Current operational status of infrastructure and the certificate authority.
Root certificates, service status, and material announcements.
Announcements
1 September 2026 - TSA practice statement v1.0. Published here
1 September 2026 - TSA disclosure statement v1.1. The TSA disclosure statement is now version 1.1. The SLH-DSA profile was previously labelled European profile; the endpoint path /eu is unchanged. Tokens remain RFC 3161 timestamps and are not qualified electronic time-stamps. TSA revocation stays on CRLs. The issuance CAs for ordinary certificates now also offer OCSP at ocsp.beatquantum.com and ocsp-b.beatquantum.com.
28 August 2026 - Revocation lists published for all Time-Stamp Authority tiers. CRLs are available for the TSA intermediate and issuing CAs, in addition to the R3 root. Distribution points are carried in the certificates. Intermediate lists are reissued every 90 days, issuing lists every 30 days.
26 August 2026 - TSA policy identifiers assigned; issuance log live. BeatQuantum's IANA Private Enterprise Number is 66626. Every timestamp token asserts a formal policy identifier: 1.3.6.1.4.1.66626.1.1 for the CNSA 2.0 profile and 1.3.6.1.4.1.66626.1.2 for the SLH-DSA profile. The RFC 3161 issuance log is operational, recording each token's serial number, asserted time, policy, message imprint and measured clock offset, and no requester identity or address. What is recorded, and how long it is retained, is set out in the TSA disclosure statement.
24 August 2026 - Time-Stamp Authority live. BeatQuantum's RFC 3161 Time-Stamp Authority is operational at tsa.beatquantum.com, anchored at a dedicated root, R3, separate from the certificate-issuance roots below. Both post-quantum profiles, CNSA 2.0 (ML-DSA-87) and SLH-DSA (SLH-DSA-SHA2-256f), are live and independently verified. See the TSA disclosure statement.
3 August 2026 - CPS v1.2 published (BeatQuantum incorporated). BeatQuantum Limited was incorporated on this date. Concurrently, the Certificate Practice Statement has been refreshed and published as version 1.2, effective 3 August 2026. The document is available at beatquantum.com/cps.
Certificates
The following root CA certificates are currently valid and have not been revoked. If any of these certificates are compromised or revoked, this section will be updated immediately with details of the affected certificate, the nature of the compromise, and the steps subscribers and relying parties should take.
BeatQuantum Labs Root CA R1 - Option A (Pure Post-Quantum)
Status: Valid
| Algorithm | ML-DSA-87 (FIPS 204) |
|---|---|
| Valid until | 4 May 2046 GMT |
| SHA-256 Fingerprint | AF:54:D7:15:0C:0A:4D:5A:4B:B7:A2:E3:7B:85:A5:7A:2E:DB:A9:02:01:FA:A2:A7:F1:87:07:87:F6:7E:41:22 |
| CRL | http://crl.beatquantum.com/root.crl |
| Download | beatquantum-root-r1.crt |
Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-root-r1.crt -noout -fingerprint -sha256
BeatQuantum Labs Root CA R2 - Option B (Hybrid Post-Quantum)
Status: Valid
| Algorithm | SLH-DSA-SHA2-256s (FIPS 205) |
|---|---|
| Valid until | 4 May 2046 GMT |
| SHA-256 Fingerprint | FA:59:7E:38:62:7C:95:E4:39:98:67:0F:5E:2B:2A:B6:9A:72:03:A3:F5:81:0F:73:88:FF:E1:E9:EC:D8:91:AC |
| CRL | http://crl.beatquantum.com/root-b.crl |
| Download | beatquantum-root-r2.crt |
Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-root-r2.crt -noout -fingerprint -sha256
BeatQuantum Limited TSA Root CA R3 - Time-Stamp Authority
Status: Valid
| Algorithm | SLH-DSA-SHA2-256s (FIPS 205) |
|---|---|
| Valid until | 19 August 2046 GMT |
| SHA-256 Fingerprint | 86:97:BD:DF:CE:41:28:F9:17:AC:17:DB:DD:D6:46:E1:73:7C:63:93:F9:8E:BE:BF:CA:9A:B5:28:98:BE:A7:06 |
| CRL | http://crl.beatquantum.com/tsa-root.crl |
| Download | beatquantum-tsa-root-r3.crt |
This root anchors RFC 3161 timestamping only and is not part of either certificate-issuance chain above. It is governed by the TSA disclosure statement, not the CPS. Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-tsa-root-r3.crt -noout -fingerprint -sha256
Issuance CA revocation (R1 / R2 chains)
| Chain | CRL | OCSP |
|---|---|---|
| Option A issuing CA | issuing.crl | http://ocsp.beatquantum.com/ |
| Option B issuing CA | issuing-b.crl | http://ocsp-b.beatquantum.com/ |
Time-Stamp Authority revocation lists
The TSA publishes CRLs only. There is no OCSP responder on the R3 hierarchy.
| Issued by | CRL |
|---|---|
| TSA Root CA R3 | tsa-root.crl |
| CNSA 2.0 TSA Intermediate CA | tsa-intermediate-cnsa.crl |
| SLH-DSA TSA Intermediate CA | tsa-intermediate-eu.crl |
| CNSA 2.0 TSA Issuing CA | tsa-issuing-cnsa.crl |
| SLH-DSA TSA Issuing CA | tsa-issuing-eu.crl |
Systems
Current operational status of BeatQuantum services. All TLS-based services negotiate post-quantum hybrid and pure post-quantum key exchange.
| Service | Description | Status |
|---|---|---|
| Web Server | beatquantum.com - HTTPS | Operational |
| Time-Stamp Authority | tsa.beatquantum.com - RFC 3161 (CNSA 2.0 and SLH-DSA profiles) | Operational |
| CRL distribution | crl.beatquantum.com - HTTP | Operational |
| OCSP (issuance CAs) | ocsp.beatquantum.com and ocsp-b.beatquantum.com - HTTP | Operational |
| SMTP | Inbound and outbound mail (STARTTLS and SMTPS) | Operational |
| IMAP / POP3 | Mailbox access (STARTTLS, IMAPS, POP3S) | Operational |
| VPN | Virtual private network (OpenVPN) | Operational |
| IKEv2 / IPsec | Hybrid post-quantum key exchange (RFC 9370, ML-KEM) | Operational |
| WireGuard | Virtual private network | Operational |
| DoH | DNS over HTTPS (RFC 8484) | Operational |
| DoT | DNS over TLS (RFC 7858) | Operational |
| DoQ | DNS over QUIC (RFC 9250) | Operational |
| NTS | Network Time Security (RFC 8915), post-quantum NTS-KE | Operational |
| LDAP | Directory service (STARTTLS and LDAPS) | Operational |
| PostgreSQL | Database over TLS | Operational |
| MariaDB | Database over TLS | Operational |
| Syslog | Log collection over TLS (RFC 5425) | Operational |
Status indicators are currently updated manually. Automated monitoring integration is planned for a future release.
Prove first, speak later.
For certificate issuance see the CPS. For timestamping see the TSA disclosure statement.
View the CPS →