MachineWitness — verification instructions for one witness (witness-2)
URL: https://machinewitness.eu/.well-known/http-message-signatures-directory
Day (UTC): 2026-09-28

This package is ONE witness's evidence. MachineWitness runs two independent
witnesses at two different providers; a full extract combines this ZIP with
the sibling witness's, built the same way on its own machine. Do not treat
one witness's package as the whole proof — see machinewitness.eu/extract.

0. WHAT THIS PACKAGE COVERS, AND WHAT IT DOES NOT
   Ring: core.
   Ring membership as recorded when this package was built; it is not
   historised. If a domain was moved into the core ring later, older
   observations were still taken under the broad ring's rules. The observation
   days measured below are the statement to rely on.

   Cadence rule this witness applies today (configuration, not a sealed fact):
     core: fetched every day, stored in full, subject only to an operating
     ceiling of 33554432 bytes

   Measured: between 2026-08-24 and 2026-09-28 this witness holds
   observations of this URL on 7 day(s):
     2026-09-22, 2026-09-23, 2026-09-24, 2026-09-25, 2026-09-26, 2026-09-27,
     2026-09-28
   This witness's live database only reaches back to 2026-09-22; earlier days
   have been moved into sealed daily bands and are not counted here. A day
   missing from the list above is therefore not evidence that nothing was
   observed on it — ask for those days and they are restored from the band.

   Completeness of the payloads in this package:
     observation 34605946: HTTP 404: the body of an error response is not
     stored (only HTTP 403 bodies are kept, capped at 32768 bytes, because
     they show how a crawler is turned away). Status, headers and provenance
     of this response are sealed as usual, and so is the SHA-256 of the body
     that was served.
       HTTP 404: the body of an error response is not stored (only HTTP 403
       bodies are kept, capped at 32768 bytes, because they show how a crawler
       is turned away). Status, headers and provenance of this response are
       sealed as usual, and so is the SHA-256 of the body that was served.

1. THE PAYLOAD MATCHES ITS HASH
   sha256sum payload-<id>.bin
   Compare the result against payload_sha256 in leaf-<id>.json.
   No payload-<id>.bin for an observation: see its 'payload' note in
   manifest.json — either the fetch failed (status/error are still in the
   sealed leaf), or the plaintext was removed under a GDPR request (§6b);
   either way the hash stands even though the bytes do not.

2. THE LEAF RECOMPUTES
   leaf = sha256(0x00 || "mwleaf-v1|" || url || "|" || observed_at || "|"
                  || payload_sha256 || "|" || status || "|" || provenance_sha256)
   provenance_sha256 = sha256sum provenance-<id>.json, the file exactly as it
   is (compact JSON, keys sorted, no trailing newline — the bytes that were hashed).
   Compare the result against the 'leaf' field in leaf-<id>.json.

3. THE LEAF IS IN THE DAY'S ROOT
   proof-<id>.json lists the sibling hashes on the path from this leaf to
   the root, each tagged 'left' or 'right'. Fold them in order, starting
   from the leaf hash as bytes:
     side 'left'  -> node = sha256(0x01 || sibling || node)
     side 'right' -> node = sha256(0x01 || node || sibling)
   The final value must equal 'root', which must equal d568805980fcf63d4fbdb54959ec16efda605b13fc1cae54b88fb94a7ebdc55d.

4. THE ROOT IS ANCHORED
   2026-09-28.root.txt is the exact file that was anchored — its second line is
   the root hash from step 3.
   2026-09-28.root.txt.ots      -> verify with: ots verify 2026-09-28.root.txt.ots
   2026-09-28.root.txt.tsr      -> verify with: openssl ts -verify -in
                              2026-09-28.root.txt.tsr -data 2026-09-28.root.txt -CAfile
                              <freetsa.org CA certificate, see docs/qts-anker.md>
   2026-09-28.root.txt.qts.tsr, if present, is a GLOBALTRUST-qualified RFC 3161
                              token (eIDAS Art. 41 presumption) — verify the
                              same way against GLOBALTRUST's CA chain.

What an extract proves, and what it does not, is stated in full at
https://machinewitness.eu/extract (docs/site/glossary.md 'Evidence extract').
