{
  "format": "iic-tsa-policy-1",
  "oid": "1.3.6.1.4.1.67100.1.1.1.1",
  "version": "1",
  "status": "approved",
  "operator": "HTTPS CARD - INTERNET IDENTITY CARD LIMITED",
  "service": "IIC TSA",
  "qualified": false,
  "status_note": "Not an eIDAS qualified trust service; not certified, accredited or recognised by any government body.",
  "related_party": "IIC TSA and VerifBox are operated by the same company; IIC TSA is not an independent third party for VerifBox users.",
  "operators": "single operator",
  "key_protection": "Google Cloud KMS, SOFTWARE protection level (not a hardware security module)",
  "hash_algorithms": ["sha256", "sha384", "sha512"],
  "signature": {"generation": "tsa-2026-a", "algorithm": "ecdsa-with-SHA256", "curve": "P-256"},
  "accuracy_seconds": 1,
  "ordering": false,
  "issuance": "SYNC only",
  "journal_retention_years": 12,
  "crl": ["https://tsa.internetidentitycard.com/tsa/crl"],
  "chain": "root only; the TSA certificate is issued directly by the root"
}
