เว็บนี้มีลิงก์ affiliate — หากสมัครผ่านลิงก์ เราได้รับค่าคอมมิชชัน · Affiliate links.

Certificate Transparency Log คืออะไร วิธีค้นหา Certificate ด้วย Analyze.in.th 2026

What is Certificate Transparency, how to search CT logs for any domain, and how to detect rogue certificates using the free CT Log Search at Analyze.in.th

Certificate Transparency Log คืออะไร วิธีค้นหา Certificate ด้วย Analyze.in.th 2026

Certificate Transparency คืออะไร

Certificate Transparency (CT) คือ Framework ของ RFC 6962 ที่บังคับให้ Certificate Authority (CA) บันทึก SSL/TLS Certificate ทุกตัวที่ออกให้ลงใน Public Log ก่อนที่ Browser จะเชื่อถือ Certificate นั้น ทำให้ใครก็ตามสามารถตรวจสอบได้ว่ามี Certificate ออกมาชื่อโดเมนใดบ้าง

Certificate Transparency (CT, RFC 6962) is a cryptographically verifiable public audit log system that requires every trusted Certificate Authority to log every TLS certificate it issues before browsers will trust it. This public log makes it impossible for a CA to issue a certificate for your domain secretly — any certificate issued becomes publicly visible within minutes.

ทำไม CT Log ถึงสำคัญ

ก่อน CT มี CA หลายเจ้าออก Certificate ให้โดเมนที่ตัวเองไม่ได้เป็นเจ้าของโดยเจ้าของโดเมนไม่รู้เรื่อง เช่น กรณี CNNIC ออก Certificate สำหรับ Google.com โดยไม่ได้รับอนุญาต CT ทำให้เหตุการณ์เช่นนี้ถูกตรวจพบและแก้ไขได้ทันที

Before CT, Certificate Authorities occasionally issued certificates for domains without the domain owner's knowledge — either due to CA compromise, insider abuse, or domain validation failures. The 2013 CNNIC incident demonstrated this risk. CT solves this by making every certificate issuance publicly visible: domain owners can monitor CT logs and detect unauthorised certificates for their domains within minutes of issuance.

CT Log ทำงานอย่างไร

CT Log คือ Cryptographically Verifiable Append-Only Log ที่ใช้โครงสร้าง Merkle Tree ทุกครั้งที่ CA ออก Certificate ต้องส่งไปยัง CT Log Server ก่อน CT Log ออก SCT (Signed Certificate Timestamp) กลับมา CA แนบ SCT ลงใน Certificate และส่งให้ผู้ขอ

Each CT log is implemented as a Merkle hash tree — a cryptographic data structure where each new entry extends the root hash in a provable way. When a CA submits a precertificate to a CT log, the log server returns a Signed Certificate Timestamp (SCT) — a cryptographic promise that the certificate will be permanently included in the log. The CA embeds the SCT in the final certificate. Browsers verify the SCT signature and optionally check the inclusion proof.

SCT: หลักฐานที่ CT Log ยอมรับ Certificate

SCT (Signed Certificate Timestamp) คือลายเซ็นดิจิทัลจาก CT Log ที่รับประกันว่า Certificate จะถูกบันทึกใน Log อย่างถาวร Browser ใช้ SCT ยืนยันว่า Certificate ผ่าน CT ก่อนเชื่อถือ

A Signed Certificate Timestamp (SCT) is a cryptographically signed promise from a CT log that a specific certificate has been submitted and will be permanently logged. SCTs can be embedded in the certificate itself, delivered via TLS extension, or stapled in an OCSP response. Chrome requires at least two SCTs from different logs for a certificate to be trusted — this prevents a compromised log from being the sole attestor.

crt.sh: Database CT Log สาธารณะ

crt.sh คือบริการของ Sectigo (เดิม Comodo CA) ที่รวบรวมข้อมูลจาก CT Log ทุกตัวและให้ค้นหา Certificate ตามโดเมน, Organization หรือ Fingerprint ได้ฟรี เครื่องมือ CT Log Search ที่ Analyze.in.th ใช้ crt.sh เป็น Backend

crt.sh is a free public CT log search service operated by Sectigo that aggregates certificate data from all major CT logs. It allows searching by domain name (including wildcard patterns with the % operator), organisation name, or certificate fingerprint. The Analyze.in.th CT Log Search tool queries crt.sh via its JSON API and presents results in a structured, readable format.

วิธีใช้ CT เพื่อตรวจ Rogue Certificate

ขั้นตอนการตรวจ Rogue Certificate คือการค้นหา Certificate ทั้งหมดที่ออกสำหรับโดเมนของคุณ แล้วเทียบว่าตรงกับ Certificate ที่คุณขอจริงไหม Certificate ที่ไม่รู้จัก = ต้องสอบสวนทันที

To detect rogue certificates: query CT logs for all certificates issued for your domain (and subdomains using the wildcard pattern), then compare each result against certificates you actually requested. Any certificate you do not recognise — by CA, validity period, or subject — is a potential rogue certificate that warrants immediate investigation and revocation request.

  1. ค้นหาด้วย CT Log Search ที่ Analyze.in.th
  2. ดู Certificate ทั้งหมดที่ออกสำหรับโดเมนของคุณ รวม Wildcard Subdomain
  3. เทียบ CA ที่ออก Cert: ถ้าไม่ใช่ CA ที่คุณใช้ = สงสัย
  4. เทียบวันที่ Issue: Certificate ที่ออกก่อนที่คุณจะ Verify Domain = สงสัย
  5. ถ้าพบ Rogue Cert: รายงานไปยัง CA ที่ออก Cert ขอ Revoke ทันที

วิธีใช้ CT Log Search ที่ Analyze.in.th

เครื่องมือ CT Log Search ที่ Analyze.in.th ค้นหา Certificate ทั้งหมดในฐานข้อมูล crt.sh สำหรับโดเมนที่ระบุ แสดงผลแบบ Paginated พร้อม Status Active/Expired

The Analyze.in.th CT Log Search queries crt.sh for all certificates issued for a domain (including wildcard subdomains) and presents the results in a paginated table sorted newest-first. Each entry shows the certificate ID, common name, SAN list, validity dates, issuing CA, and active/expired status.

  1. เปิด https://dnsxray.com/ct-search.php
  2. พิมพ์ชื่อโดเมน เช่น example.com
  3. กด Search CT Logs
  4. ผลลัพธ์แสดง: Certificate ID, Common Name, SAN, วันหมดอายุ, CA, Status
  5. ใช้ Pagination ดู Certificate เพิ่มเติม (แสดงทีละ 50 รายการ)

The search automatically queries both the domain itself and the wildcard pattern (%.domain) to surface subdomain certificates. Results are deduplicated by certificate ID and sorted newest-first, with active certificates highlighted separately from expired ones.

วิธี Monitor CT Log สำหรับโดเมนของคุณ

การ Monitor CT Log แบบ Manual ทุกครั้งไม่สะดวก เครื่องมือ Monitoring อัตโนมัติจะแจ้งเตือนทุกครั้งที่มี Certificate ใหม่ออกสำหรับโดเมนของคุณ

Manual CT log checks are useful for one-off audits but not for continuous monitoring. Automated CT monitoring services watch the public logs in near-real-time and alert you when a new certificate is issued for your domain. This gives you a short window to detect and respond to a rogue certificate before it can be abused.

SSL Hosting ที่มีคุณภาพ

Hosting ที่ดีต้องออก SSL Certificate ที่ผ่าน CT อย่างถูกต้อง ถ้าใช้ Hosting ที่ออก Self-Signed Certificate หรือ Certificate จาก CA ที่ไม่ถูก Trust โดย Browser ผู้เยี่ยมชมจะเห็น Certificate Error

Good hosting providers issue publicly trusted TLS certificates from recognised Certificate Authorities, with valid SCTs embedded. All major CAs — Let's Encrypt, DigiCert, Sectigo — log to CT automatically. If your hosting uses an in-house or untrusted CA for SSL, browser visitors will see certificate errors. AsiaGB.com provides hosting with SSD storage, DirectAdmin, and 24-hour Thai-language support.

แนะนำAsiaGB.com — Web Hosting & VPS ที่เราใช้และแนะนำ เซิร์ฟเวอร์ในไทยและสิงคโปร์ สตอเรจ SSD จัดการผ่าน DirectAdmin พร้อมทีม Support ภาษาไทย 24 ชั่วโมง uptime 99%

AsiaGB.com — hosting & VPS we use and recommend: TH/SG servers, SSD storage, DirectAdmin, 24h Thai support, 99% uptime.

เยี่ยมชม AsiaGB →

คำถามที่พบบ่อย (FAQ)

CT Log เก็บข้อมูลอะไรบ้าง
CT Log เก็บข้อมูล Certificate ทั้งหมดที่ CA Submit มา ได้แก่ ชื่อ Common Name, SAN (Subject Alternative Names), วันเริ่มต้น/หมดอายุ, Serial Number, Public Key, CA ที่ออก และ Timestamp ที่ Log รับ Certificate
ค้นหาใน CT Log ผิดกฎหมายไหม
ไม่ CT Log เป็นข้อมูลสาธารณะที่ทุกคนสามารถค้นหาได้ตามเจตนาของ RFC 6962 การค้นหาเพื่อ Monitor โดเมนตัวเองหรือตรวจสอบ Certificate เป็นการใช้งานที่ถูกต้องสมบูรณ์
CAA Record ป้องกัน Rogue Certificate ได้ไหม
ได้บางส่วน CAA (Certificate Authority Authorization) บอกว่า CA ใดมีสิทธิ์ออก Certificate สำหรับโดเมน CA ต้องตรวจ CAA ก่อน Issue ถ้าฝ่าฝืน = Violation ที่ปรากฏใน CT แต่ CAA ไม่ได้ป้องกัน 100% ถ้า CA มีบัคในการตรวจ
Certificate ที่ Revoke แล้วยังปรากฏใน CT ไหม
ยังปรากฏ CT Log เป็น Append-Only ลบข้อมูลไม่ได้ Certificate ที่ Revoke ยังอยู่ใน Log แต่ Browser ตรวจสถานะ Revocation ผ่าน OCSP หรือ CRL แยกต่างหาก สถานะ Revoke ไม่ได้ฝังอยู่ใน CT Entry โดยตรง