Hello ct-policy,
Chrome has allowed for temporally-sharded CT Logs since 2017 and as they’ve grown in popularity, we’ve come to strongly prefer them over “monolithic” CT Logs that grow indefinitely. At a moderately small marginal cost to Log Operators and CAs, sharded CT Logs provide:
Reasonable caps for Log Operators on the growth of their Qualified CT Logs
More predictable CT Log lifecycle for user agents and CAs
Lower cost of entry and ongoing storage costs for CT Monitors and Auditors
After the first batch of sharded CT Logs were stood up, most Log Operators coalesced around annual, non-overlapping shards, but this was never put into policy and we’re currently reviewing a new CT Log with a much larger expiry range (2021-2025). Given the benefits of moving the CT ecosystem to predictably sharded CT Logs, we’re proposing to require all new CT Logs be sharded on an annual basis. Each set of sharded CT Logs should keep enough shards to cover the current year plus 2-3 subsequent years to ensure continuity of coverage for certificate logging.
I’d like to hear feedback from the community about whether there are any concerns with us updating our CT Policy to reflect the above suggested changes.
Best,
Devon
--
You received this message because you are subscribed to the Google Groups "Certificate Transparency Policy" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ct-policy+...@chromium.org.
To view this discussion on the web visit https://groups.google.com/a/chromium.org/d/msgid/ct-policy/29f53e01-b1e5-456c-aff6-21e1ca32c6df%40chromium.org.
> ct-policy+unsubscribe@chromium.org. To view this discussion on the
> web visit
> https://groups.google.com/a/chromium.org/d/msgid/ct-policy/29f53e01-b1e5-456c-aff6-21e1ca32c6df%40chromium.org.