DigiCert - Shutdown old 2024 and 2025 logs

212 views
Skip to first unread message

Rick Roos

unread,
May 26, 2026, 4:45:27 PMMay 26
to Certificate Transparency Policy
Hello All,

We have some old CT logs that are past their inclusion window and will be shut down.  All of these logs have been frozen and have had their last signed tree published for several weeks.

The following logs will be turned off on Thursday June 4th:

Filippo Valsorda

unread,
May 27, 2026, 11:13:44 AMMay 27
to Certificate Transparency Policy
Hi Rick,

Any chance you could archive the 2025h2 shards to https://github.com/geomys/ct-archive? The rest were already captured.

Thank you!
Filippo
--
You received this message because you are subscribed to the Google Groups "Certificate Transparency Policy" group.
To unsubscribe from this group and stop receiving emails from it, send an email to ct-policy+...@chromium.org.

Filippo Valsorda

unread,
Jun 3, 2026, 5:47:29 PM (10 days ago) Jun 3
to Certificate Transparency Policy
Hi Rick,

Have you given any consideration to archiving the 2025h2 shards before shutting them down tomorrow?

Fetching them externally seems impossible due to rate limits: it'd take 4M requests each, which based on https://groups.google.com/a/chromium.org/g/ct-policy/c/lTqtb4WHsqo/m/38t48RAyAgAJ would take a month and a half, assuming 1 req/s because you have not confirmed the actual rate limit and ideal pattern.

It's unfortunate to have CT logs in the ecosystem that are so hard to monitor that it's impossible to fetch them between the day their shut down is announced and the day they are shut down.

Rick Roos

unread,
Jun 3, 2026, 6:58:13 PM (10 days ago) Jun 3
to Filippo Valsorda, Certificate Transparency Policy
Hi Filippo,

We discussed this internally and will delay shutting down the 2025h2 logs to give you more time to download them (we will still move forward shutting down the other logs).  In addition, we are increasing the per Nginx server rate limit to 5 requests per second. I just responded to Rob on the other thread with the best download pattern. Can your tool download the entries in parallel?  If so that will greatly speed up the process. 

Let us know if this speeds up your download and if you can give an estimate of how long it will take to download.

Additionally, in the future we will announce the freezing of logs earlier and allow more time to download the logs before shutting them down.

Thanks,
Rick

Filippo Valsorda

unread,
Jun 4, 2026, 4:08:15 PM (9 days ago) Jun 4
to Rick Roos, Certificate Transparency Policy
Thank you, I kicked off a fetch and I seem to be able to get between 5 and 15 requests per second by using a pool of parallel connections.

Should be done in a week or so, I will report back.

Filippo Valsorda

unread,
Jun 8, 2026, 7:10:39 AM (5 days ago) Jun 8
to Rick Roos, Certificate Transparency Policy
I have finished downloading digicert_sphinx2025h2 and digicert_wyvern2025h2. The latter is already uploaded at https://archive.org/details/ct_digicert_wyvern2025h2, the former is still uploading to https://archive.org/details/ct_digicert_sphinx2025h2.

Rick Roos

unread,
Jun 9, 2026, 12:37:04 PM (4 days ago) Jun 9
to Filippo Valsorda, Certificate Transparency Policy
Thanks Filippo!  We will go ahead and shut down the 2025h2 logs this week.

-Rick
Reply all
Reply to author
Forward
0 new messages