GoogleChrome / GoogleChrome/CertificateTransparency
Retrospective log disqualification scenarios
Open
- Dominant language
- HTML
- Stars
- 198
- Forks
- 104
- Avg merge
- 3d 48m
- Merged PRs (30d)
- 4
Description
There could be a situation where a log distrust action will have to be applied retrospectively. I.e., if it comes to light that a log has been maliciously operating over the last 6 months, I assume SCTs from such a log would have to be retrospectively rejected?
The current policy and the definition of "once qualified" doesn't seem to account for such a scenario. It allows for a SCT to be acceptable as long as the log was qualified at the time of cert issuance.
Contributor guide
Assessment
This issue has not been assessed yet.