NakedSignal OS

Certificate registry

Load the certificates you hold and see what lapses, and when.

How certificate registry works

Every passport is signed over two dates — issued_utc and expiry_utc — and a plain-language expiry_basis that says why the second date is the date it is. None of those three is held by us or looked up anywhere: they are inside the file, under the same Ed25519 signature as the scores, so moving an expiry date breaks the signature exactly the way moving an accuracy figure does.

Each bar runs from one of those dates to the other. The vertical rule is your own computer’s clock, read when the page loaded — this route is a static export, so a “today” computed when the site was built would be frozen on the day it deployed. Every colour on the chart follows from comparing the two.

The band behind the bars is the sealed held-out generation the portfolio is anchored to. Its retirement date is parsed out of the passports’ own expiry_basisstrings, because that is the only place it is written down: the held-out cycle record names the generation and carries its set hash, but publishes no dates. What the record does let us do is check that the set-hash prefix in the documents is the prefix of the hash in the ledgered cycle — the documents and the track are demonstrably talking about the same sealed set, rather than both using the word “gen2”.

Per spec a passport lapses when its generation retires or when its spec version is superseded, whichever comes first. No supersession date has been published for MedEval-1 v0.1, so only the first of those two bases has a date that can be drawn on an axis; the second is shown per row instead.

Live evaluation

No portfolio to hand?
Load 42 real certificates and see the whole registry at once.