Certificate Transparency Monitoring is now generally available
Blog post from Cloudflare
Cloudflare has made its Certificate Transparency Monitoring service generally available after redesigning it to suppress alerts for certificates that Cloudflare itself issues and renews, reducing routine notification noise across more than 650,000 monitored domains. The change addresses frequent alerts caused by short-lived Universal SSL, Advanced Certificate Manager, Total TLS, and backup certificates, whose issuance must be publicly recorded in Certificate Transparency logs. Cloudflare connected its certificate-ordering and alerting systems using an SHA-256 hash of the certificate’s SubjectPublicKeyInfo public key, which is generated early, remains consistent across certificate lifecycle stages, and can be independently recalculated from log entries. This enables the service to recognize and suppress Cloudflare-managed pre-certificates and final certificates while continuing to alert customers about externally issued or uploaded custom certificates. Updated alert emails now identify the affected hostname, provide certificate details, and link to the Cloudflare dashboard, while planned integration with Cloudflare Notifications may add routing to webhooks, PagerDuty, and additional email destinations.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.