Time-stamping

IIC TSA

A Time Stamp Authority designed to RFC 3161 / RFC 5816, operated by Https Card — Internet Identity Card Ltd.
In service since 10 October 2026 · not eIDAS-qualified · free of charge

Read this first

IIC TSA is designed to RFC 3161 / RFC 5816. It is not a qualified trust service under eIDAS or UK eIDAS, it holds no ETSI audit, it is not listed in any trust list, and neither the service nor its signing key is certified, accredited or FIPS-validated. The signing key is held in Google Cloud KMS at the SOFTWARE protection level, not in a hardware security module. The service has a single operator.

Same company as VerifBox. IIC TSA and VerifBox ↗ (a file time-stamping website that is a client of IIC TSA since 10 October 2026) are both operated by Https Card — Internet Identity Card Ltd. For VerifBox users, IIC TSA is therefore not an independent third party; where independent evidence is needed, it has to come from a source that does not depend on this company, such as a third-party time-stamp authority or an anchor in the Bitcoin blockchain.

The service is provided free of charge, with no commitment of availability, under the IIC TSA terms of use.

What IIC TSA is

IIC TSA (Internet Identity Card Time Stamp Authority) is a public time-stamping service operated by HTTPS CARD — INTERNET IDENTITY CARD LIMITED (England and Wales, company no. 09168431). It answers RFC 3161 requests: a client sends the hash of a file, and the service returns a signed time-stamp token stating that this hash existed at the time written in the token.

The service receives only the hash, never the file. It does not examine, store or interpret the hash, and keeps no record of it: the issuance log holds the token's serial number, time and signature digest, not the hash submitted.

A token proves that the authority signed a given hash at the stated time. It does not prove who created or owns the file, its content, its accuracy or its lawfulness; it is not a signature of the file and it is not a qualified electronic time stamp.

Production opened on 10 October 2026, after an offline key ceremony and an acceptance run of 40 checks on the production service. A 14-day accuracy measurement campaign runs in parallel on the test service and is reviewed on day 14; every token is in any case gated by a live measurement against four time sources (see below).

Service details

Endpoint
POST https://tsa.internetidentitycard.com/tsa
Protocol
RFC 3161, as updated by RFC 5816 · HTTP transport only · Content-Type application/timestamp-query · request at most 8,192 bytes
Policy OID
1.3.6.1.4.1.67100.1.1.1.1 (IIC TSA Timestamp Policy v1.0, under IANA Private Enterprise Number 67100)
Hash algorithms
SHA-256, SHA-384, SHA-512 (SHA-1 and MD5 rejected)
Token signature
ECDSA P-256 with SHA-256, key generation tsa-2026-a; single signature; ESSCertIDv2
Declared accuracy
1 second (genTime in UTC, rounded to the whole second)
Time sources
Measured on demand over TLS against PTB (traceable to UTC(PTB)), Akamai, Google and Cloudflare; a token is issued only when at least three sources agree, PTB among them; otherwise the request is rejected (timeNotAvailable)
Rate limit
60 requests per minute per client address (HTTP 429, Retry-After: 60)
Nonce / certReq
nonce copied unchanged; certReq TRUE returns the TSA certificate only (never the root)
Hosting
Google Cloud Run, region europe-west1 (Belgium)
Status page
Policy (JSON)

Trust anchor and revocation

The hierarchy has two levels: an offline root, IIC TSA Root R1 (ECDSA P-384, valid 10 October 2026 to 9 October 2056), which issues the TSA certificate directly. There is no intermediate CA. The root never signs tokens; the TSA key signs nothing else.

Root certificate
Root SHA-256
86:52:E3:D1:3E:72:5F:7C:75:7C:FA:05:3D:64:13:60:AC:A4:43:CF:6C:09:D7:D6:DD:D4:4B:EA:85:1E:D3:B9
TSA certificate
https://tsa.internetidentitycard.com/tsa/certificate ↗ (PEM) · CN = IIC TSA tsa-2026-a · valid 10 October 2026 to 9 January 2038; the key signs tokens for at most 15 months
TSA cert SHA-256
E4:F9:8E:7A:ED:CD:1A:07:D8:1C:A5:9D:1C:19:92:AB:E7:85:7A:2C:A1:CC:8D:F6:9F:72:05:FF:AD:34:FB:E8
CRL
https://tsa.internetidentitycard.com/tsa/crl ↗ (DER, re-issued yearly, valid 365 days; emergency CRL on compromise) · copy at verifbox.com/.well-known/iic-tsa-racine.crl ↗

Compare the fingerprint of the root you download with the value above before pinning it. Expiry of the TSA certificate alone does not invalidate a token issued while it was valid: tokens are verified at their genTime, with a CRL issued after that time. Keep each token together with the certificate chain and such a CRL for long-term validation.

Request a time-stamp

With OpenSSL, for a file named document.pdf:

openssl ts -query -data document.pdf -sha256 -cert -out request.tsq
curl -s -H "Content-Type: application/timestamp-query" \
     --data-binary @request.tsq \
     https://tsa.internetidentitycard.com/tsa -o token.tsr

Only the SHA-256 of the file leaves your computer. The service also accepts SHA-384 and SHA-512 requests.

Verify a token

curl -s https://tsa.internetidentitycard.com/tsa/chain -o iic-tsa-root.pem
openssl ts -reply -in token.tsr -text          # shows genTime, policy OID, serial, accuracy
openssl ts -verify -data document.pdf -in token.tsr -CAfile iic-tsa-root.pem

A verifier checks separately that the CMS signature is valid, that the TSA certificate chains to the root above and carries the critical id-kp-timeStamping extended key usage, that it was valid and not revoked at genTime (CRL issued after genTime), that the policy OID is 1.3.6.1.4.1.67100.1.1.1.1 (never the test OID 1.3.6.1.4.1.67100.1.1.9.1), and that the message imprint matches the file. The public VerifBox repository ↗ contains a Python verifier (written by the operator, so not independent of it) and a worked example; a verifier written independently of the token encoder is still pending.

Governance documents

The service runs under a published Timestamp Policy and Practice Statement. Both are version 1.0, approved 10 October 2026. The Practice Statement follows the structure of ETSI EN 319 421 as a drafting grid only, without any claim of conformity, audit or qualification.

Timestamp Policy
IIC-TSA-Timestamp-Policy-v1.0.pdf · v1.0 · 208 KB
SHA-256 ac7b2f5c72ccb0936dab1eba7d4902313dd0b8eb30bc8ab253010e507d66177c
Practice Statement
IIC-TSA-Practice-Statement-v1.0.pdf · v1.0 · 208 KB
SHA-256 e453485c5a11bc27ed652ff723a8ef003bc25a707ebf84c1bf670ab7d7dd5931
Terms of use
Privacy

Any change to the policy produces a new version with a new OID; tokens always name the policy under which they were issued. Notices of key rotation, revocation, incidents or termination are published on the status page and on this page.

What is not promised

Contact

Questions about the service, requests for the issuance-log entries of a given day, or reports of a suspected key compromise: contact@internetidentitycard.com. Security reports: security@internetidentitycard.com (see security.txt).

Operator: HTTPS CARD — INTERNET IDENTITY CARD LIMITED, 124 City Road, London EC1V 2NX, United Kingdom. Company no. 09168431. ICO registration ZA457585.