Open
Description
- Draft Spec
- https://scotthelme.co.uk/a-new-security-header-expect-ct/
- Chrome feature available since chrome 61
Client side support
- Support for Expect-CT header in lpeg_patterns (Tracking issue: Expect-CT http header lpeg_patterns#11)
- Track known expect-ct hosts
- Support report-uri
- This requires json library
- May want to turn off by default for privacy?
-
UAs SHOULD limit the rate at which they send reports. For example, it is unnecessary to send the same report to the same "report-uri" more than once.
- Come up with a CT Policy
- Google's
- Need to include default log providers? See https://www.certificate-transparency.org/known-logs