KW Logo 01
KW
K-Works
Stage 3 Security Cluster
KW Logo 02
PKI Cluster Status
AION TSA Live!! By K-Workz
AION-KW Cryptographic Griffin
πŸ›‘οΈ Operational Emblem β€’ RFC3161 TSA Node

The AION-KW Time-Guardian

The visual heart of the AION-KW PKI is represented by the legendary crowned griffinβ€”a noble mythological beast uniting the foresight of the eagle with the unshakeable strength of the lion.

We Stand With Time

Cryptographic timestamp verification anchors the validity of signatures indefinitely, neutralizing local clock tampering threats.

SHA256 β€’ RSA4096

Robust 4096-bit asymmetry bound to SHA-256 message digests, ensuring future-proof protection of critical network nodes.

X.509 Compliant β€’ Trust Chain Validated

AION-KW Trust Anchor Directory

Providing cryptographic verification assets, revocation lists, and secure, high-precision document time-stamping.

πŸ›‘οΈ Public Cryptographic Assets & CRLs

Root CA Certificate

Ultimate trust anchor used to initialize computer chains.

πŸ“₯ root.crt

Intermediate CA

Active delegation authority that signs signing certificates.

πŸ“₯ intermediate.crt

TSA Leaf Cert

Leaf certificate used directly by the signing loop.

πŸ“₯ tsa_cert.crt

Owner Signer Cert

Personal S/MIME profile issued to Kelvin Wong.

πŸ“₯ kelvin-signing.crt

Root CA CRL

Revocation list specifically checking Intermediate CA status.

Download Root CRL

Intermediate CA CRL

Revocation list checking end-user credentials, S/MIME profiles, and TSA Leaf status.

Download Intermediate CRL
Stage 2 Live Monitoring

Live Telemetry & Endpoint Health

This controller performs dynamic polling queries directly against your local background engines, authority paths, and CRL files to check live system readiness and prevent authorization bottlenecks.

RFC 3161 Timestamp Authority

Port: 3180
Version: v1.0.3
Latency: checking...
Checking...

OCSP Responder Gateway

URI: http://ocsp.wongkelvin.com/
Status: Probing port 8889...
Checking...

CRL Publication Engine

Status: checking...
CRL Number: waiting...
Next Update: waiting...
Days Remaining: waiting...
Revoked Count: waiting...

Drag-and-Drop X.509 Certificate Scraper

Upload your PEM certificate file (.crt, .pem, .cer) to parse and visualize its validity metrics instantly on your dashboard!

πŸ“œ

Click to select or drag your certificate here

Accepts standard X.509 PEM certificate blocks

Parsed Certificate Metrics
Common Name (CN): Not Loaded
Issuer Details: Not Loaded
Calculated Expiry (NotAfter): No data
Stage 3 Enrollment Hub

Interactive Registration Portal

Choose a certificate template profile to dynamically configure common name entries, generate corresponding local terminal enrollment commands, or mock-issue leaves directly inside your local browser cache!

Configure Certificate parameters

AION Terminal Output
# Select an option to output exact copy-pasteable OpenSSL setup sequences...

Authority Registration & Revocation Registry

Serial Hex Common Name (CN) Template profile Lifecycle Status Terminal actions
01A39D9B rsa.wongkelvin.com TSA Server Profile Active
01A39D9C ocsp.wongkelvin.com OCSP Signer Profile Active
01A39D9D Kelvin Wong Owner Signer Profile Active

Operational Lifespans

The integrity of a PKI relies on hierarchical expiration limits. The Root CA represents the absolute trust anchor, requiring an extended 20-year lifespan (7,300 days) to minimize dangerous root rotation events.

In contrast, the Intermediate CA acts as a protective buffer, issued with a 10-year lifespan (3,650 days). This structural constraint ensures that any potential compromise at the intermediate level naturally decays faster than the root itself.

Cryptographic Profiles Overview

The radar analysis below structures the cryptographic capability boundaries. Only the authorities hold permission to execute certificate and CRL issuing, preventing privilege escalation.

Unified Routing Interfaces

Endpoints resolve seamlessly over secure pathways utilizing Cloudflare tunnels to bridge external requests to internal port processes.

caIssuers Endpoint
https://rsa.wongkelvin.com/certs/intermediate.crt
CDP Distribution URI
https://rsa.wongkelvin.com/crl/intermediate.crl
OCSP Responder Endpoint
http://ocsp.wongkelvin.com
✨

AI Cryptographic Advisor

An LLM-driven assistant designed for debugging openssl, certutil, mapping tunnels, and validating active directories matching the local AION-KW configuration.

Advisor Idle. Choose a preset or type a question to perform cross-check analysis.