edit: s/Digicert/Sectigo - thanks jaas
edit: s/Digicert/Sectigo - thanks jaas
https://www.cloudflare.com/dns/dnssec/dnssec-complexities-an...
I suppose you can get around enumeration concerns with CT by using a wildcard cert. It's always seemed odd to me to worry about information in a public database like DNS being retrievable on bulk anyway - that approach is just security by obscurity.
Obscurity does have a role to play in security - leaving your front door unlocked is unlikely to be a problem but if you publish that information in a publicly searchable database then you are making yourself a target
There are companies that use private (not publicly resolvable) domains for which they create public certificates for internal hosts, that get published via CT.
Nice for OpsSec sleuthing.
Edit: how to find these "private domains"? Often public certificates contain more than one DNS names, of which one might be "private". YMMV