checkId: doctor.evidence.timestamp.revocation.ocsp-responder family: doctor-check/v1 service: evidence-web scope: installation severity: warning tags: [timestamping, revocation, ocsp, evidence]

OCSP Responder

Stella Ops is self-hosted software. It does not issue electronic time stamps or provide any qualified trust service. This deployment performs local verification using operator-supplied evidence. Unless an approved jurisdiction-, provider-, service-, and deployment-specific claim profile applies, qualified status is not determined.

Asks the OCSP responder that the TSA signer certificate ITSELF declares (its AIA extension) for the signer’s status, and verifies the response signature and its binding to the certificate. A configured responder URL is never probed: a healthy answer about the wrong certificate is worthless. Default severity when it fails: warning. Installation-scoped: one result per estate, served on the Evidence doctor path and probed on the worker schedule active-probes (every 15 minutes).

What it measures

The check never reports a pass for a value it does not have. When its source cannot be read it reports unhealthy with the message Source unavailable (<reason>): <detail>. No verdict can be reported. and the evidence keys source.state=unavailable, source.reason (one of source-not-configured, source-configuration-invalid, unavailable-by-sealed-policy, source-material-invalid, source-read-failed) and source.detail.

Evidence keys

Every value is a bounded measurement or pointer; no token bytes, trust material or credentials appear in evidence.

Common causes

Configuration

The responder is taken from the signer certificate; its host must be reachable under the egress guard (AllowedHosts, private-network posture). In a sealed estate a live OCSP query is egress and is refused before DNS; the revocation snapshot in the OfflineKit bundle covers that estate instead.

The TSA path is configured on BOTH Evidence roles (the compose file carries the keys in the shared x-evidence-runtime anchor, so the web role’s doctor and the worker’s schedules read the same graph):

Evidence__TimestampAssurance__Adapters__PrimaryProviderId: "local-tsa"
Evidence__TimestampAssurance__Adapters__Providers__0__ProviderId: "local-tsa"
Evidence__TimestampAssurance__Adapters__Providers__0__Endpoint: "http://tsa.stella-ops.local:318/"
Evidence__TimestampAssurance__Adapters__Providers__0__Requirement: "Mandatory"   # or Optional
Evidence__TimestampAssurance__Adapters__Providers__0__AllowPlaintextHttp: "true"  # compose-internal TSA only
Evidence__TimestampAssurance__Adapters__Providers__0__AllowPrivateNetwork: "true"
Evidence__TimestampAssurance__Adapters__AllowedHosts__0: "tsa.stella-ops.local"

Every outbound probe passes the Timestamp Assurance egress guard: the host must be on AllowedHosts, the resolved address must satisfy the provider’s private-network posture, and the connection is pinned to the vetted address. In a sealed estate (AirGap__Egress__Mode=Sealed) the estate policy is evaluated BEFORE DNS and classifies by host string, so a compose-internal TSA named by hostname is refused even with AllowPrivateNetworks=true; name it through an explicit AirGap allow rule or an IP-literal endpoint.

How to verify

The 17 installation checks are served by evidence-web on the shared doctor-check/v1 path and need the ops.health scope. Probe the service DIRECTLY from inside the estate network: the gateway’s unprefixed /doctor/evidence/checks resolves to whichever service registered that template first, not to Evidence.

curl -sS -H "Authorization: Bearer $OPS_HEALTH_TOKEN" \
  http://evidence-web.stella-ops.local:8080/doctor/evidence/checks \
  | jq '.checks[] | select(.checkId == "doctor.evidence.timestamp.revocation.ocsp-responder")'

Once the Evidence doctor registration is activated (it is off by default in a sealed estate), the same result is also visible through the Platform doctor aggregator under the evidence service.

This is a local evidentiary classification of the token and issuing service at the stated time. It is not the output of a qualified validation or qualified preservation service and does not determine the legal effect of the underlying release, document, or transaction.