September 2022 - Apple Log List Updates

1,285 views
Skip to first unread message

Clint

unread,
Sep 9, 2022, 1:01:33 PM9/9/22
to Certificate Transparency Policy
Hello All,

Apple has updated its CT Log List from version 142 to 166. These updates include several logs being moved to Read-Only (and shortly to Retired) and several new logs being added.

Read-Only Logs
The following logs have been transitioned to readonly:
Newly Qualified Logs
The following logs have been added as qualified:

Cloudflare Nimbus2024
DigiCert Nessie2024 Log
DigiCert Nessie2025 Log
DigiCert Yeti2024 Log
  • Log ID: SLDja9qmRzQP5WoC+p0w6xxSActW3SyB2bu/qznYhHM=
  • Log URL: https://yeti2024.ct.digicert.com/log/
  • Certificate Expiry Range: Jan 01 2024 00:00:00Z inclusive to Jan 01 2025 00:00:00Z exclusive
DigiCert Yeti2025 Log
  • Log ID: fVkeEuF4KnscYWd8Xv340IdcFKBOlZ65Ay/ZDowuebg=
  • Log URL: https://yeti2025.ct.digicert.com/log/
  • Certificate Expiry Range: Jan 01 2025 00:00:00Z inclusive to Jan 01 2026 00:00:00Z exclusive
Google Argon2024
Google Xenon2024
Let’s Encrypt Oak 2024H1
  • Log ID: O1N3dT4tuYBOizBbBv5AO2fYT8P0x70ADS1yb+H61Bc=
  • Log URL: https://oak.ct.letsencrypt.org/2024h1
  • Certificate Expiry Range: Dec 20 2023 00:00:00Z inclusive to Jul 20 2024 00:00:00Z exclusive
Let’s Encrypt Oak 2024H2
  • Log ID: PxdLT9ciR1iUHWUchL4NEu2QN38fhWrrwb8ohez4ZG4=
  • Log URL: https://oak.ct.letsencrypt.org/2024h2
  • Certificate Expiry Range: Jun 20 2024 00:00:00Z inclusive to Jan 20 2025 00:00:00Z exclusive
Apple's current log list is available at https://valid.apple.com/ct/log_list/current_log_list.json.
Our current log list schema is available at https://valid.apple.com/ct/log_list/current_log_list_schema.json.

Details on Apple's log policy are available at https://support.apple.com/en-us/HT205280.
Apple's log program requirements, including definitions for CT log states, are available at https://support.apple.com/en-us/HT209255.
Prior versions of our log list may be found under https://valid.apple.com/ct/log_list/log_list_versions/log_list_v<log list version>.json (e.g. https://valid.apple.com/ct/log_list/log_list_versions/log_list_v142.json).

Thanks!
-Clint

Clint

unread,
Sep 27, 2022, 4:01:59 PM9/27/22
to Certificate Transparency Policy, Clint
Hello All,

Apple has updated its CT Log List from version 166 to 170. These updates include several logs being Retired.

Retired Logs
The following logs have been transitioned to retired with a timestamp of 2022-09-15T00:00:00Z:

Apple's current log list is available at https://valid.apple.com/ct/log_list/current_log_list.json.
Our current log list schema is available at https://valid.apple.com/ct/log_list/current_log_list_schema.json.

Details on Apple's log policy are available at https://support.apple.com/en-us/HT205280.
Apple's log program requirements, including definitions for CT log states, are available at https://support.apple.com/en-us/HT209255.
Prior versions of our log list may be found under https://valid.apple.com/ct/log_list/log_list_versions/log_list_v<log list version>.json (e.g. https://valid.apple.com/ct/log_list/log_list_versions/log_list_v166.json).

Thanks!
-Clint

Xiaoming Yang

unread,
Mar 28, 2023, 9:58:51 PM3/28/23
to Certificate Transparency Policy, Clint
I am the operator of TrustAsia's CT Logs, and we are apply to add our TrustAsia Log2024 to the Apple CT Log List.

We had sent a apply email to the Apple CT Log List, but it seems that we have not received any feedback.

We were researched the updates log of the Apple CT Log List in the Google Groups. It seems that our TrustAsia Log2024 missed the last updates.

Thank you for raising your concerns.

Jaime Hablutzel

unread,
Jul 29, 2023, 4:58:19 PM7/29/23
to Certificate Transparency Policy, Xiaoming Yang, Clint
Is https://ct2024.trustasia.com/log2024 going to be included in the Apple's Certificate Transparency log program any time soon? 

It is already included in the Chrome CT Log list for some time now, https://bugs.chromium.org/p/chromium/issues/detail?id=1315126#c19.

Clint Wilson

unread,
Jul 29, 2023, 6:44:35 PM7/29/23
to Jaime Hablutzel, Certificate Transparency Policy, Xiaoming Yang
It should be soon, yes.

-Clint
Reply all
Reply to author
Forward
0 new messages