ct-tools icon indicating copy to clipboard operation
ct-tools copied to clipboard

ct-tools seems to trip over AIA chasing via crt.sh if input is more than >25-50 certifices

Open jochemvdberge opened this issue 6 years ago • 1 comments

Although I know that the AIA chasing via crt.sh was meant as a stopgap measure (I read the comments in the code) I do rely on it for submitting previously unknown certs to CT logs when I don't have the complete chain included. When submitting larger number of certificates the chain building fails and as such incomplete certificates are offered to CT logs with predictable results. Maybe it could be a rate limit bij crt.sh per IP-address?

jochemvdberge avatar Aug 27 '19 11:08 jochemvdberge

Manage to work around it with a bash script... but the issue of AIA chasing is still a valid one I think? ;-)

jochemvdberge avatar Aug 27 '19 11:08 jochemvdberge