The Sunlight CT Log

pentestercrab1 pts0 comments

The Sunlight CT Log

The Sunlight CT Log

Sunlight is a Certificate Transparency<br>log implementation and monitoring API designed for scalability, ease of operation,<br>and reduced cost.

What started as the Sunlight API is now the Static CT API<br>and is allowed by the CT log policies of the major browsers.

Sunlight was designed by Filippo Valsorda for the<br>needs of the WebPKI community, through the feedback of many of its members,<br>and in particular of the Sigsum,<br>Google TrustFabric,<br>and ISRG teams.<br>It is partially based on the Go Checksum Database.<br>Sunlight's development was sponsored by Let's Encrypt.

If you have feedback on the design, please join the conversation on the<br>ct-policy mailing list,<br>or in the #sunlight channel<br>of the transparency-dev Slack.

For more information, read the<br>introductory blog post.

We have a set of resources for various WebPKI stakeholders. Are you…

… a log operator?<br>You can find the open source Sunlight implementation at<br>github.com/FiloSottile/sunlight<br>and the original design document,<br>including a description of the Sunlight architecture and tradeoffs,<br>at filippo.io/a-different-CT-log.

There are other implementations of Static CT:<br>Azul by Cloudflare, which was accompanyed by a<br>detailed blog post<br>that also presents the Static CT and Sunlight designs;<br>and Itko,<br>which exposes both the Static CT and RFC 6962 APIs.

… a CT monitor?<br>An easy to use Go client is available.<br>The Static CT API is fully specified at c2sp.org/static-ct-api,<br>and you can test against the logs below.

You might be happy to know that the object storage backends used by some<br>Static CT log read paths are nearly rate-limit free!

Andrew Ayer also published Sunglasses,<br>an RFC 6962 compatibility proxy for Static CT logs.

… a certificate authority? You can submit to Sunlight logs like to any other CT log!

You can use the Geomys or<br>Let's Encrypt logs for testing.

… looking for the logo?<br>You can find it here.<br>It's based on a real place in the vicinity of Rome, where the first commit was made.<br>Use it under the terms of the CC BY-ND 4.0 license.

sunlight static logs certificate transparency implementation

Related Articles