本站包含推广链接——通过链接注册我们可能获得佣金。

证书透明度日志搜索:查找您域名的所有SSL证书 (2026)

证书透明度日志搜索:查找您域名的所有SSL证书 (2026)

简介

Certificate Transparency (CT) คือ Framework ของ RFC 6962 ที่บังคับให้ Certificate Authority (CA) บันทึก SSL/TLS Certificate ทุกตัวที่ออกให้ลงใน Public Log ก่อนที่ Browser จะเชื่อถือ Certificate นั้น ทำให้ใครก็ตามสามารถตรวจสอบได้ว่ามี Certificate ออกมาชื่อโดเมนใดบ้าง

Certificate Transparency (CT, RFC 6962) is a cryptographically verifiable public audit log system that requires every trusted Certificate Authority to log every TLS certificate it issues before browsers will trust it. This public log makes it impossible for a CA to issue a certificate for your domain secretly — any certificate issued becomes publicly visible within minutes.

重要性

ก่อน CT มี CA หลายเจ้าออก Certificate ให้โดเมนที่ตัวเองไม่ได้เป็นเจ้าของโดยเจ้าของโดเมนไม่รู้เรื่อง เช่น กรณี CNNIC ออก Certificate สำหรับ Google.com โดยไม่ได้รับอนุญาต CT ทำให้เหตุการณ์เช่นนี้ถูกตรวจพบและแก้ไขได้ทันที

Before CT, Certificate Authorities occasionally issued certificates for domains without the domain owner's knowledge — either due to CA compromise, insider abuse, or domain validation failures. The 2013 CNNIC incident demonstrated this risk. CT solves this by making every certificate issuance publicly visible: domain owners can monitor CT logs and detect unauthorised certificates for their domains within minutes of issuance.

工作原理

CT Log คือ Cryptographically Verifiable Append-Only Log ที่ใช้โครงสร้าง Merkle Tree ทุกครั้งที่ CA ออก Certificate ต้องส่งไปยัง CT Log Server ก่อน CT Log ออก SCT (Signed Certificate Timestamp) กลับมา CA แนบ SCT ลงใน Certificate และส่งให้ผู้ขอ

Each CT log is implemented as a Merkle hash tree — a cryptographic data structure where each new entry extends the root hash in a provable way. When a CA submits a precertificate to a CT log, the log server returns a Signed Certificate Timestamp (SCT) — a cryptographic promise that the certificate will be permanently included in the log. The CA embeds the SCT in the final certificate. Browsers verify the SCT signature and optionally check the inclusion proof.

SCT时间戳

SCT (Signed Certificate Timestamp) คือลายเซ็นดิจิทัลจาก CT Log ที่รับประกันว่า Certificate จะถูกบันทึกใน Log อย่างถาวร Browser ใช้ SCT ยืนยันว่า Certificate ผ่าน CT ก่อนเชื่อถือ

A Signed Certificate Timestamp (SCT) is a cryptographically signed promise from a CT log that a specific certificate has been submitted and will be permanently logged. SCTs can be embedded in the certificate itself, delivered via TLS extension, or stapled in an OCSP response. Chrome requires at least two SCTs from different logs for a certificate to be trusted — this prevents a compromised log from being the sole attestor.

crt.sh数据库

crt.sh คือบริการของ Sectigo (เดิม Comodo CA) ที่รวบรวมข้อมูลจาก CT Log ทุกตัวและให้ค้นหา Certificate ตามโดเมน, Organization หรือ Fingerprint ได้ฟรี เครื่องมือ CT Log Search ที่ Analyze.in.th ใช้ crt.sh เป็น Backend

crt.sh is a free public CT log search service operated by Sectigo that aggregates certificate data from all major CT logs. It allows searching by domain name (including wildcard patterns with the % operator), organisation name, or certificate fingerprint. The Analyze.in.th CT Log Search tool queries crt.sh via its JSON API and presents results in a structured, readable format.

检测恶意证书

ขั้นตอนการตรวจ Rogue Certificate คือการค้นหา Certificate ทั้งหมดที่ออกสำหรับโดเมนของคุณ แล้วเทียบว่าตรงกับ Certificate ที่คุณขอจริงไหม Certificate ที่ไม่รู้จัก = ต้องสอบสวนทันที

To detect rogue certificates: query CT logs for all certificates issued for your domain (and subdomains using the wildcard pattern), then compare each result against certificates you actually requested. Any certificate you do not recognise — by CA, validity period, or subject — is a potential rogue certificate that warrants immediate investigation and revocation request.

  1. ค้นหาด้วย CT Log Search ที่ Analyze.in.th
  2. ดู Certificate ทั้งหมดที่ออกสำหรับโดเมนของคุณ รวม Wildcard Subdomain
  3. เทียบ CA ที่ออก Cert: ถ้าไม่ใช่ CA ที่คุณใช้ = สงสัย
  4. เทียบวันที่ Issue: Certificate ที่ออกก่อนที่คุณจะ Verify Domain = สงสัย
  5. ถ้าพบ Rogue Cert: รายงานไปยัง CA ที่ออก Cert ขอ Revoke ทันที

使用方法

เครื่องมือ CT Log Search ที่ Analyze.in.th ค้นหา Certificate ทั้งหมดในฐานข้อมูล crt.sh สำหรับโดเมนที่ระบุ แสดงผลแบบ Paginated พร้อม Status Active/Expired

The Analyze.in.th CT Log Search queries crt.sh for all certificates issued for a domain (including wildcard subdomains) and presents the results in a paginated table sorted newest-first. Each entry shows the certificate ID, common name, SAN list, validity dates, issuing CA, and active/expired status.

  1. เปิด https://dnsxray.com/ct-search.php
  2. พิมพ์ชื่อโดเมน เช่น example.com
  3. กด Search CT Logs
  4. ผลลัพธ์แสดง: Certificate ID, Common Name, SAN, วันหมดอายุ, CA, Status
  5. ใช้ Pagination ดู Certificate เพิ่มเติม (แสดงทีละ 50 รายการ)

The search automatically queries both the domain itself and the wildcard pattern (%.domain) to surface subdomain certificates. Results are deduplicated by certificate ID and sorted newest-first, with active certificates highlighted separately from expired ones.

监控方法

การ Monitor CT Log แบบ Manual ทุกครั้งไม่สะดวก เครื่องมือ Monitoring อัตโนมัติจะแจ้งเตือนทุกครั้งที่มี Certificate ใหม่ออกสำหรับโดเมนของคุณ

Manual CT log checks are useful for one-off audits but not for continuous monitoring. Automated CT monitoring services watch the public logs in near-real-time and alert you when a new certificate is issued for your domain. This gives you a short window to detect and respond to a rogue certificate before it can be abused.

主机推荐

Hosting ที่ดีต้องออก SSL Certificate ที่ผ่าน CT อย่างถูกต้อง ถ้าใช้ Hosting ที่ออก Self-Signed Certificate หรือ Certificate จาก CA ที่ไม่ถูก Trust โดย Browser ผู้เยี่ยมชมจะเห็น Certificate Error

Good hosting providers issue publicly trusted TLS certificates from recognised Certificate Authorities, with valid SCTs embedded. All major CAs — Let's Encrypt, DigiCert, Sectigo — log to CT automatically. If your hosting uses an in-house or untrusted CA for SSL, browser visitors will see certificate errors. AsiaGB.com provides hosting with SSD storage, DirectAdmin, and 24-hour Thai-language support.

推荐AsiaGB.com — 我们使用并推荐的虚拟主机和VPS服务。服务器位于泰国和新加坡,SSD存储,DirectAdmin控制面板,24小时泰语支持,99%正常运行时间。

编辑首选泰国虚拟主机 — 可靠、实惠且有本地支持。

访问 AsiaGB →

常见问题 (FAQ)

CT Log เก็บข้อมูลอะไรบ้าง
CT Log เก็บข้อมูล Certificate ทั้งหมดที่ CA Submit มา ได้แก่ ชื่อ Common Name, SAN (Subject Alternative Names), วันเริ่มต้น/หมดอายุ, Serial Number, Public Key, CA ที่ออก และ Timestamp ที่ Log รับ Certificate
ค้นหาใน CT Log ผิดกฎหมายไหม
ไม่ CT Log เป็นข้อมูลสาธารณะที่ทุกคนสามารถค้นหาได้ตามเจตนาของ RFC 6962 การค้นหาเพื่อ Monitor โดเมนตัวเองหรือตรวจสอบ Certificate เป็นการใช้งานที่ถูกต้องสมบูรณ์
CAA Record ป้องกัน Rogue Certificate ได้ไหม
ได้บางส่วน CAA (Certificate Authority Authorization) บอกว่า CA ใดมีสิทธิ์ออก Certificate สำหรับโดเมน CA ต้องตรวจ CAA ก่อน Issue ถ้าฝ่าฝืน = Violation ที่ปรากฏใน CT แต่ CAA ไม่ได้ป้องกัน 100% ถ้า CA มีบัคในการตรวจ
Certificate ที่ Revoke แล้วยังปรากฏใน CT ไหม
ยังปรากฏ CT Log เป็น Append-Only ลบข้อมูลไม่ได้ Certificate ที่ Revoke ยังอยู่ใน Log แต่ Browser ตรวจสถานะ Revocation ผ่าน OCSP หรือ CRL แยกต่างหาก สถานะ Revoke ไม่ได้ฝังอยู่ใน CT Entry โดยตรง