RFC 9162: Certificate Transparency Version 2.0
In plain English — editorial summary, not part of the RFC
This document describes version 2.0 of the Certificate Transparency (CT) protocol for publicly logging the existence of Transport Layer Security (TLS) server certificates as they are issued or observed, in a manner that allows anyone to audit certification authority (CA) activity and notice the issuance of suspect certificates as well as to audit the certificate logs themselves. The intent is that eventually clients would refuse to honor certificates that do not appear in a log, effectively forcing CAs to add all issued certificates to the logs. This document obsoletes RFC 6962. It also specifies a new TLS extension that is used to send various CT log artifacts. Logs are network services that implement the protocol operations for submissions and queries that are defined in this document.
Document record
- Document ID
- RFC9162
- Published
- December 2021
- Authors
- B. Laurie; E. Messeri; R. Stradling
- Status
- EXPERIMENTAL
- Stream
- IETF
- Area
- sec
- Pages
- 53
- Also known as
- —
- Obsoletes:
- RFC 6962
Topics
Related documents
Ranked automatically by shared keywords, IETF area and stream — not by editorial selection.
- RFC 6394Use Cases and Requirements for DNS-Based Authentication of Named Entities (DANE)Current
October 2011
- RFC 5922Domain Certificates in the Session Initiation Protocol (SIP)Current
June 2010
- RFC 4894Use of Hash Algorithms in Internet Key Exchange (IKE) and IPsecCurrent
May 2007
- RFC 9155Deprecating MD5 and SHA-1 Signature Hashes in TLS 1.2 and DTLS 1.2Current
December 2021
- RFC 9149TLS Ticket RequestsCurrent
April 2022
- RFC 9216S/MIME Example Keys and CertificatesCurrent
April 2022
- RFC 9295Clarifications for Ed25519, Ed448, X25519, and X448 Algorithm IdentifiersCurrent
September 2022
- RFC 8996Deprecating TLS 1.0 and TLS 1.1Current
March 2021
Also filed under
About this page
The document record above — title, authors, date, status, stream, area, relationships, DOI and errata — is imported verbatim from the public RFC Editor index. The “in plain English” section is editorial: written by The metasystema editorial team, not part of the RFC. Where the two differ, the RFC text governs.
Last checked against the RFC Editor index on . RFCs are never revised after publication; changes are issued as new documents.
Data sources · Editorial policy · Report a correction · What is an RFC?