From bf9012075e1da14309c3f24b8e7bf1eb67e54ba5 Mon Sep 17 00:00:00 2001 From: Dana Keeler Date: Sun, 26 Jan 2025 15:24:04 -0800 Subject: [PATCH] Firefox desktop now requires CT (#37777) * Firefox desktop now requires CT On desktop platforms, Firefox now requires certificate transparency information for all certificates issued by certificate authorities in Mozilla's Root CA Program. * Apply suggestions from code review --------- Co-authored-by: Hamish Willee --- files/en-us/web/security/certificate_transparency/index.md | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/files/en-us/web/security/certificate_transparency/index.md b/files/en-us/web/security/certificate_transparency/index.md index aab025e79b8d98d..779ba584ad8e8b8 100644 --- a/files/en-us/web/security/certificate_transparency/index.md +++ b/files/en-us/web/security/certificate_transparency/index.md @@ -34,8 +34,9 @@ With the latter methods, servers will need to be updated to send the required da ## Browser Requirements -Google Chrome requires CT log inclusion for all certificates issues with a notBefore date of after 30 April 2018. Users will be prevented from visiting sites using non-compliant TLS certificates. Chrome had previously required CT inclusion for _Extended Validation_ (EV) and Symantec-issued certificates. +Google Chrome 107 and later requires CT log inclusion for all certificates issued with a notBefore date of after 30 April 2018. Users will be prevented from visiting sites using non-compliant TLS certificates. +Chrome had previously required CT inclusion for _Extended Validation_ (EV) and Symantec-issued certificates. Apple [requires](https://support.apple.com/en-gb/103214) a varying number of SCTs in order for Safari and other servers to trust server certificates. -Firefox [does not](https://bugzil.la/1281469) currently check or require the use of CT logs for sites that users visit. +Firefox desktop from version 135 requires CT log inclusion for all certificates issued by certificate authorities in Mozilla's Root CA Program. Firefox for Android does not currently require CT log inclusion.