CT MONITORING

Frequently asked questions

What does CT stand for?

Certificate Transparency: an ecosystem of public, append-only logs for publicly trusted TLS certificates.

Are these figures exact?

The processed-entry counter is exact for these collectors. Distinct totals are estimates with an expected relative standard error of approximately 0.20%.

Why are entries higher than certificates?

The same certificate can be logged more than once, including across different CT logs. Precertificates also contribute entries.

What does reduced CT log coverage mean?

It means at least one monitored log has not recorded a recent successful update or is still processing delayed entries. Collection from other logs continues. Publicly trusted certificates normally have signed timestamps from multiple independent CT logs, so the same certificate or precertificate is commonly observed in more than one log. This overlap usually limits the immediate effect on aggregate distinct estimates and monitoring, making a short-lived reduction a warning rather than a collection outage.

Overlap is not guaranteed for every entry. Some entries may be unique to an affected log, so figures and monitoring remain provisional until collection catches up. The status page names affected logs when that detail was recorded.

Does a logged certificate mean it is trusted or in use?

No. Logging is evidence that a certificate or precertificate was submitted to a log, not that it is currently deployed, valid, trusted by every client or authorised by the domain owner.

How fresh is the data?

The public snapshot is updated every 15 minutes when the collectors and upload path are operating normally. The page displays the source timestamp.

Can I rely on this as a complete historical dataset?

No. The counters cover these collectors from the displayed start date and remain subject to log availability, CT log coverage and the limitations described in the methodology.