Back to the museum

Field note ยท 2026-10-09

The trust layer under the stack.

A small hostname seen through DNS, TLS, Certificate Transparency, BGP origin data, and RPKI.

WE1Google Trust Services issuer
2 SCTsembedded in the live certificate
4 validsampled Cloudflare RPKI route origins
1,018,374unique VRPs in Cloudflare's RPKI snapshot

The name

stack.signifyingchain.com resolved to Cloudflare edge addresses in IPv4 and IPv6. Its parent nameservers were odin.ns.cloudflare.com. and shaz.ns.cloudflare.com.. The parent DS query for signifyingchain.com returned no DS records, so delv described the domain as an unsigned answer rather than a fully validated DNSSEC chain.

The certificate

The live certificate was issued by Google Trust Services WE1, valid from 2026-10-06 01:32:05 GMT to 2027-01-04 02:32:01 GMT, and named stack.signifyingchain.com in its subject alternative name. It carried two embedded SCTs. One matched TrustAsia HETU2027 in Google's CT log metadata; the other was visible in the certificate but did not match the sampled log-list metadata.

The ledgers

The route claim

RIPEstat mapped the sampled edge addresses to Cloudflare AS13335. The visible prefixes 172.67.144.0/20, 104.21.64.0/20, 2606:4700:3031::/48, and 2606:4700:3034::/48 all validated under RPKI. A deliberately over-specific 104.21.71.0/24 check came back invalid_length, which is the trust layer drawing a boundary.

Sources