CT alerts: know when someone gets a certificate for your domains
CertKit now watches certificate transparency logs for your domains and emails you when a certificate appears that you have never seen before.
CertKit now watches certificate transparency logs for your domains and emails you when a certificate appears that you have never seen before.
We forgot a DNS record for ten years. Someone else got the IP, a certificate, and our subdomain. How dangling DNS becomes a subdomain takeover.
There is a permanent public record of every certificate ever issued for your domain. You never agreed to it and you can’t opt out. I read ours, and it names our dev servers and most of our vendors.
You’ve been using wildcard certificates for years because they were simpler. One cert, one renewal, copy it everywhere. But now you’re automating anyway. If certificate management is no longer painful, do you still need wildcards? Or are they solving a problem that no longer exists?
In this post we’ll build a Clickhouse database schema to store billions of Certificate Transparency Log entries.
In this post we’ll write Golang code to pull Certificate Transparency Log entries and process them at scale.
Every TLS certificate ever issued for a domain is recorded in public Certificate Transparency logs. Here’s how to search them to find mis-issued certificates, unauthorized changes, or infrastructure you didn’t know existed.
New writing on certificate management, sent when there is something worth your time. Shrinking lifetimes, ACME on real infrastructure, the occasional outage post-mortem.