The Wiert Corner – irregular stream of stuff

Jeroen W. Pluimers on .NET, C#, Delphi, databases, and personal interests

  • My badges

  • Twitter Updates

  • My Flickr Stream

  • Pages

  • All categories

  • Enter your email address to subscribe to this blog and receive notifications of new posts by email.

    Join 1,860 other subscribers

crt.sh allows you to search for the history of TLS certificates for domains (example: *.wiert.me)

Posted by jpluimers on 2024/11/19

I while ago, I bumped into [Wayback/Archive] crt.sh | Certificate Search that allows searching for (the history of) TLS certificates.

One example of what it returns is [Wayback/Archive] crt.sh | wiert.me (for my blog domain and subdomains).

The basic mechanism of crt.sh is to query various Certificate Transparency logs and Certificate revocation list, terms I vaguely knew, but never fully realised the vast usefulness of (including questions like [Wayback/Archive] How does crt.sh becomes aware of certificates that are in no CT logs?).

The cool thing is that most (everything?) of it is open source in the various repositories at [Wayback/Archive] Github: crt.sh.

There is also an advanced search page [Wayback/Archive] crt.sh | Certificate Search (a=1) with many more options (including linting) I really want to try later plus a bunch of background links (including the support forum at) of which some *.crt.sh returned a http 502 while writing this blog post. Will try later to see if they have started working again:

crt.sh [Wayback/Archive] Forum
[Wayback/Archive] Certificate Populations
[Wayback/Archive] Revoked Intermediates
[Wayback/Archive] CA Issuers
[Wayback/Archive] OCSP Responders
[Wayback/Archive] Test Websites
Linting [Wayback/Archive] TBSCertificate Linter
[Wayback/Archive] Certificate Linter
CT [Wayback/Archive] Monitored Logs
[Wayback/Archive] Certificate Submission Assistant
Mozilla [Wayback/Archive] CA Certificate Disclosures
[Wayback/Archive] Certificate Validations
[Wayback/Archive] OneCRL

Via [Wayback] Archive.is blog — archive ph occasionally serves an invalid…

Anonymous said: archive ph occasionally serves an invalid certificate (digicert instead of lets encrypt)

Answer: digicert is not mine [Wayback/Archive] https://crt.sh/?q=archive.ph

--jeroen

Leave a comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.