Authoritative Time Proof
⏱
2026-10-06 19:56:18 UTC
UTC · Locked by an independent Timestamp Authority; the issuer cannot alter or re-sign after the fact
Timestamp metadata
| Credential ID | 14e7e3dd-1bf7-4e74-889a-a85fa48ff63c |
|---|---|
| Timestamp Authority (TSA) | www.freetsa.org O=Free TSA, OU=TSA, 2.5.4.13=This certificate digitally signs documents and time stamp requests made using the freetsa.org online services, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@mailbox.org, L=Wuerzburg, C=DE, ST=Bayern |
| Status | granted |
| Policy OID | 1.2.3.4.1 |
| Serial number | 150439781 |
| Nonce | 3353010309817556539 |
| Applied at | 2026-10-06 19:56:17 UTC |
Local re-verification
✕
Overall conclusion
时间戳校验存在未通过项。
✕
Message imprint match
时间戳锁定的摘要与当前凭证不一致(凭证可能被改动,或申请的是另一份内容)
✓
Encapsulated content type
encapContentInfo.eContentType = id-ct-TSTInfo
✓
Signing certificate identification
O=Free TSA, OU=TSA, 2.5.4.13=This certificate digitally signs documents and time stamp requests made using the freetsa.org online services, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@mailbox.org, L=Wuerzburg, C=DE, ST=Bayern
✓
signedAttrs.messageDigest
Digest in signedAttrs equals TSTInfo digest
✓
signedAttrs.contentType
id-ct-TSTInfo
✓
CMS signature
using "O=Free TSA, OU=TSA, 2.5.4.13=This certificate digitally signs documents and time stamp requests made using the freetsa.org online services, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@mailbox.org, L=Wuerzburg, C=DE, ST=Bayern"public key signature verified
✓
Certificate chain to self-signed root
chain length 2,root: O=Free TSA, OU=Root CA, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@gmail.com, L=Wuerzburg, ST=Bayern, C=DE
✓
Signing cert valid at authority time
2026-02-15T19:44:22Z ~ 2040-02-02T19:44:22Z
✓
Root certificate trust
Chain top root matched built-in trusted SPKI fingerprint
✓
Root trust level
Root matched built-in trust anchor
Capability boundary
The engine has built in the FreeTSA root certificate’s SPKI SHA-256 fingerprint as the trust anchor: if the chain top matches this fingerprint during re-verification, it is judged as “root pinned”, without relying on the OS root store. The system does not perform CRL/OCSP revocation or full X.509 path-constraint checks. The TSR file is in standard RFC 3161 format and can be downloaded for independent verification by any third-party tool (e.g. OpenSSL).