Status

Current operational status of infrastructure and the certificate authority.

Root certificates, service status, and material announcements.

01

Announcements

1 September 2026 - TSA practice statement v1.0. Published here

1 September 2026 - TSA disclosure statement v1.1. The TSA disclosure statement is now version 1.1. The SLH-DSA profile was previously labelled European profile; the endpoint path /eu is unchanged. Tokens remain RFC 3161 timestamps and are not qualified electronic time-stamps. TSA revocation stays on CRLs. The issuance CAs for ordinary certificates now also offer OCSP at ocsp.beatquantum.com and ocsp-b.beatquantum.com.

28 August 2026 - Revocation lists published for all Time-Stamp Authority tiers. CRLs are available for the TSA intermediate and issuing CAs, in addition to the R3 root. Distribution points are carried in the certificates. Intermediate lists are reissued every 90 days, issuing lists every 30 days.

26 August 2026 - TSA policy identifiers assigned; issuance log live. BeatQuantum's IANA Private Enterprise Number is 66626. Every timestamp token asserts a formal policy identifier: 1.3.6.1.4.1.66626.1.1 for the CNSA 2.0 profile and 1.3.6.1.4.1.66626.1.2 for the SLH-DSA profile. The RFC 3161 issuance log is operational, recording each token's serial number, asserted time, policy, message imprint and measured clock offset, and no requester identity or address. What is recorded, and how long it is retained, is set out in the TSA disclosure statement.

24 August 2026 - Time-Stamp Authority live. BeatQuantum's RFC 3161 Time-Stamp Authority is operational at tsa.beatquantum.com, anchored at a dedicated root, R3, separate from the certificate-issuance roots below. Both post-quantum profiles, CNSA 2.0 (ML-DSA-87) and SLH-DSA (SLH-DSA-SHA2-256f), are live and independently verified. See the TSA disclosure statement.

3 August 2026 - CPS v1.2 published (BeatQuantum incorporated). BeatQuantum Limited was incorporated on this date. Concurrently, the Certificate Practice Statement has been refreshed and published as version 1.2, effective 3 August 2026. The document is available at beatquantum.com/cps.

02

Certificates

The following root CA certificates are currently valid and have not been revoked. If any of these certificates are compromised or revoked, this section will be updated immediately with details of the affected certificate, the nature of the compromise, and the steps subscribers and relying parties should take.

BeatQuantum Labs Root CA R1 - Option A (Pure Post-Quantum)

Status: Valid

Algorithm ML-DSA-87 (FIPS 204)
Valid until 4 May 2046 GMT
SHA-256 Fingerprint AF:54:D7:15:0C:0A:4D:5A:4B:B7:A2:E3:7B:85:A5:7A:2E:DB:A9:02:01:FA:A2:A7:F1:87:07:87:F6:7E:41:22
CRL http://crl.beatquantum.com/root.crl
Download beatquantum-root-r1.crt

Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-root-r1.crt -noout -fingerprint -sha256

BeatQuantum Labs Root CA R2 - Option B (Hybrid Post-Quantum)

Status: Valid

Algorithm SLH-DSA-SHA2-256s (FIPS 205)
Valid until 4 May 2046 GMT
SHA-256 Fingerprint FA:59:7E:38:62:7C:95:E4:39:98:67:0F:5E:2B:2A:B6:9A:72:03:A3:F5:81:0F:73:88:FF:E1:E9:EC:D8:91:AC
CRL http://crl.beatquantum.com/root-b.crl
Download beatquantum-root-r2.crt

Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-root-r2.crt -noout -fingerprint -sha256

BeatQuantum Limited TSA Root CA R3 - Time-Stamp Authority

Status: Valid

Algorithm SLH-DSA-SHA2-256s (FIPS 205)
Valid until 19 August 2046 GMT
SHA-256 Fingerprint 86:97:BD:DF:CE:41:28:F9:17:AC:17:DB:DD:D6:46:E1:73:7C:63:93:F9:8E:BE:BF:CA:9A:B5:28:98:BE:A7:06
CRL http://crl.beatquantum.com/tsa-root.crl
Download beatquantum-tsa-root-r3.crt

This root anchors RFC 3161 timestamping only and is not part of either certificate-issuance chain above. It is governed by the TSA disclosure statement, not the CPS. Verify the SHA-256 fingerprint before installing this certificate into any trust store. On Linux and macOS: openssl x509 -in beatquantum-tsa-root-r3.crt -noout -fingerprint -sha256

Issuance CA revocation (R1 / R2 chains)

ChainCRLOCSP
Option A issuing CA issuing.crl http://ocsp.beatquantum.com/
Option B issuing CA issuing-b.crl http://ocsp-b.beatquantum.com/

Time-Stamp Authority revocation lists

The TSA publishes CRLs only. There is no OCSP responder on the R3 hierarchy.

Issued byCRL
TSA Root CA R3tsa-root.crl
CNSA 2.0 TSA Intermediate CAtsa-intermediate-cnsa.crl
SLH-DSA TSA Intermediate CAtsa-intermediate-eu.crl
CNSA 2.0 TSA Issuing CAtsa-issuing-cnsa.crl
SLH-DSA TSA Issuing CAtsa-issuing-eu.crl
03

Systems

Current operational status of BeatQuantum services. All TLS-based services negotiate post-quantum hybrid and pure post-quantum key exchange.

Service Description Status
Web Server beatquantum.com - HTTPS Operational
Time-Stamp Authority tsa.beatquantum.com - RFC 3161 (CNSA 2.0 and SLH-DSA profiles) Operational
CRL distribution crl.beatquantum.com - HTTP Operational
OCSP (issuance CAs) ocsp.beatquantum.com and ocsp-b.beatquantum.com - HTTP Operational
SMTP Inbound and outbound mail (STARTTLS and SMTPS) Operational
IMAP / POP3 Mailbox access (STARTTLS, IMAPS, POP3S) Operational
VPN Virtual private network (OpenVPN) Operational
IKEv2 / IPsec Hybrid post-quantum key exchange (RFC 9370, ML-KEM) Operational
WireGuard Virtual private network Operational
DoH DNS over HTTPS (RFC 8484) Operational
DoT DNS over TLS (RFC 7858) Operational
DoQ DNS over QUIC (RFC 9250) Operational
NTS Network Time Security (RFC 8915), post-quantum NTS-KE Operational
LDAP Directory service (STARTTLS and LDAPS) Operational
PostgreSQL Database over TLS Operational
MariaDB Database over TLS Operational
Syslog Log collection over TLS (RFC 5425) Operational

Status indicators are currently updated manually. Automated monitoring integration is planned for a future release.

Prove first, speak later.

For certificate issuance see the CPS. For timestamping see the TSA disclosure statement.

View the CPS →