Knowledge Base

Browse the concepts behind Truestamp. Follow the links between concepts, or search across everything.

RFC 6962

The Certificate Transparency standard Truestamp takes its Merkle hash primitives from - SHA-256 with 0x00 leaf and 0x01 node domain-separation prefixes, and the empty-tree root - while shaping the tree above them by its own key-sort and power-of-two padding rules.

Overview

RFC 6962 is the Certificate Transparency standard Truestamp takes its Merkle hash primitives from. It specifies SHA-256 hashing with single-byte domain-separation prefixes, 0x00 for leaves and 0x01 for interior nodes, and defines how leaves, nodes, roots, and audit paths are computed. Truestamp takes those primitives and not the standard’s tree shape, so an independent verifier needs the published spec plus Truestamp’s two extra rules, a byte-wise key sort and padding out to a power of two. The hashing has been scrutinized and depended upon at internet scale by Certificate Transparency, which is why Truestamp adopted it rather than inventing a bespoke scheme; the full construction and the divergences are covered in Truestamp’s Merkle tree, and the byte-prefix discipline it introduced extends across all of Truestamp’s hashing in hashing domain separation.

Citations

  1. RFC 6962: Certificate Transparency. The standard defining the Merkle hash construction and domain-separation prefixes named by this term.