A real trust chain was just minted in your browser.
Certificate claims each one is checked by a test in this repository
Five certificates — a CA, two agents, two signing authorities P-256 keypairs, generated in this tab by Web Crypto (§7.1: 128-bit security, EC recommended) Certificates signed ecdsa-with-SHA256; envelopes signed ECDSA as fixed-width r‖s (§3.1) Real X.509 — openssl verify -ignore_critical returns OK; plain openssl verify refuses them, by design (§8.2) The Agent Template extension, critical, carrying the nine template members as JCS (§8.2) The child carries the Agent Spawn extension: parent, timestamp, nonce, CA-attested (§10.5) RFC 5280 profile — cA:FALSE, keyUsage digitalSignature only, 160-bit serials, keyCertSign on the CA cRLDistributionPoints on every leaf, pointing at a .invalid host (§14.4) Name-constrained — this CA cannot issue for a real hostname Validity bound to each template’s TTL: 24 h parent, 12 h child, and enforced (§9.3) Owner and Policy Authority each hold their own CA-issued certificate; the Owner’s CN is the template owner (§9.2) The CA is self-signed and in nobody’s trust store
Edit the document on the left or press a modify button below, then Validate to re-run all nine checks. Green changes stay valid. Red ones are refused, and name the clause of the draft that refused them.
EDIT — THE DOCUMENT IS THE SOURCE OF TRUTH every panel is a view over this JSON
VALIDATE — NINE CHECKS, SEVEN STEPS click a refusal to jump to the field
TRY IT

Each button edits the document, jumps to the line it changed, then re-validates — grouped by the step of the chain each one exercises.