class_list":["post-3204","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-industry-lowdown","tag-certificate-authorities","tag-certificate-transparency","tag-google","tag-mozilla","tag-ssl","tag-tls","post-with-tags"],"views":19165,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/iStock-614017676.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3204","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3204"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3204\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3205"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3204"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3204"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3204"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}