Answers which tenants have moved off the deployment RFC 3161 default, and onto what in ONE read, over the WHOLE tenant population.
It never answers 404, and that is the point. The per-tenant override read uses 404 to mean this tenant inherits — defensible when you asked about one tenant, and wrong for a fleet, because an operator asking who has diverged would get an error for every tenant that has not. Here an inheriting tenant is counted in onDefaultCount and is absent from bindings; the only statuses this path can return are 200, 401, 403 and 500.
The response is a CLASS-level projection, on both planes. This surface has no closed vendor vocabulary — a connection is an endpoint URL, a policy OID, a hash algorithm and a timeout — so the class is the one fact that is one: whether the plane timestamps. RFC3161_TSA names a plane pointed at an authority and TIMESTAMPING_DISABLED a plane that has switched timestamping off, which is a divergence in its own right and is never folded into the inheriting band. It deliberately omits: the TSA endpoint URL, the policy OID, the hash algorithm, the timeout, the client credential and its mask, and the per-tenant KEK reference. The same rule binds the DEPLOYMENT default — deploymentShape and deploymentLabel name its class, never a configured value, and on this surface that is not a formality: the deployment TSA URL is not under this endpoint's scope at all.
The four coverage bands partition the whole population, so onDefaultCount + divergingCount + notEligibleCount + suspendedCount == tenantCount always holds. This surface has no entitlement plane, so notEligibleCount is 0 and notEligibleTenants is [] — present, never omitted. A suspended tenant stays INSIDE the denominator.
deploymentStatus is the deployment's timestamping CAPABILITY, not the settings flag alone. TSA_ENABLED=false DOMINATES and is NOT_CONFIGURED whatever the trust-anchor count — a deliberate operator decision is not a fault. Only once the plane claims to timestamp does the anchor count decide: at least one ACTIVE RFC 3161 trust anchor is ACTIVE, and none is ATTENTION — configured but not operational, which is what ATTENTION means everywhere on this platform. The anchor fact is deployment-global: it never reaches a bindings[*].status.
surfaceStatus is the server-composed worst-of across both planes (FR-190.21); deploymentStatus and every bindings[*].status are returned unchanged beside it. chain is [] — this is not an ordered-chain surface — and deploymentChain is [] because this plane is SINGLE_VALUED: it holds at most one class, and deploymentShape names it. The two keys are empty for DIFFERENT reasons, and after PRD §202 they must be: a surface that is not ordered-chain may still populate deploymentChain — the three multi-class surfaces do. It is the CARDINALITY, not the ordering, that empties it here. maxTenantBindings is null because it states no per-tenant ceiling. Both keys are PRESENT: a band with nothing in it emits 0, [] or null and never omits its key, which is what makes the six surfaces one envelope.
Takes no path and no query parameter, so no caller-supplied identifier enters a query. It writes nothing: no audit row, no event, no state change. Required: the ROOT platform tenant, holding admin.platform.settings.timestamping.override.read, admin.tenant.list and admin.platform.tsa-trust-anchor.manage. No conjunct is decoration. The second is what makes enumerating every tenant and NAMING it not a widening, which the surface scope alone does not grant. The third is what keeps this response a strict subset of what its caller may already read directly: deploymentStatus discloses whether the deployment holds an ACTIVE RFC 3161 trust anchor, and that fact is otherwise obtainable only through GET /api/v3/admin/platform/tsa/trust-anchors, which is gated on it.
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||