
Certificate Transparency Monitoring is now generally available
Cloudflare updated its Certificate Transparency Monitoring service to filter out routine alerts for certificates it issues on behalf of customers. This ensures users are only notified about unexpected or external certificate issuances.
Why it matters
Domain owners can now detect potentially unauthorized certificates without being overwhelmed by routine renewal alerts. This makes the tool a more effective early warning system for security threats.
The details
- The filter uses spki_sha256, a public key hash, to identify managed certificates.
- Routine renewals for Universal SSL and Advanced Certificate Manager are now suppressed.
- Alerts for custom uploaded certificates remain active to maintain security monitoring.
Show entities and relationshipsHide entities and relationships
In this article
Products
Topics
Companies
Technologies
Organizations
Key connections
Cloudflare owns Certificate Transparency Monitoring
Cloudflare developed and made Certificate Transparency Monitoring generally available.
Cloudflare owns Universal SSL
Cloudflare offers Universal SSL certificate issuance for customer domains.
Cloudflare owns Advanced Certificate Manager
Cloudflare provides Advanced Certificate Manager for certificate customization.
Cloudflare owns Total TLS
Cloudflare provides Total TLS for automated certificate management.
Cloudflare owns Cloudflare Notifications
Cloudflare operates Cloudflare Notifications for routing platform alerts.
Both are major web browsers requiring Certificate Transparency logging.
Show 11 more connectionsShow fewer connections
Both are major web browsers requiring Certificate Transparency logging.
Certificate Transparency Monitoring uses Certificate Transparency
Monitors public Certificate Transparency logs to alert subscribers about newly issued certificates.
Certificate Transparency Monitoring uses TLS
Monitors TLS certificates across customer domains.
Certificate Transparency Monitoring uses SHA-256
Uses an SHA-256 hash of the DER-encoded SPKI to deduplicate and filter out Cloudflare-managed certificates.
Certificate Transparency Monitoring is related to Cloudflare Notifications
Planned integration to route Certificate Transparency alerts through Cloudflare Notifications.
Cloudflare Notifications is related to PagerDuty
Allows routing alerts to notification services including PagerDuty.
Universal SSL uses TLS
Issues and renews TLS certificates automatically for customer domains.
Provides automated TLS certificate coverage.
Chrome uses Certificate Transparency
Requires TLS certificates to be logged in public CT logs to be trusted.
Safari uses Certificate Transparency
Requires TLS certificates to be logged in public CT logs to be trusted.
CA/Browser Forum regulates TLS
Voted to cut the maximum certificate lifetime to 47 days by 2029.
Related events
Cloudflare Makes Certificate Transparency Monitoring Generally Available with SPKI-Based Alert Filtering
Get the weekly recap
The stories like this one, picked and explained — once a week, straight to your inbox.