Research / Finding
rfc3161 timestamp verification accepts revoked tsa certificate (no crl/ocsp checking) F-SIG-014-001
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
—score not recorded
rfc3161 timestamp verification accepts revoked tsa certificate (no crl/ocsp checking)
merged
details
Finding IDs F-SIG-014-001 Status merged Reported date 10 Jan 2026 Rationale prevents accepting revoked tsa certificates (crl/ocsp). PR opened by @1seal PR state observed closed; GitHub merged: true; 2026-09-24 PR observation basis Public PR metadata recorded in the 2026-09-24 evidence audit; not a live status feed. Contribution boundary @1seal opened this PR; this alone does not establish sole code authorship. F-SIG-014-001: Verification failures. RFC3161 verification accepts the recorded revoked timestamp signer. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-SIG-014-001
Security area (1seal assessment): Identity. RFC3161 verification accepts the recorded revoked timestamp signer. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .