Certificate Transparency Version 2.0
RFC 9162, “Certificate Transparency Version 2.0”, is an Experimental document published in December 2021 by B. Laurie, E. Messeri, R. Stradling. It obsoletes RFC 6962. The canonical text is published by the RFC Editor.
Abstract
This document describes version 2.0 of the Certificate Transparency (CT) protocol for publicly logging the existence of Transport Layer Security (TLS) server certificates as they are issued or observed, in a manner that allows anyone to audit certification authority (CA) activity and notice the issuance of suspect certificates as well as to audit the certificate logs themselves. The intent is that eventually clients would refuse to honor certificates that do not appear in a log, effectively forcing CAs to add all issued certificates to the logs.
This document obsoletes RFC 6962. It also specifies a new TLS extension that is used to send various CT log artifacts.
Logs are network services that implement the protocol operations for submissions and queries that are defined in this document.
What “Experimental” means
Describes a specification that is part of a research or development effort, published so the community can gain experience with it.
The canonical text of RFC 9162 is hosted at rfc-editor.org. Available in HTML,TXT,PDF,XML.
- RFC 9160 Export of MPLS Segment Routing Label Type Information in IP Flow Information Export
- RFC 9164 Concise Binary Object Representation Tags for IPv4 and IPv6 Addresses and Prefixes
- RFC 9159 IPv6 Mesh over BLUETOOTH Low Energy Using the Internet Protocol Support Profile
- RFC 9165 Additional Control Operators for the Concise Data Definition Language
- RFC 9158 Update to the Object Identifier Registry for the PKIX Working Group
- RFC 9157 Revised IANA Considerations for DNSSEC
- RFC 9167 Registry Maintenance Notification for the Extensible Provisioning Protocol
- RFC 9156 DNS Query Name Minimisation to Improve Privacy