证书透明度日志搜索:查找您域名的所有SSL证书 (2026)
简介
Certificate Transparency (CT) คือ Framework ของ RFC 6962 ที่บังคับให้ Certificate Authority (CA) บันทึก SSL/TLS Certificate ทุกตัวที่ออกให้ลงใน Public Log ก่อนที่ Browser จะเชื่อถือ Certificate นั้น ทำให้ใครก็ตามสามารถตรวจสอบได้ว่ามี Certificate ออกมาชื่อโดเมนใดบ้าง
Certificate Transparency (CT, RFC 6962) is a cryptographically verifiable public audit log system that requires every trusted Certificate Authority to log every TLS certificate it issues before browsers will trust it. This public log makes it impossible for a CA to issue a certificate for your domain secretly — any certificate issued becomes publicly visible within minutes.
- บังคับโดย Google Chrome ตั้งแต่ 2018 (Certificate ที่ไม่ Log = ไม่ Trusted)
- Apple Safari บังคับตั้งแต่ 2021
- CA ทุกเจ้าต้องส่ง Certificate ให้ CT Log ก่อน Issue
- CT Log เป็น Append-Only (ลบข้อมูลไม่ได้ = ตรวจสอบได้ตลอด)
- มี Log Provider หลายเจ้า: Google Argon, Cloudflare Nimbus, DigiCert Yeti
重要性
ก่อน CT มี CA หลายเจ้าออก Certificate ให้โดเมนที่ตัวเองไม่ได้เป็นเจ้าของโดยเจ้าของโดเมนไม่รู้เรื่อง เช่น กรณี CNNIC ออก Certificate สำหรับ Google.com โดยไม่ได้รับอนุญาต CT ทำให้เหตุการณ์เช่นนี้ถูกตรวจพบและแก้ไขได้ทันที
Before CT, Certificate Authorities occasionally issued certificates for domains without the domain owner's knowledge — either due to CA compromise, insider abuse, or domain validation failures. The 2013 CNNIC incident demonstrated this risk. CT solves this by making every certificate issuance publicly visible: domain owners can monitor CT logs and detect unauthorised certificates for their domains within minutes of issuance.
- ตรวจจับ Rogue Certificate: CA ออก Cert ให้โดเมนคุณโดยไม่ได้รับอนุญาต
- ตรวจจับ CA Mis-issuance: CA ออก Cert ผิดขั้นตอน
- Monitor Subdomain: ค้นหา Cert ที่ออกสำหรับ Subdomain ที่คุณไม่ได้ขอ
- Audit Certificate Lifecycle: ดูว่า Cert หมดอายุเมื่อไรและถูก Revoke ไหม
- เครื่องมือ Security: CT Log ใช้ตรวจสอบระบบ PKI ทั้งหมด
工作原理
CT Log คือ Cryptographically Verifiable Append-Only Log ที่ใช้โครงสร้าง Merkle Tree ทุกครั้งที่ CA ออก Certificate ต้องส่งไปยัง CT Log Server ก่อน CT Log ออก SCT (Signed Certificate Timestamp) กลับมา CA แนบ SCT ลงใน Certificate และส่งให้ผู้ขอ
Each CT log is implemented as a Merkle hash tree — a cryptographic data structure where each new entry extends the root hash in a provable way. When a CA submits a precertificate to a CT log, the log server returns a Signed Certificate Timestamp (SCT) — a cryptographic promise that the certificate will be permanently included in the log. The CA embeds the SCT in the final certificate. Browsers verify the SCT signature and optionally check the inclusion proof.
- CA Submit "Pre-Certificate" ไปยัง CT Log
- CT Log ออก SCT (Signed Certificate Timestamp) กลับมา
- CA ใส่ SCT ลงใน Certificate
- Browser ตรวจ SCT ว่ามี Signature จาก Trusted Log
- Chrome ต้องการ SCT อย่างน้อย 2 SCT จาก Log ที่ Trust
SCT时间戳
SCT (Signed Certificate Timestamp) คือลายเซ็นดิจิทัลจาก CT Log ที่รับประกันว่า Certificate จะถูกบันทึกใน Log อย่างถาวร Browser ใช้ SCT ยืนยันว่า Certificate ผ่าน CT ก่อนเชื่อถือ
A Signed Certificate Timestamp (SCT) is a cryptographically signed promise from a CT log that a specific certificate has been submitted and will be permanently logged. SCTs can be embedded in the certificate itself, delivered via TLS extension, or stapled in an OCSP response. Chrome requires at least two SCTs from different logs for a certificate to be trusted — this prevents a compromised log from being the sole attestor.
- SCT ฝังอยู่ใน Certificate Extensions ของ TLS Cert
- Chrome ต้องการ ≥2 SCT จาก Log ที่ต่างกัน
- SCT แต่ละตัวมี: Log ID, Timestamp, Signature
- Browser ตรวจ SCT Signature ก่อน Trust Certificate
- ถ้าไม่มี SCT = Browser แสดง Certificate Error
crt.sh数据库
crt.sh คือบริการของ Sectigo (เดิม Comodo CA) ที่รวบรวมข้อมูลจาก CT Log ทุกตัวและให้ค้นหา Certificate ตามโดเมน, Organization หรือ Fingerprint ได้ฟรี เครื่องมือ CT Log Search ที่ Analyze.in.th ใช้ crt.sh เป็น Backend
crt.sh is a free public CT log search service operated by Sectigo that aggregates certificate data from all major CT logs. It allows searching by domain name (including wildcard patterns with the % operator), organisation name, or certificate fingerprint. The Analyze.in.th CT Log Search tool queries crt.sh via its JSON API and presents results in a structured, readable format.
- crt.sh รวม Log จาก: Google Argon, Cloudflare Nimbus, DigiCert Yeti, Sectigo Mammoth
- ค้นหา Wildcard:
%.example.com= Subdomain ทั้งหมด - JSON API:
https://crt.sh/?q=%.example.com&output=json - ข้อมูลในแต่ละ Cert: Serial, Subject CN, SAN, Valid From/To, CA, Log
- บางครั้ง crt.sh อาจช้าหรือ Timeout ในช่วง Peak
检测恶意证书
ขั้นตอนการตรวจ Rogue Certificate คือการค้นหา Certificate ทั้งหมดที่ออกสำหรับโดเมนของคุณ แล้วเทียบว่าตรงกับ Certificate ที่คุณขอจริงไหม Certificate ที่ไม่รู้จัก = ต้องสอบสวนทันที
To detect rogue certificates: query CT logs for all certificates issued for your domain (and subdomains using the wildcard pattern), then compare each result against certificates you actually requested. Any certificate you do not recognise — by CA, validity period, or subject — is a potential rogue certificate that warrants immediate investigation and revocation request.
- ค้นหาด้วย CT Log Search ที่ Analyze.in.th
- ดู Certificate ทั้งหมดที่ออกสำหรับโดเมนของคุณ รวม Wildcard Subdomain
- เทียบ CA ที่ออก Cert: ถ้าไม่ใช่ CA ที่คุณใช้ = สงสัย
- เทียบวันที่ Issue: Certificate ที่ออกก่อนที่คุณจะ Verify Domain = สงสัย
- ถ้าพบ Rogue Cert: รายงานไปยัง CA ที่ออก Cert ขอ Revoke ทันที
使用方法
เครื่องมือ CT Log Search ที่ Analyze.in.th ค้นหา Certificate ทั้งหมดในฐานข้อมูล crt.sh สำหรับโดเมนที่ระบุ แสดงผลแบบ Paginated พร้อม Status Active/Expired
The Analyze.in.th CT Log Search queries crt.sh for all certificates issued for a domain (including wildcard subdomains) and presents the results in a paginated table sorted newest-first. Each entry shows the certificate ID, common name, SAN list, validity dates, issuing CA, and active/expired status.
- เปิด https://dnsxray.com/ct-search.php
- พิมพ์ชื่อโดเมน เช่น
example.com - กด Search CT Logs
- ผลลัพธ์แสดง: Certificate ID, Common Name, SAN, วันหมดอายุ, CA, Status
- ใช้ Pagination ดู Certificate เพิ่มเติม (แสดงทีละ 50 รายการ)
The search automatically queries both the domain itself and the wildcard pattern (%.domain) to surface subdomain certificates. Results are deduplicated by certificate ID and sorted newest-first, with active certificates highlighted separately from expired ones.
监控方法
การ Monitor CT Log แบบ Manual ทุกครั้งไม่สะดวก เครื่องมือ Monitoring อัตโนมัติจะแจ้งเตือนทุกครั้งที่มี Certificate ใหม่ออกสำหรับโดเมนของคุณ
Manual CT log checks are useful for one-off audits but not for continuous monitoring. Automated CT monitoring services watch the public logs in near-real-time and alert you when a new certificate is issued for your domain. This gives you a short window to detect and respond to a rogue certificate before it can be abused.
- certspotter.com: Free Monitoring สำหรับ 1 โดเมน Email แจ้งเตือนทันทีที่มี Cert ใหม่
- crt.sh RSS Feed: Subscribe RSS ของโดเมนสำหรับ Alert
- Certificate Authority Authorization (CAA): DNS Record ที่จำกัดว่า CA ใดออก Cert สำหรับโดเมนได้
- CAA Record ตัวอย่าง:
example.com. CAA 0 issue "letsencrypt.org;" - CAA ไม่ได้ป้องกัน 100% แต่ CA ต้องตรวจ CAA ก่อน Issue และ Violation ปรากฏใน CT
主机推荐
Hosting ที่ดีต้องออก SSL Certificate ที่ผ่าน CT อย่างถูกต้อง ถ้าใช้ Hosting ที่ออก Self-Signed Certificate หรือ Certificate จาก CA ที่ไม่ถูก Trust โดย Browser ผู้เยี่ยมชมจะเห็น Certificate Error
Good hosting providers issue publicly trusted TLS certificates from recognised Certificate Authorities, with valid SCTs embedded. All major CAs — Let's Encrypt, DigiCert, Sectigo — log to CT automatically. If your hosting uses an in-house or untrusted CA for SSL, browser visitors will see certificate errors. AsiaGB.com provides hosting with SSD storage, DirectAdmin, and 24-hour Thai-language support.
- ตรวจ SSL Certificate ของ Hosting: ใช้ Analyze.in.th SSL Checker
- ตรวจ Certificate ใน CT Log: CT Log Search
- Let's Encrypt ฟรีสำหรับทุก Hosting ที่รองรับ
- AsiaGB.com: Hosting SSD, DirectAdmin, ทีม Support ภาษาไทย 24 ชม.