Trusted Timestamp

Authoritative Time Proof

This timestamp was independently issued by a third-party RFC 3161 authority — an external trust anchor that the credential content existed at the specified moment and has not been tampered with since.

Authoritative Time Proof

⏱
2026-10-06 18:47:39 UTC
UTC · Locked by an independent Timestamp Authority; the issuer cannot alter or re-sign after the fact

Timestamp metadata

Credential IDc2b76f40-af83-4387-8550-a23d37681eee
Timestamp Authority (TSA)www.freetsa.org
O=Free TSA, OU=TSA, 2.5.4.13=This certificate digitally signs documents and time stamp requests made using the freetsa.org online services, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@mailbox.org, L=Wuerzburg, C=DE, ST=Bayern
Statusgranted
Policy OID1.2.3.4.1
Serial number150407626
Nonce5055882059122957229
Applied at2026-10-06 18:47:39 UTC
⬇ Download raw timestamp token (TSR)

Local re-verification

✓ Overall conclusion Timestamp signature and content verified; root matched built-in trust anchor。
✓ Message imprint match Digest locked by timestamp matches current credential
✓ Encapsulated content type encapContentInfo.eContentType = id-ct-TSTInfo
✓ Signing certificate identification O=Free TSA, OU=TSA, 2.5.4.13=This certificate digitally signs documents and time stamp requests made using the freetsa.org online services, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@mailbox.org, L=Wuerzburg, C=DE, ST=Bayern
✓ signedAttrs.messageDigest Digest in signedAttrs equals TSTInfo digest
✓ signedAttrs.contentType id-ct-TSTInfo
✓ CMS signature using "O=Free TSA, OU=TSA, 2.5.4.13=This certificate digitally signs documents and time stamp requests made using the freetsa.org online services, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@mailbox.org, L=Wuerzburg, C=DE, ST=Bayern"public key signature verified
✓ Certificate chain to self-signed root chain length 2,root: O=Free TSA, OU=Root CA, CN=www.freetsa.org, 1.2.840.113549.1.9.1=busilezas@gmail.com, L=Wuerzburg, ST=Bayern, C=DE
✓ Signing cert valid at authority time 2026-02-15T19:44:22Z ~ 2040-02-02T19:44:22Z
✓ Root certificate trust Chain top root matched built-in trusted SPKI fingerprint
✓ Root trust level Root matched built-in trust anchor

Capability boundary

The engine has built in the FreeTSA root certificate’s SPKI SHA-256 fingerprint as the trust anchor: if the chain top matches this fingerprint during re-verification, it is judged as “root pinned”, without relying on the OS root store. The system does not perform CRL/OCSP revocation or full X.509 path-constraint checks. The TSR file is in standard RFC 3161 format and can be downloaded for independent verification by any third-party tool (e.g. OpenSSL).