Cite this RFC:TXT | XML | BibTeX
DOI: https://doi.org/10.17487/RFC9162
Discuss this RFC: Send questions or comments to the mailing listtrans@ietf.org
Other actions:View Errata | Submit Errata | Find IPR Disclosures from the IETF | View History of RFC 9162
This document describes version 2.0 of the Certificate Transparency(CT) protocol for publicly logging the existence of Transport LayerSecurity (TLS) server certificates as they are issued or observed, ina manner that allows anyone to audit certification authority (CA)activity and notice the issuance of suspect certificates as well asto audit the certificate logs themselves. The intent is thateventually clients would refuse to honor certificates that do notappear in a log, effectively forcing CAs to add all issuedcertificates to the logs.
This document obsoletes RFC 6962. It also specifies a new TLSextension that is used to send various CT log artifacts.
Logs are network services that implement the protocol operations forsubmissions and queries that are defined in this document.
For the definition ofStatus,seeRFC 2026.
For the definition ofStream, seeRFC 8729.