|
|
|
|
|
by nickf
1121 days ago
|
|
Aside from what mjg59 said, it's clear you don't quite understand how CT works.
Logs are stood up and then go through a fairly rigorous acceptance process by Google (and Apple) before finally being used. 'Used' in that a CA can then submit pre-certs to it and include the resulting SCTs in signed certificates, making them functional on Chrome/Apple platforms. Even the CA using the log generally takes some communication with the log operator to ensure the right set of roots are trusted for submitted pre-certs. CT logs are used by CAs, not clients. A 'fake' log isn't a thing. |
|
(Not that I'm a DNSSEC user myself, my feet aren't bulletproof)