--You received this message because you are subscribed to a topic in the Google Groups "certificate-transparency" group.To unsubscribe from this topic, visit https://groups.google.com/d/topic/certificate-transparency/ViOlp7fEzWQ/unsubscribe.To unsubscribe from this group and all its topics, send an email to certificate-transp...@googlegroups.com.To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/625c342d-4baf-4635-8a24-f502a3179e8an%40googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/5300fda0-38b3-4e47-8edc-fafd458ea868%40app.fastmail.com.
I have a little more work to do around the CA root validation and then, I'll apply for a test log.
You received this message because you are subscribed to the Google Groups "certificate-transparency" group.
To unsubscribe from this group and stop receiving emails from it, send an email to certificate-transp...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/9c7fe07f-1bf3-4ab6-ad0f-1bf3c448207c%40app.fastmail.com.
Hi Ryan,Thank you _so much_ for your email. I completely missed that and was going to implement something not-optimal in comparison.Should this remain static in the context of a log? Or is it permitted to fetch the list in a worker every so often to update get-roots, and related verification path?
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/6298137e-1cd3-4fd1-b179-f027e3e94e49%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/52c4bdcf-c82c-4f8b-8f08-b405ce913230%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/db1d6c88-b7a0-4418-b4d7-40053dabc0cc%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/6298137e-1cd3-4fd1-b179-f027e3e94e49%40app.fastmail.com.
Thank you!I’ll go that route then.By the way, out of curiosity, is the primary reason for a log to not just accept anything primarily for anti-spam reasons and to not make monitors waste resources? Or is there also something else?
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/3b6bff4a-dabc-4656-a5a7-773f76066b5b%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/c223fc2f-aec1-4805-952c-4d774ca53e44%40app.fastmail.com.
Not sure about illegal things, but cat pictures? Definitely: https://static.sched.com/hosted_files/bsidessf2019/88/Catlog_BSidesSF_2019.pdf
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/94ec1cc4-cc4b-4807-a88f-4d48f332446c%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/DS0PR14MB62161BD6A69C1AD3608405E5926EA%40DS0PR14MB6216.namprd14.prod.outlook.com.Attachments:
- smime.p7s
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/afe2828a-8fef-4914-8b2d-810722c10328%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/c82c7eb1-323f-4793-9937-0854f7b6d0ae%40app.fastmail.com.
cert:{hash}
keysDeduplicatedLogEntry
structure contains:To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/6d1eb2d8-3882-4e22-8cbf-87ef751d3382%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/14d48c2a-9583-40ae-b84d-eaa57451175d%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/11b1f516-f331-4cc5-bfd3-6503092116ce%40app.fastmail.com.
Hello everyone,I've ingested 54M certificates in CompactLog from real sources (current and past logs).Current storage: 122GB for 54M+ entries (https://compact-log.pre-test.ct.merklemap.com/ct/v1/get-sth). This translates to approximately 236GB per 100M certificates or 2.36TB per billion. I was able to ingest continuously at around 4k-8k entries per second on commodity hardware.For reference, Let's Encrypt's 2019 blog post (https://letsencrypt.org/2019/11/20/how-le-runs-ct-logs/) mentioned their implementation used around 1TB per 100M entries. I wonder if their current numbers are similar.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/d61a3a91-9485-4de9-b480-0108aca9a468%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/9b52ece4-13eb-4623-b879-8e06701a05c1%40app.fastmail.com.
I've successfully implemented logic to fetch the CCADB report, and the process went very smoothly. This report has made the implementation much more straightforward than I anticipated. I'm grateful it exists, as I expected significant challenges in fetching and assembling roots.
Rather than adding special handling for these monitoring certificates (which would compromise the clean design), I wanted to ask: Is there any possibility these could be included in report, or are they intentionally excluded from its scope?
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/207395d5-3ef9-467f-9f70-82f21b147fd3%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/9b52ece4-13eb-4623-b879-8e06701a05c1%40app.fastmail.com.
Just curious, how much is "Logical Used" in zfs? And the compression algorithm you use / as well as the recordsize, if you can share that :)
logicalused is 535G, compression is the "on" default (lz4), and recordsize is the default (128K). Here's a full listing.
Note that Sunlight simply stores Static CT files on disk, and data tiles in Static CT are compressed with gzip. I am actually kinda surprised by the 1.28x compress ratio.
We’ve added the compliance monitoring root to the Production Logs report (the report that includes CAs trusted by at least one of the CCADB Root Store Operators). We still need to investigate the endpoint errors you referenced, and we’ll plan to report back shortly after reviewing.
Thank you
-Chris, on behalf of the Chrome CT team
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/68723675-cf3c-4ab2-a20e-ce8b732edd9e%40app.fastmail.com.
To view this discussion visit https://groups.google.com/d/msgid/certificate-transparency/e20eeabd-9620-426d-802e-0690acbbabfd%40app.fastmail.com.