AI Briefing
KO

Certificate Transparency Monitoring Now Generally Available

·2026.08.13 22:00

Key point

Cloudflare has launched the generally available Certificate Transparency Monitoring, which filters notifications for certificates issued by Cloudflare to more accurately detect security threats.

Details

Certificate Transparency (CT) monitoring is now generally available (GA). This service sends notifications when new TLS certificates for a domain appear in public CT logs, helping to detect misissued certificates early.

Previously, there was a 'noise' issue where all certificates issued by Cloudflare on behalf of customers (such as Universal SSL and Advanced Certificate Manager) were sent as notifications. As certificate lifespans shortened and automatic renewals became more frequent, important security threat notifications were buried among routine renewal alerts.

To address this, Cloudflare introduced a feature that filters out certificates issued by Cloudflare before sending notifications. Users can now receive notifications only for unexpected certificates not issued by Cloudflare.

Technically, the core challenge was resolving data inconsistencies between the certificate management system and the CT notification service. During the certificate issuance process, a pre-certificate is logged first, but at this stage, the certificate's identifier, the stripped_fingerprint, has not yet been registered in the Ordering Service, making it impossible to immediately verify if the certificate was issued by Cloudflare.

Cloudflare has resolved this issue, eliminating routine renewal notifications and providing accurate alerts only for external certificate issuances that could pose actual security threats.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.