# Certificate Transparency
## 概要
**Certificate Transparency(CT)** は、証明書の発行を追跡・監査するための公開ログの仕組みである。[[認証局とPKIの信頼モデル]] が記録するとおり、2011 年の DigiNotar 事件をはじめとする不正発行事案を受け、ブラウザベンダーが中心となって整備した是正策の一つに数えられ、[[Google]] が 2013 年に最初のログを開始し、2018 年には主要ブラウザが全ての公的に信頼される CA に対して CT へのログ記録を事実上義務化した。(Source: [[@2020__Wiley__Security Engineering 3e - Chapter 21 Network Attack and Defence]] ch.21 §21.6)
## Google 自身の CA における実装(ch.11)
[[@2020__OReilly__Building Secure and Reliable Systems - Chapter 11 Case Study - Designing, Implementing, and Maintaining a Publicly Trusted CA]] は、CT を「証明書を監視・監査する方法」と位置づけ、ドメイン検証手法(DNS・HTTP 等)と並んで、Google が商用 CA ソフトウェアの購入ではなく自前実装を選んだ理由の一つに挙げる——新しいエコシステムの取り組みに早期に追従できる柔軟性が、独自 CA の強みだと説明している。実際の発行パイプラインでは、リンタによる検証を通過した証明書を CT ログに登録して公衆による継続的な検証を可能にし、さらに複数の独立したログシステムをエントリ単位で突き合わせて不正発行の最終防衛線とする。これらのログはリポジトリに届く前に署名され、後日の検証に備える。(Source: [[@2020__OReilly__Building Secure and Reliable Systems - Chapter 11 Case Study - Designing, Implementing, and Maintaining a Publicly Trusted CA]] §Design, Implementation, and Maintenance Considerations > Data Validation)
## 出典
- Ross Anderson, *Security Engineering: A Guide to Building Dependable Distributed Systems*, 3rd Edition, John Wiley & Sons, 2020, Chapter 21, §21.6.
- Andy Warner et al., in Heather Adkins et al. (eds.), *Building Secure and Reliable Systems*, O'Reilly Media, 2020, Chapter 11.