Field note ยท 2026-10-09
The trust layer under the stack.
A small hostname seen through DNS, TLS, Certificate Transparency, BGP origin data, and RPKI.
The name
stack.signifyingchain.com resolved to Cloudflare edge addresses in IPv4
and IPv6. Its parent nameservers were odin.ns.cloudflare.com. and
shaz.ns.cloudflare.com.. The parent DS query for signifyingchain.com
returned no DS records, so delv described the domain as an unsigned
answer rather than a fully validated DNSSEC chain.
The certificate
The live certificate was issued by Google Trust Services WE1, valid from
2026-10-06 01:32:05 GMT to 2027-01-04 02:32:01 GMT, and named
stack.signifyingchain.com in its subject alternative name. It carried
two embedded SCTs. One matched TrustAsia HETU2027 in Google's CT log
metadata; the other was visible in the certificate but did not match the
sampled log-list metadata.
The ledgers
- TrustAsia
HETU2027reported tree size 264,537,208 and 416 accepted roots. - Cloudflare
Nimbus2027reported tree size 478,769,569 and 615 accepted roots. - Google
Argon2027h1reported tree size 465,712,722 and 670 accepted roots. - Google
Xenon2027h1reported tree size 345,031,352 and 670 accepted roots.
The route claim
RIPEstat mapped the sampled edge addresses to Cloudflare AS13335. The
visible prefixes 172.67.144.0/20, 104.21.64.0/20,
2606:4700:3031::/48, and 2606:4700:3034::/48 all validated under
RPKI. A deliberately over-specific 104.21.71.0/24 check came back
invalid_length, which is the trust layer drawing a boundary.