Introducing GoDaddy Static CT Logs: Peridot and Aquamarine

292 views
Skip to first unread message

Lee Sautia

unread,
Jul 8, 2026, 5:50:11 AMJul 8
to certificate-transparency

Hi everyone,

We're excited to announce two new Static Certificate Transparency logs operated by GoDaddy, built on the Sunlight implementation.

Staging logs (Peridot):

Production logs (Aquamarine):

Both logs accept all publicly trusted WebPKI roots (all roots in the Google, Apple, and Mozilla root programs).

Peridot is our staging environment — it currently accepts testing roots, and we're happy to add more. We'd welcome monitors and CAs to test against it and share any feedback.

Aquamarine is our production log, which we intend to submit for inclusion in the approved log lists for Google and Apple following validation of Peridot. We are internally targeting 99.9% uptime.

We plan to submit both logs for inclusion once initial testing is complete. Please note that GoDaddy is already submitting all newly issued certificates to the production log (Aquamarine). Feedback is very welcome — feel free to reach out at ct...@godaddy.com or find us on the Transparency Dev Slack.

Best,

Lee Sautia

GoDaddy

Filippo Valsorda

unread,
Jul 8, 2026, 12:08:34 PMJul 8
to certificate-...@googlegroups.com
Hi Lee,

This is great news, love to see new CT operators and I am glad Sunlight is proving useful.

Could you share some details on the backend? Does it use the POSIX filesystem backend or the S3 one?

Is the home page (like https://tuscolo.sunlight.geomys.org/) reachable anywhere? I run a Prometheus scrape of all Sunlight log metrics, and it's moderately useful while developing, so I don't have to guess as to the performance observed by other operators.

Cheers,
Filippo

Lee Sautia

unread,
Jul 13, 2026, 7:09:18 PMJul 13
to certificate-transparency
Hi Filippo,

Thanks, and thanks for Sunlight.

We are running Sunlight with the S3-compatible object storage backend. We are intentionally keeping the rest of the deployment architecture fairly minimal in public discussion: the logs sit behind standard HTTP serving infrastructure with independent monitoring and operational alerting on our side.

We do not currently plan to publish a home page or Prometheus metrics externally. We agree those can be useful for ecosystem visibility, but for now we are limiting public exposure to the CT API endpoints and the information required for log monitoring and CT program participation.

If we see operational issues that affect availability, correctness, latency, or MMD commitments, we will report those through the usual CT community/program channels.

Best,
Lee Sautia

Lee Sautia

unread,
Jul 21, 2026, 3:19:31 PM (9 days ago) Jul 21
to certificate-transparency

Hi everyone,

Following up on our earlier announcement of GoDaddy Static CT logs, we're also making available Verified Mark Certificate (VMC) specific Static CT logs built on the Sunlight implementation.

Staging VMC logs (Emerald):

Production VMC logs (Garnet):

These logs are for Verified Mark Certificates, not TLS server authentication certificates. They require the VMC EKU:

1.3.6.1.5.5.7.3.31

At minimum we will accept all BIMI approved roots:

https://bimigroup.org/vmc-issuers/

Emerald is our staging environment. Garnet is our production VMC log set. The logs use 60-second MMDs and are temporally sharded across 2026h2, 2027h1, and 2027h2.

Please note that these are mark-certificate-only logs. They reject ordinary TLS certificates, submissions without the VMC EKU, certificates outside the configured shard interval, and chains outside the accepted mark root set.

Best,

Lee Sautia | GoDaddy

r...@sectigo.com

unread,
Jul 22, 2026, 3:59:31 PM (8 days ago) Jul 22
to certificate-transparency
Hi Lee.

> We'd welcome monitors and CAs to test against it and share any feedback.

To enable that testing, are you able to share the public keys for each of the Peridot, Aquamarine, Emerald, and Garnet logs?

Andrew Ayer

unread,
Jul 22, 2026, 4:03:41 PM (8 days ago) Jul 22
to certificate-...@googlegroups.com
On Wed, 22 Jul 2026 12:59:30 -0700 (PDT)
"'r...@sectigo.com' via certificate-transparency"
<certificate-...@googlegroups.com> wrote:

> > We'd welcome monitors and CAs to test against it and share any
> > feedback.
>
> To enable that testing, are you able to share the public keys for
> each of the Peridot, Aquamarine, Emerald, and Garnet logs?

They're running Sunlight so you can just fetch log.v3.json :-D

e.g. https://ct-log-api-vmark.ote-godaddy.com/emerald2026h2/log.v3.json

r...@sectigo.com

unread,
Jul 22, 2026, 4:05:27 PM (8 days ago) Jul 22
to certificate-transparency
Ah, of course.  Thanks Andrew!
Reply all
Reply to author
Forward
0 new messages