Safety
Expect-CT vs Certificate Transparency for Public TLS
September 6, 2023
Expect-CT vs Certificate Transparency is a leftover header versus a living ecosystem. Expect-CT told browsers to require CT evidence and optionally report failures. Chrome dropped enforcement; MDN marks the header obsolete. Shipping Expect-CT today is cargo-cult OPSEC. Certificate Transparency logs still record publicly trusted certificates. Operators should monitor new issuance for their names (CA mail, crt.sh-style search, or a vendor) and keep CAA tight. RoastMyOpsec's TLS check is HTTPS plus trust-store acceptance at scan time. It does not send Expect-CT, does not query CT logs, and does not watch expiry for you — see certificate expiry vs HSTS.
The practical difference
Expect-CT was a browser policy header. CT is a set of append-only logs CAs submit to. You can have CT without Expect-CT — that is the current world. You cannot resurrect Expect-CT into a useful control.
A surprise certificate in a log is an inventory event. It may be a CDN, a forgotten load balancer, or something you should revoke. CAA limits who should issue; CT helps you notice who did.
How to choose what to operate
Delete Expect-CT from the CDN template. Turn on issuance alerts at your CA or a CT monitor. Keep CAA current. Automate renewal. Do not add Expect-CT to a header checklist in 2026.
| Control | Status | Job | Takeaway |
|---|---|---|---|
| Expect-CT header | Obsolete | None in modern browsers | Remove it |
| CT logs | Current for public CAs | Public record of issuance | Monitor names you own |
| CAA | Current | Who may issue | See CAA vs registrar lock |
| HSTS + live cert | Current | This visit's transport | See expiry vs HSTS |
What the roast can see
TLS scheme and trust at scan time. Presence of Expect-CT is not a score bonus. Absence of CT monitoring is outside the HTTP response.
Common mistakes
The first mistake is a 2018 header pack that still requires Expect-CT.
The second mistake is ignoring a CT alert because 'we use Let's Encrypt.'
The third mistake is Expect-CT report-uri to an unattended inbox.
Free audit the URL you own
RoastMyOpsec is a defensive public-surface roast: headers, cookies, sensitive paths, and more — no exploit payloads. Start with the free audit, then open the vault if the blurred findings look expensive.
Free audit nowFAQ
- Should I enable Expect-CT?
- No. The header is obsolete. Monitor Certificate Transparency and CAA instead.
- Does RoastMyOpsec check CT logs?
- No. The TLS check is HTTPS and trust-store acceptance. Watch issuance in your CA or a CT monitor.
- Is a CT-logged cert a vulnerability?
- Logging is normal for public CAs. A cert you did not request is the finding — inventory and revoke if needed.