checkId: doctor.evidence.timestamp.revocation.ocsp-responder family: doctor-check/v1 service: evidence-web scope: installation severity: warning tags: [timestamping, revocation, ocsp, evidence]
OCSP Responder
Stella Ops is self-hosted software. It does not issue electronic time stamps or provide any qualified trust service. This deployment performs local verification using operator-supplied evidence. Unless an approved jurisdiction-, provider-, service-, and deployment-specific claim profile applies, qualified status is not determined.
Asks the OCSP responder that the TSA signer certificate ITSELF declares (its AIA extension) for the signer’s status, and verifies the response signature and its binding to the certificate. A configured responder URL is never probed: a healthy answer about the wrong certificate is worthless. Default severity when it fails: warning. Installation-scoped: one result per estate, served on the Evidence doctor path and probed on the worker schedule active-probes (every 15 minutes).
What it measures
- Fails when the certificate declares no OCSP responder.
- Fails when no response arrives; critical when the response signature does not verify or is not bound to the asked certificate.
- Critical when the reported status is not
good; fails when the response is past itsnextUpdate.
The check never reports a pass for a value it does not have. When its source cannot be read it reports unhealthy with the message Source unavailable (<reason>): <detail>. No verdict can be reported. and the evidence keys source.state=unavailable, source.reason (one of source-not-configured, source-configuration-invalid, unavailable-by-sealed-policy, source-material-invalid, source-read-failed) and source.detail.
Evidence keys
ocsp.certStatusocsp.responseSignatureVerifiedocsp.certificateIdMatchedocsp.thisUpdateocsp.nextUpdateocsp.mode
Every value is a bounded measurement or pointer; no token bytes, trust material or credentials appear in evidence.
Common causes
- The signer certificate carries no AIA/OCSP URL.
- The responder host is not allow-listed or is unreachable.
- The responder signs with a key that does not chain to the trust material.
Configuration
The responder is taken from the signer certificate; its host must be reachable under the egress guard (AllowedHosts, private-network posture). In a sealed estate a live OCSP query is egress and is refused before DNS; the revocation snapshot in the OfflineKit bundle covers that estate instead.
The TSA path is configured on BOTH Evidence roles (the compose file carries the keys in the shared x-evidence-runtime anchor, so the web role’s doctor and the worker’s schedules read the same graph):
Evidence__TimestampAssurance__Adapters__PrimaryProviderId: "local-tsa"
Evidence__TimestampAssurance__Adapters__Providers__0__ProviderId: "local-tsa"
Evidence__TimestampAssurance__Adapters__Providers__0__Endpoint: "http://tsa.stella-ops.local:318/"
Evidence__TimestampAssurance__Adapters__Providers__0__Requirement: "Mandatory" # or Optional
Evidence__TimestampAssurance__Adapters__Providers__0__AllowPlaintextHttp: "true" # compose-internal TSA only
Evidence__TimestampAssurance__Adapters__Providers__0__AllowPrivateNetwork: "true"
Evidence__TimestampAssurance__Adapters__AllowedHosts__0: "tsa.stella-ops.local"
Every outbound probe passes the Timestamp Assurance egress guard: the host must be on AllowedHosts, the resolved address must satisfy the provider’s private-network posture, and the connection is pinned to the vetted address. In a sealed estate (AirGap__Egress__Mode=Sealed) the estate policy is evaluated BEFORE DNS and classifies by host string, so a compose-internal TSA named by hostname is refused even with AllowPrivateNetworks=true; name it through an explicit AirGap allow rule or an IP-literal endpoint.
How to verify
The 17 installation checks are served by evidence-web on the shared doctor-check/v1 path and need the ops.health scope. Probe the service DIRECTLY from inside the estate network: the gateway’s unprefixed /doctor/evidence/checks resolves to whichever service registered that template first, not to Evidence.
curl -sS -H "Authorization: Bearer $OPS_HEALTH_TOKEN" \
http://evidence-web.stella-ops.local:8080/doctor/evidence/checks \
| jq '.checks[] | select(.checkId == "doctor.evidence.timestamp.revocation.ocsp-responder")'
Once the Evidence doctor registration is activated (it is off by default in a sealed estate), the same result is also visible through the Platform doctor aggregator under the evidence service.
Related checks
- CRL Distribution Point (
doctor.evidence.timestamp.revocation.crl-distribution) - Revocation Cache Fresh (
doctor.evidence.timestamp.revocation.cache-fresh) - Revocation Material Stapled at Issuance (
doctor.evidence.timestamp.revocation.stapling-present)
This is a local evidentiary classification of the token and issuing service at the stated time. It is not the output of a qualified validation or qualified preservation service and does not determine the legal effect of the underlying release, document, or transaction.
