• Sources: primary, discussion
  • Summary: The post, dated 2026-08-13, states that the feature is on for more than 650,000 customer domains and that until now every Cloudflare-issued renewal generated an alert, which buried the mis-issuance the alert exists for. Cloudflare now records spki_sha256, a hash of the DER-encoded SubjectPublicKeyInfo, at key generation before issuance begins, and the alerter recomputes it from each log entry and suppresses on a match, which works because the SPKI is identical in the pre-certificate and the final certificate, while the existing stripped_fingerprint key could not be computed by the ordering service that never receives the pre-certificate. Universal SSL, Advanced Certificate Manager, Total TLS, and Backup Certificates now pass silently, abandoned pre-certificates stop alerting, customer-uploaded custom certificates still alert, and the filtering is already enabled with no customer action.
  • Why it matters: Anyone who turned the feature off over renewal noise can turn it back on, and the CA/Browser Forum vote to cut maximum certificate lifetime to 47 days by 2029 multiplies the renewals flowing through the logs.

send feedback on this story