Checks

Certificate Transparency SCTs missing

The certificate itself does not contain Signed Certificate Timestamps.

Why it matters

Publicly trusted certificates are expected to be logged. Browsers can still accept SCTs delivered another way.

What to do

Ask the CA for a certificate that includes SCTs, or confirm the TLS handshake or OCSP staple provides them.

Reference

Publicly trusted certificates should include SCTs. Browsers also accept SCTs from the TLS handshake or OCSP.

Certificate Transparency