🔒

We respect your privacy. This site sets no cookies and uses no trackers. The only thing it keeps in your browser is an offline copy of its own pages. Privacy details

IIC TSA

IIC TSA status and incidents

Notices, incident history and measured availability of the service at tsa.internetidentitycard.com
Last updated: 11 October 2026

Current state

The service publishes its state as JSON at https://tsa.internetidentitycard.com/tsa/status ↗: the clock state (SYNC or FAIL), the time since that state began, the active key generation, the policy OID, the time of the last token, whether public issuance is open, and the current notices. This page explains how to read it and keeps the history that the JSON does not.

In service since
10 October 2026, 18:02:46 UTC (first production token)
Token issuance
Available to VerifBox only since 10 October 2026, 21:55 UTC; public access on request (contact@internetidentitycard.com). Verification endpoints (root, CRL, status) are public.
Key generation
tsa-2026-a, certificate valid to 9 January 2038, signs for at most 15 months (ceremony record R1)
Reading state
A token is issued only in SYNC, after a live measurement against four time sources. The service keeps no instance running between requests, so an idle instance reports FAIL with last_token_time: null until the first request measures the clock: that is a cold start, not an outage. A FAIL that persists after a token request is an incident and is recorded below.

Notices

Dated, newest first. Notices are also carried in the notices field of the status JSON while they are current.

11 October 2026
Self-assessment against ETSI EN 319 421 v1.0 published (PDF): not a conformity assessment or a certification; gaps stated.
11 October 2026
Erratum 2 to the Practice Statement (section 10): at termination of the service, every TSA certificate not yet expired is revoked in the final root CRL. A clarification, no change to the service.
11 October 2026
Key ceremony record R1 published (PDF).
11 October 2026
Erratum 1 to the Timestamp Policy and Practice Statement: the retention lock of the 12-year issuance-log and archive buckets is deferred by owner decision to after a few weeks of operation. The retention policy itself is in place; the lock will be applied and the erratum lifted in a further notice.
10 October 2026
Public token issuance closed at 21:55 UTC: tokens are available to VerifBox only, public access on request. POST requests on the public endpoint answer 403 issuance_closed.
10 October 2026
Production opened: offline key ceremony, production acceptance 40 of 40 checks at 18:22 UTC, first token at 18:02:46 UTC.

Incidents

None recorded since the opening on 10 October 2026. An incident, for this page, is any of: a token issued outside the SYNC state or with a wrong time; a suspected or confirmed compromise of a key; a revocation; a FAIL state persisting after a token request; the public verification endpoints (root, CRL, status) unreachable for more than one hour; a missed or failed nightly journal batch not recovered the following night; any loss of issuance-log data. Each incident is recorded here with its time (UTC), its effect on tokens, what was done, and the serial numbers of any token concerned, within seven days of being known.

Date (UTC)EffectTokens concernedResolution
No incident recorded.

Availability

IIC TSA is a free service with no availability commitment and no service-level agreement (terms of use). Availability is therefore measured and published, not promised. Since 11 October 2026 at 13:00 UTC, an external probe (Google Cloud Monitoring uptime check) requests GET /tsa/status every 5 minutes from three regions (Europe, USA Oregon, Asia Pacific) and counts the check as passed when the answer is HTTP 200 and contains a status JSON. A cold-start FAIL clock state is not a probe failure: the probe measures whether the endpoint answers, not the clock state. The measured monthly figure is listed here from the first full month; months without a complete measurement are shown as such, not estimated.

MonthMeasured availability of /tsa/statusMethod
November 2026to be published early December 2026uptime check, 3 regions, every 5 min
October 2026 (from the 10th)partial month, probe in place from the 11th: not reported—

Daily journal batches

Every day at 00:20 UTC, the previous day's issuance-log entries are written to a batch file whose SHA-256 is time-stamped by DigiCert's public RFC 3161 server and anchored in Bitcoin through OpenTimestamps, then copied to an archive bucket in another region (Practice Statement, section 8). The first batch, for 10 October 2026, ran on 11 October 2026 at 00:20 UTC (25 entries, DigiCert token granted, archive copy made). A failed batch is an incident only if it is not recovered the following night; the entries of a given day are provided to a relying party on request.

Check it yourself

Nothing on this page needs to be taken on trust:

This page is updated by the operator when a notice, an incident or a monthly figure is added; its date is in the subtitle. IIC TSA is designed to RFC 3161 / RFC 5816; it is not a qualified trust service, and IIC TSA and VerifBox belong to the same company.