
Cloudflare has made its Certificate Transparency Monitoring generally available, with a practical change for hosting teams: alerts should now exclude the certificates Cloudflare itself issues for a customer’s zone.
The service watches public Certificate Transparency logs for new TLS certificates tied to customer domains. That is useful for spotting a mis-issued or unexpected certificate, but Cloudflare says the beta had become noisy because routine Universal SSL, Advanced Certificate Manager, backup certificate, and renewal activity also landed in the same public logs.
The timing matters for site operators. Publicly trusted certificates are moving toward shorter lifetimes, with the CA/Browser Forum voting to reduce maximum certificate validity to 47 days by 2029. Shorter lifetimes mean more legitimate renewals, which can make certificate-monitoring inboxes harder to triage unless managed issuance is filtered out.
Cloudflare says the updated monitoring path connects certificate issuance data with the CT alerting service so that routine Cloudflare-managed certificates are suppressed before an email is sent. The alerts that remain should represent certificates issued outside Cloudflare’s system and therefore deserve closer review by domain owners.
For hosting providers, agencies, and businesses running many domains, the change is a reminder that TLS visibility is now part of operational security. Certificate Transparency is only valuable if the alert stream is credible enough that administrators keep reading it.
Source: Cloudflare Blog — “Certificate Transparency Monitoring is now generally available”.