checkId: doctor.evidence.timestamp.time.rekor-correlation family: doctor-check/v1 service: evidence-web scope: installation severity: warning tags: [timestamping, time, transparency, rekor, evidence]
Transparency Time Correlation
Stella Ops is self-hosted software. It does not issue electronic time stamps or provide any qualified trust service. This deployment performs local verification using operator-supplied evidence. Unless an approved jurisdiction-, provider-, service-, and deployment-specific claim profile applies, qualified status is not determined.
Correlates timestamp tokens with their transparency-log integration times in the window: a token that claims a generation time AFTER its log entry is a chronology violation, and a gap beyond the budget is reported. An empty window is stated as unmeasured, not as agreement. Default severity when it fails: warning. Installation-scoped: one result per estate, served on the Evidence doctor path and probed on the worker schedule active-probes (every 15 minutes).
What it measures
- Critical when any pair is inverted (log integration before token generation).
- Fails when any pair’s gap exceeds
MaximumTransparencyCorrelationGap(default 5 minutes).
The check never reports a pass for a value it does not have. When its source cannot be read it reports unhealthy with the message Source unavailable (<reason>): <detail>. No verdict can be reported. and the evidence keys source.state=unavailable, source.reason (one of source-not-configured, source-configuration-invalid, unavailable-by-sealed-policy, source-material-invalid, source-read-failed) and source.detail.
Evidence keys
correlation.pairCountcorrelation.invertedCountcorrelation.overGapCountcorrelation.maximumGapSecondscorrelation.windowHours
Every value is a bounded measurement or pointer; no token bytes, trust material or credentials appear in evidence.
Common causes
- No correlation source is wired (current state).
- Once wired: a transparency log or TSA with a wrong clock.
Configuration
Needs the Evidence-owned attestation/transparency metadata reader, which is not composed yet: the check reports unavailable (source-not-configured online, unavailable-by-sealed-policy sealed).
Thresholds live in Evidence__TimestampAssurance__Policy__* and default to the values the retired Doctor plugin used (carried verbatim so a cadence or threshold change is always a visible edit).
How to verify
The 17 installation checks are served by evidence-web on the shared doctor-check/v1 path and need the ops.health scope. Probe the service DIRECTLY from inside the estate network: the gateway’s unprefixed /doctor/evidence/checks resolves to whichever service registered that template first, not to Evidence.
curl -sS -H "Authorization: Bearer $OPS_HEALTH_TOKEN" \
http://evidence-web.stella-ops.local:8080/doctor/evidence/checks \
| jq '.checks[] | select(.checkId == "doctor.evidence.timestamp.time.rekor-correlation")'
Once the Evidence doctor registration is activated (it is off by default in a sealed estate), the same result is also visible through the Platform doctor aggregator under the evidence service.
Related checks
- TSA Time Skew (
doctor.evidence.timestamp.time.tsa-skew) - System Time Sync (
doctor.evidence.timestamp.time.system-sync)
This is a local evidentiary classification of the token and issuing service at the stated time. It is not the output of a qualified validation or qualified preservation service and does not determine the legal effect of the underlying release, document, or transaction.
