Certificate Transparency (CT)
Embed This Widget
Add the script tag and a data attribute to embed this widget.
Embed via iframe for maximum compatibility.
<iframe src="https://tldfyi.com/iframe/glossary/certificate-transparency/" width="420" height="400" frameborder="0" style="border:0;border-radius:10px;max-width:100%" loading="lazy"></iframe>
Paste this URL in WordPress, Medium, or any oEmbed-compatible platform.
https://tldfyi.com/glossary/certificate-transparency/
Add a dynamic SVG badge to your README or docs.
[](https://tldfyi.com/glossary/certificate-transparency/)
Use the native HTML custom element.
Certificate Transparency (CT) là một tiêu chuẩn mở (RFC 9162) yêu cầu tất cả [[ssl-tls|chứng chỉ SSL/TLS]] được tin cậy công khai phải được ghi vào các sổ cái chỉ thêm vào và có thể kiểm tra công khai gọi là CT logs. Trình duyệt thực thi CT bằng cách yêu cầu mỗi chứng chỉ phải bao gồm bằng chứng đã ký (SCT) từ CT logs được công nhận trước khi được tin cậy. CT giúp chủ sở hữu tên miền theo dõi các chứng chỉ không được phép cấp cho tên miền của họ và cho phép nhà nghiên cứu bảo mật phát hiện việc cấp sai bởi các tổ chức chứng nhận. Các dịch vụ như crt.sh và Báo cáo Minh bạch của Google cung cấp truy cập tìm kiếm được vào dữ liệu CT log.
Ví dụ
A company monitoring CT logs via crt.sh discovers a certificate was issued for 'secure.theircompany.com' by an unauthorized CA — indicating a potential phishing setup or CA compromise.