Apple's list of trusted logs

121 views
Skip to first unread message

Alex Cohn

unread,
Apr 4, 2017, 5:23:09 PM4/4/17
to certificate-transparency
I was reading through Apple's documentation for their App Transport Security system, and it apparently has an app-level flag to require CT for certain domains, called NSRequiresCertificateTransparency: https://developer.apple.com/library/content/documentation/General/Reference/InfoPlistKeyReference/Articles/CocoaKeys.html#//apple_ref/doc/uid/TP40009251-SW58

To pass this check, a domain "must prove to the system that its X.509 digital certificate is present in at least two CT logs trusted by Apple." However, I have not been able to find an authoritative source for Apple's list of trusted logs anywhere - the closest I have found is https://opensource.apple.com/source/security_certificates/security_certificates-55070.1.1/certificate_transparency/log_list.json.auto.html, but there's nothing I've found that actually says this is the list Apple ships.

Does anyone know where Apple's list lives? 

Also, while the official log list on certificate-transparency.org is being reworked, would it make sense to add a "trusted by Apple" field to the relevant logs? In addition to being useful info, it might help to convince people that CT is more than just a Chromium/Google thing.

Alex
Reply all
Reply to author
Forward
0 new messages