checkId: doctor.evidence.timestamp.eidas.status-change family: doctor-check/v1 service: evidence-web scope: installation severity: warning tags: [timestamping, eidas, status-change, trusted-list, evidence]

Qualified Status Change

Stella Ops is self-hosted software. It does not issue electronic time stamps or provide any qualified trust service. This deployment performs local verification using operator-supplied evidence. Unless an approved jurisdiction-, provider-, service-, and deployment-specific claim profile applies, qualified status is not determined.

Compares two successive validated trust snapshots (each identified by digest) and reports any qualified-status change between them. A snapshot compared with itself can only ever report no change, so a single snapshot is reported as unable to detect changes. Default severity when it fails: warning. Installation-scoped: one result per estate, served on the Evidence doctor path and probed on the worker schedule trust-list-refresh (daily).

What it measures

The check never reports a pass for a value it does not have. When its source cannot be read it reports unhealthy with the message Source unavailable (<reason>): <detail>. No verdict can be reported. and the evidence keys source.state=unavailable, source.reason (one of source-not-configured, source-configuration-invalid, unavailable-by-sealed-policy, source-material-invalid, source-read-failed) and source.detail.

Evidence keys

Every value is a bounded measurement or pointer; no token bytes, trust material or credentials appear in evidence.

Common causes

Configuration

Depends on the trusted-list source that does not exist yet; reports unavailable with reason source-not-configured today.

How to verify

The 17 installation checks are served by evidence-web on the shared doctor-check/v1 path and need the ops.health scope. Probe the service DIRECTLY from inside the estate network: the gateway’s unprefixed /doctor/evidence/checks resolves to whichever service registered that template first, not to Evidence.

curl -sS -H "Authorization: Bearer $OPS_HEALTH_TOKEN" \
  http://evidence-web.stella-ops.local:8080/doctor/evidence/checks \
  | jq '.checks[] | select(.checkId == "doctor.evidence.timestamp.eidas.status-change")'

Once the Evidence doctor registration is activated (it is off by default in a sealed estate), the same result is also visible through the Platform doctor aggregator under the evidence service.

This is a local evidentiary classification of the token and issuing service at the stated time. It is not the output of a qualified validation or qualified preservation service and does not determine the legal effect of the underlying release, document, or transaction.