CLOUDFLARE has launched Certificate Transparency Monitoring (CTM) for over 650,000 customer domains, providing alerts when new TLS certificates appear in public logs. Previously, alerts were noisy due to many routine renewals from Cloudflare's own issuances. To address this, CTM now filters these out, ensuring users only receive alerts for unexpected certificates not issued by Cloudflare.
The updates enhance accuracy by utilizing a unique identifier, the Subject Public Key Info (SPKI), that remains consistent throughout a certificate's lifecycle. Alerts are now clearer and include relevant certificate details. Looking forward, Cloudflare plans to integrate CT monitoring with notifications for better alert management.