Elektrine lite

← Feed

@filippo@abyssdomain.expert

Post #1074166

2026-04-04 13:13 UTC

There was no good way to see what CT logs are actually used by CAs, so I made a dashboard of Censys data on exe.dev. There are some interesting patterns, but the main one is that Let's Encrypt is the only CA that evenly spreads load. Other CAs are mostly using older logs, or their own logs and Google's. (Of course, LE is 50% of issuance, and GTS is 25%, so the rest don't matter much.) https://groups.google.com/a/chromium.org/d/msgid/ct-policy/718571cb-a841-4102-bcfa-3fe3feab63ae%40app.fastmail.com

Replies (2)

  • @certkit@infosec.exchange 2026-04-06 14:29

    @filippo They may not matter much in volume, but lots of orgs are still tied to the OV/EV certs from legacy CAs. We still need to pull from just about all the CT Logs to get a complete picture for our discovery tool. https://www.certkit.io/tools/ct-logs/

    Open ##1074234

  • @icing@chaos.social 2026-04-04 19:42

    @filippo It‘s amazing what a few people who know what they are doing are able to achieve when left outside any corporate structure.😌

    Open ##1202092