checkId: doctor.evidence.timestamp.eidas.status-change family: doctor-check/v1 service: evidence-web scope: installation severity: warning tags: [timestamping, eidas, status-change, trusted-list, evidence]
Qualified Status Change
Stella Ops is self-hosted software. It does not issue electronic time stamps or provide any qualified trust service. This deployment performs local verification using operator-supplied evidence. Unless an approved jurisdiction-, provider-, service-, and deployment-specific claim profile applies, qualified status is not determined.
Compares two successive validated trust snapshots (each identified by digest) and reports any qualified-status change between them. A snapshot compared with itself can only ever report no change, so a single snapshot is reported as unable to detect changes. Default severity when it fails: warning. Installation-scoped: one result per estate, served on the Evidence doctor path and probed on the worker schedule trust-list-refresh (daily).
What it measures
- Fails when only one distinct snapshot is available.
- Fails with the changed service identifiers when any status changed between the two snapshots.
The check never reports a pass for a value it does not have. When its source cannot be read it reports unhealthy with the message Source unavailable (<reason>): <detail>. No verdict can be reported. and the evidence keys source.state=unavailable, source.reason (one of source-not-configured, source-configuration-invalid, unavailable-by-sealed-policy, source-material-invalid, source-read-failed) and source.detail.
Evidence keys
statusChange.countstatusChange.changedServicesstatusChange.previousSnapshotDigeststatusChange.currentSnapshotDigeststatusChange.windowDays
Every value is a bounded measurement or pointer; no token bytes, trust material or credentials appear in evidence.
Common causes
- No trusted-list source is wired (current state everywhere).
- Once wired: a supervisory-body action or a provider withdrawal.
Configuration
Depends on the trusted-list source that does not exist yet; reports unavailable with reason source-not-configured today.
How to verify
The 17 installation checks are served by evidence-web on the shared doctor-check/v1 path and need the ops.health scope. Probe the service DIRECTLY from inside the estate network: the gateway’s unprefixed /doctor/evidence/checks resolves to whichever service registered that template first, not to Evidence.
curl -sS -H "Authorization: Bearer $OPS_HEALTH_TOKEN" \
http://evidence-web.stella-ops.local:8080/doctor/evidence/checks \
| jq '.checks[] | select(.checkId == "doctor.evidence.timestamp.eidas.status-change")'
Once the Evidence doctor registration is activated (it is off by default in a sealed estate), the same result is also visible through the Platform doctor aggregator under the evidence service.
Related checks
- Qualified Status (Claim-Gated) (
doctor.evidence.timestamp.eidas.qualified-status) - Trusted List Fresh (
doctor.evidence.timestamp.eidas.trust-list-fresh)
This is a local evidentiary classification of the token and issuing service at the stated time. It is not the output of a qualified validation or qualified preservation service and does not determine the legal effect of the underlying release, document, or transaction.
