The AION-KW Time-Guardian
The visual heart of the AION-KW PKI is represented by the legendary crowned griffinβa noble mythological beast uniting the foresight of the eagle with the unshakeable strength of the lion.
Cryptographic timestamp verification anchors the validity of signatures indefinitely, neutralizing local clock tampering threats.
Robust 4096-bit asymmetry bound to SHA-256 message digests, ensuring future-proof protection of critical network nodes.
AION-KW Trust Anchor Directory
Providing cryptographic verification assets, revocation lists, and secure, high-precision document time-stamping.
π‘οΈ Public Cryptographic Assets & CRLs
Root CA Certificate
Ultimate trust anchor used to initialize computer chains.
Intermediate CA
Active delegation authority that signs signing certificates.
TSA Leaf Cert
Leaf certificate used directly by the signing loop.
Owner Signer Cert
Personal S/MIME profile issued to Kelvin Wong.
Root CA CRL
Revocation list specifically checking Intermediate CA status.
Intermediate CA CRL
Revocation list checking end-user credentials, S/MIME profiles, and TSA Leaf status.
Live Telemetry & Endpoint Health
This controller performs dynamic polling queries directly against your local background engines, authority paths, and CRL files to check live system readiness and prevent authorization bottlenecks.
RFC 3161 Timestamp Authority
OCSP Responder Gateway
CRL Publication Engine
Drag-and-Drop X.509 Certificate Scraper
Upload your PEM certificate file (.crt, .pem, .cer) to parse and visualize its validity metrics instantly on your dashboard!
Click to select or drag your certificate here
Accepts standard X.509 PEM certificate blocks
Interactive Registration Portal
Choose a certificate template profile to dynamically configure common name entries, generate corresponding local terminal enrollment commands, or mock-issue leaves directly inside your local browser cache!
Configure Certificate parameters
Authority Registration & Revocation Registry
| Serial Hex | Common Name (CN) | Template profile | Lifecycle Status | Terminal actions |
|---|---|---|---|---|
| 01A39D9B | rsa.wongkelvin.com | TSA Server Profile | Active | |
| 01A39D9C | ocsp.wongkelvin.com | OCSP Signer Profile | Active | |
| 01A39D9D | Kelvin Wong | Owner Signer Profile | Active |
Operational Lifespans
The integrity of a PKI relies on hierarchical expiration limits. The Root CA represents the absolute trust anchor, requiring an extended 20-year lifespan (7,300 days) to minimize dangerous root rotation events.
In contrast, the Intermediate CA acts as a protective buffer, issued with a 10-year lifespan (3,650 days). This structural constraint ensures that any potential compromise at the intermediate level naturally decays faster than the root itself.
Cryptographic Profiles Overview
The radar analysis below structures the cryptographic capability boundaries. Only the authorities hold permission to execute certificate and CRL issuing, preventing privilege escalation.
Unified Routing Interfaces
Endpoints resolve seamlessly over secure pathways utilizing Cloudflare tunnels to bridge external requests to internal port processes.
AI Cryptographic Advisor
An LLM-driven assistant designed for debugging openssl, certutil, mapping tunnels, and validating active directories matching the local AION-KW configuration.