Fake Certificate Transparency Notification on April Fools' Day from Cloudflare?

What is the name of the domain?

What is the issue you’re encountering

Recieve a CT Notification, and the cert doesn’t exist (Google Trust)

What steps have you taken to resolve the issue?

The cert below can’t find on crt.sh

Cloudflare has observed issuance of the following certificate for gorlee.me or one of its subdomains:

Log date: 2025-04-01 13:14:55 UTC
Issuer: CN=AE1,O=Google Trust Services,C=US
Validity: 2025-04-01 12:14:55 UTC - 2025-05-16 13:14:24 UTC
DNS Names: .com, *..com

Most certificates are trustworthy. However, if the data above is surprising to you or incorrect, visit Certificate Transparency Monitoring · Cloudflare SSL/TLS docs.

Was the site working with SSL prior to adding it to Cloudflare?

Yes

What is the current SSL/TLS setting?

Strict (SSL-Only Origin Pull)

It’s weird that CN=AE1, I have never seen this before

That cert shows up in the certificate transparency logs.

Cloudflare doesn’t do April Fools.. especially not with regards to security.

AE1 is listed here: Google Trust Services | Repository

But I have never request for a cert, someone finished the acme challange and get the cert

And the AE1 cert isn’t shown in Edge Certificates dashboard

You use Cloudflare in proxied mode so at a minimum Cloudflare is requesting certificates on your behalf regularly.

That’s fine than, other domains I owned just have GTS cert [CN=WE1][CN=WR1] and SSL.com [CN=Cloudflare TLS Issuing ECC CA 1]

This topic was automatically closed 15 days after the last reply. New replies are no longer allowed.