What Is Certificate Transparency?

Certificate Transparency is a system of public, append-only logs that record every TLS certificate a certificate authority issues, so a mis-issued or fraudulent certificate cannot stay hidden. Standardised as RFC 6962, it uses Merkle trees to let anyone verify that a certificate was logged and that the log has not been tampered with. It is the working template for the estate’s own transparency log over sealed claims.

Logs
Every issued TLS certificate, publicly
Standard
RFC 6962, built on Merkle trees
Guarantees
Append-only, independently auditable

Making misissuance visible

Before Certificate Transparency, a compromised or coerced certificate authority could issue a certificate for a domain and no one would necessarily know. CT requires certificates to be logged in public, append-only logs, so domain owners and auditors can watch for certificates they did not request, and the log’s Merkle structure makes any tampering detectable.

The pattern — a public append-only log whose integrity anyone can check — is exactly what the estate’s checkpoint and transparency formats apply to sealed claims, so a record’s presence and order can be proven to a stranger.

Related standards

RFC 6962 — Certificate Transparency

Questions

Does CT stop a bad certificate being issued?

No — it makes issuance visible after the fact, so misissuance is detected quickly rather than prevented silently.

What does it have to do with agents?

It is the proven design for an auditable, append-only record — the same guarantee the estate needs for the claims agents seal.

Keep reading

related
What Is a Merkle Tree?
related
What Is a Cryptographic Hash Function?
related
What Is a Trust Graph for Agents?
related
How Do You Audit an Autonomous AI Agent?
Trust & the Record
Verify, Don’t Trust: Verification for AI Agents
Trust & the Record
Provenance for Autonomous Actions
Trust & the Record
How Is AI Agent Reputation Earned and Verified?
Trust & the Record
Zero-Trust Architecture for AI Agents
Trust & the Record
What Is Agent Attestation?
Trust & the Record
What Is a Zero-Knowledge Proof?
Trust & the Record
What Is a zk-Rollup?
Trust & the Record
What Is a Blockchain Oracle?
Trust & the Record
What Is Confidential Computing?
Trust & the Record
zk-Rollup vs Optimistic Rollup: What’s the Difference?
Trust & the Record
TEEs vs Zero-Knowledge Proofs: Two Roads to Privacy
Trust & the Record
What Is Public-Key Cryptography?
Trust & the Record
What Is a Digital Signature?
Trust & the Record
What Is Mutual TLS (mTLS)?
Trust & the Record
What Is a Sybil Attack?
Trust & the Record
Symmetric vs Asymmetric Encryption: What’s the Difference?
Trust & the Record
Hashing vs Encryption: What’s the Difference?

By Michael Gord · published 2026-10-09 · part of the Agentic Encyclopedia. Dates are the day of publication; events are cited at their own dates.