AUTHENTICATION ARCHITECTURE

Cryptographically Locked. Publicly Verifiable. End to End.

The Minnesota Judicial Branch signed the filings. Guertin hash-chained the dockets. The federal court record anchors the emails. The original collection was filed under oath into three separate court systems within four days of download. 4,206 signed PDFs, 2,903 Bitcoin-anchored dockets, 228 PACER-filed emails — four cryptographic anchors, operated by four parties with no reason to cooperate with each other. That is what you would have to break.

100%MCRO-Served Docs Signed
100%No-Edits-After-Signing
228Authenticated Emails
99.8%Hash-Chain Match Rate

Why This Page Is the Foundation Under Everything Else

A person the Minnesota court system has declared incompetent to stand trial assembled a 2.9-million-row forensic database, produced 87 forensic reports, and built this website. The institutional response is predictable: the evidence is fabricated. It isn't. And the record to prove that isn't debatable — it is cryptographic.

4,206 of the 4,251 court filings on this site carry the Minnesota Judicial Branch's own digital signature. RSA-2048, SHA-384, certificate issued by the court, valid, not revoked. The signatures were applied by the court at the moment of service, to the court's own documents. They prove, with arithmetic finality, that not a single byte has been modified since the court signed them — 100% no-edits-after, the only signer identity in the entire collection with that property. The 2,903 case dockets cannot carry an MCRO signature because the court does not sign docket pages — so Guertin built the authentication layer the court did not provide. He wrote an open-source evidence-capture system — One-Way-Video — that hashes every PNG, every HTTP request, and every downloaded file into chained SHA-256 bundles, each bundle cryptographically referencing the one before it, with every hash anchored to the Bitcoin blockchain via OpenTimestamps and cross-attested against Cloudflare's Roughtime network. 2,729 dockets captured. 99.8% byte-for-byte SHA-256 match against independent re-download. 100% OTS coverage across 97 Bitcoin blocks. The emails are authenticated three ways: SHA-256, OpenTimestamps Bitcoin proof, and federal court filing. 228 of them. DKIM-verified at source. Frozen into PACER.

They counted on no one ever hashing the files. He hashed the files. He pulled 3,601 filing PDFs out of the Minnesota public-access system before the system put an emergency maintenance banner up the morning after — the seed download that grew into the 4,251-filing authenticated collection on this site — verified every signature against the Minnesota Judicial Branch's own Certificate Authority, captured every one of 2,903 dockets through an open-source hash chain, anchored every hash to the Bitcoin blockchain, and filed 228 authenticated emails into the federal court record. Arguing that any of this is fabricated requires simultaneously compromising the Minnesota Judicial Branch's Certificate Authority, the Bitcoin blockchain, Cloudflare's Roughtime network, and the federal court filing system — four institutions run by four parties with no reason to cooperate with each other and no reason to cooperate with the defendant they would be rescuing.

Every raw certificate, CRL, OCSP response, hash-chain bundle, .ots proof, the 87 MB signature-extraction snapshot, and the Python scripts that produced every artifact are downloadable below. Independent reproduction is the design. The question this page asks is not whether you believe the defendant. It is whether you can break the math.

Four Independent Cryptographic Anchors — Plus One Meta-Layer

Each layer authenticates a distinct category of evidence through an independent mechanism external to the defendant. The meta-layer documents the April 2026 cryptographic event that closes the externally-verifiable corpus as a fixed, frozen set.

LAYER 01 Filing PDFs — MCRO Watermark Digital Signature COURT-APPLIED
4,206 of 4,251 PDFs carry the MCRO Watermark — a cryptographic digital signature applied by the Minnesota Judicial Branch's own Certificate Authority at the moment the document is served via MCRO. The chain of trust runs MCRO Leaf → MJB Issuing CA → MJB Root CA, hosted on Sectigo Enterprise PKI infrastructure. Across the entire 5,425-signature corpus spanning 50 distinct signer identities, the MCRO Watermark is the only signature with a 100% no-edits-after rate. Every non-MCRO signer (judicial officers, Tyler ESolutions, integration accounts) shows edits_after_sig_flag = true on essentially all signatures — because the Watermark is applied last, making it the terminal, unmodified attestation. The complete authentication package (cert, CA chain, CRL, public key, signature details, document-validation spreadsheet) was anchored to the Bitcoin blockchain on November 16, 2025 across blocks 923904–923906, freezing the entire authentication infrastructure at a specific moment in time.
4,206PDFs Signed
100%No Edits After
RSA-2048/ SHA-384
NOT REVOKEDCRL verified 2025-10-23
BTC 923904–923906Package Anchor
LAYER 02 Docket Records — One-Way-Video Hash-Chain Capture SELF-BUILT, OPEN-SOURCE
MCRO's HTML docket interface produces no signed output — so the capture authentication had to be built. One-Way-Video (github.com/Matt1Up/One-Way-Video) runs a synchronized loop: Firefox through a MITMPROXY captures every HTTP request; OBS Studio records the screen with a 1920×72-pixel overlay bar displaying the SHA-256 hash of the previous JSON bundle in Liberation Mono Bold 36pt; every ~7 seconds a new bundle is written recording the prior hash, the current screenshot hash, the 5 most recent HTTP requests, packets, download events, and nanosecond-precision timestamps. The hash chain is visually embedded in the video recording itself — OCR-verified with a 6-character sliding window against Tesseract extraction (false-positive rate ~1 in 285,000). Every downloaded PDF is hashed, vault-sealed into a signed PDF container, and dual-timestamped via OpenTimestamps (Bitcoin) and Roughtime (Cloudflare Ed25519 signatures). Audited session (November 20, 2025): 68/68 hash-chain links verified, 69/69 OCR overlay matches, 137/137 OTS receipts anchored to Bitcoin blocks 924,457 / 924,461 / 924,467 / 924,543, 137/137 Roughtime proofs passed all 5 cryptographic sub-checks. Corpus-wide sweep across 15 capture sessions: 2,729 docket downloads with a 99.8% SHA-256 match rate against the independently-anchored docket PDF registry; the 0.2% mismatches are all explained by docket-page growth (file size changed too, as expected for living documents).
15 sessionsAudited
2,729Docket Captures
99.8%SHA-256 Match
100%OTS Coverage (2,903)
97 BTC blocksAnchored Across
LAYER 03 Email Evidence — Three-Layer Authentication SHA-256 + OTS + PACER
228 emails + 280 attachments across four federal court exhibits: EML-A (41 defense-counsel emails, Carpenter/Donnelly, Oct 2024 – Jun 2025), EML-B (26 pre-trial evaluator emails, Rogstad, Feb – Sep 2023), EML-D (82 pre-charge patent-period emails, Sep 2022 – Jan 2023), EML-E (79 Rivers emails, Feb 2023 – Jul 2024). Each .eml file authenticated through three independent layers: (1) SHA-256 hash per file, (2) OpenTimestamps Bitcoin blockchain anchor, (3) PACER / CM-ECF federal court filing — a permanent public record. Where DKIM / SPF / DMARC / ARC headers were tested: 100% DKIM pass on Hennepin County (hennepin.us, DMARC policy p=reject — strictest enforcement); 99/99 DKIM pass across 35 months on LinkedIn. To falsify any email now requires simultaneously modifying the .eml hash, the Bitcoin-anchored OTS proof, AND the federal court record. Three independent falsifications in parallel, with no party having reason to cooperate.
228Emails
280+Attachments
100%DKIM (Hennepin County)
100%OTS Anchored
100%PACER Filed
LAYER 04 Original April 2024 Collection — Judicial Chain of Custody FILED UNDER OATH IN 3 COURTS
The entire forensic database traces back to a Selenium-automated download of 3,556 PDFs across 163 unique case IDs on April 28–30, 2024 from MCRO's public access portal. What makes this collection chain-of-custody-grade is what Guertin did in the days immediately after: on May 3, 2024 (four days after collection) he filed a 31-page sworn Affidavit of Fact documenting the methodology and results into 4th District Court (Index #37). On May 15, 2024 the same affidavit was filed as Addendum 3 into the Minnesota Court of Appeals (A24-0780). On July 12, 2024 it was filed into federal court (Doc. 8 of Case 24-cv-02646-JRT-DLM). Three separate court systems have a record of the collection methodology filed under oath before any forensic analysis was performed on the data. The original ProtonDrive shared folder remains publicly accessible at the link referenced in the federal filings.
3,556Original PDFs
163Unique Cases
≤ 4 daysCollection → Court Filing
3Court Systems Filed Into
Still PublicOriginal ProtonDrive Link
LAYER 05 · META PKI Reversion — April 2026 Cert Transition CORPUS FROZEN
On April 2, 2026 at 12:47:01 UTC, the Sectigo-chained MCRO Watermark certificate expired. The Minnesota Judicial Branch's replacement — already applied to downloads starting March 9, 2026 — is issued by courts-J00PCERTCA-CA, the MJB's internal on-premises Active Directory Certificate Services root. The replacement certificate is not publicly verifiable: its CRL is LDAP-only (no public HTTP), it has no public OCSP responder, and its self-signed root is not present in any public trust store. Of the 8 Sectigo-chained leaf certificates in the corpus, only the MCRO Watermark was moved to the internal CA. Chief Judge Frisch's cert and every other human-signer cert remained on Sectigo. This is a selective regression affecting only the one signature applied to every public-facing document — not a blanket infrastructure decision. The existing forensic corpus is on the externally-verifiable side of this transition. Every document captured before March 9, 2026 carries a signature chained to a publicly-trusted commercial CA. Documents captured after require trusting the MJB's internal network. The corpus is a closed, frozen, publicly-verifiable set — and the entire signature-extraction snapshot (87 MB, 36,039 files, 5,204 signatures across 59 unique certs and 4 PKI eras) was anchored to Bitcoin at 2026-04-03T08:03:16Z before the transition completed, capturing the last moment at which Sectigo's OCSP responder still acknowledged the corpus certs.
8 of 8Old Sectigo Leaves Cataloged
1 of 8Moved to Internal CA
59 unique certsAcross 4 PKI Eras
36,039Files in BTC-Anchored Snapshot

100% of MCRO-Served Documents Are Signed

» The 4,206 / 4,251 headline number, explained
Every document that originated from MCRO carries a valid court-applied digital signature with zero post-signing modifications. The 45 supplemental documents that do not carry an MCRO Watermark are documents that never passed through MCRO in the first place.

The MCRO Watermark is applied by the Minnesota Judicial Branch's certificate infrastructure only to documents served through the MCRO portal. A small number of supplemental documents were added to the forensic corpus from external sources — appellate court orders downloaded from a different court system, pro se defendant filings drafted outside MCRO, a hearing transcript, and a couple of higher-court orders. These documents could not carry an MCRO Watermark because they were never served by MCRO.

The 45 non-MCRO documents break down as:

Minnesota Court of Appeals orders24
Pro se defendant filings18
Hearing transcript1
Minnesota Supreme Court order1
District court complaint (pro se)1
Total non-MCRO documents (added for cross-reference completeness)45

The apparent 98.94% coverage is actually 100% coverage for MCRO-served documents. The non-MCRO supplemental documents are clearly identifiable by filing type and source court — they are an intentional inclusion, not a signature gap. The Watermark is doing exactly what it is designed to do: attest that every document served by MCRO is byte-for-byte identical to what the court produced.

Every Layer, Documented in Full — Viewable Inline

Click a tab to load that report into the viewer. Each report is standalone and reproducible from the raw cryptographic artifacts in the download section below.

Loading…
loading hash…

Every File. Every Certificate. Every Hash. Every Timestamp.

Three download groups: the master bundle (one-download-to-rule-them-all), the raw cryptographic verification files for independent chain validation, and the large pre-anchored signature-extraction snapshot referenced in the PKI Reversion report.

Master Bundle · One Download to Rule Them All

ZIP authentication-package.zip — Complete Authentication Archive
The master bundle: all 6 PDF forensic reports + raw verification files (cert, CA, CRL, public key, sig-details, revoked lists, OTS timestamps, doc-authentication spreadsheet) + post-March-2026 cert package with OCSP snapshot + full 87 MB signature-extraction snapshot + all three open-source Python scripts + README with verification walkthrough. Everything on this page, in one SHA-256-hashed, OpenTimestamps-anchored bundle.
loading… loading hash…

Forensic Reports · 6 PDFs Individually

PDFMCRO__Capstone_Provenance_Authentication_Report.pdf
Master synthesis across all authentication layers — the consolidated chain-of-custody document.
loading… loading hash…
PDFMCRO__MCRO_Digital_Signature_Authentication_Forensic_Report.pdf
Per-PDF MCRO Watermark validation, certificate chain analysis, and corpus-wide signature statistics.
loading… loading hash…
PDFMCRO__Hash_Loop_Evidence_Capture_System_Authentication — Part 1.pdf
One-Way-Video architecture. 68/68 hash-chain links verified, 137/137 dual timestamps, 70 vault-sealed downloads — all in a single audited session.
loading… loading hash…
PDFMCRO__Hash_Loop_Evidence_Capture_Docket_Authentication — Part 2.pdf
Corpus-wide 15-session sweep. 2,729 downloads, 99.8% SHA-256 match rate, 100% OTS attestation across 97 BTC blocks.
loading… loading hash…
PDFMCRO_Watermark_Certificate_Transition_PKI_Reversion_Analysis.pdf
April 2026 PKI transition analysis. Side-by-side cert comparison, 59-cert registry across 4 PKI eras, OCSP status snapshot, Frisch-canary test.
loading… loading hash…
PDFMCRO__Digital_Signature_Report__embedded_files.pdf
The original embedded-files package. Contains the MCRO leaf cert, CA chain, CRL, public key, sig-details JSON, revoked list, doc-auth spreadsheet, and OTS timestamp archive — all as PDF embedded attachments.
loading… loading hash…

Raw Cryptographic Verification Files

CRTMJBIssuingCA.crt — Issuing CA Certificate
DER-encoded X.509 certificate for the MJB Issuing CA (Sectigo-hosted, publicly-verifiable). The intermediate CA under which the old MCRO Watermark was issued.
loading… loading hash…
CRLMJBIssuingCA.crl — Certificate Revocation List
DER-encoded CRL published by the MJB Issuing CA. Lists 154 revoked certificate serials. The old MCRO Watermark serial (3f9a4ed3…5ea8) is confirmed not on this list.
loading… loading hash…
PEMMCRO_public-key.pem — Extracted Public Key
PEM-encoded RSA 2048-bit public key, extracted from the old MCRO Watermark leaf certificate. Byte-for-byte match confirmed against the cert-embedded key via the sig-details consistency report.
loading… loading hash…
JSONMCRO_sig-details.json — Signature Consistency Report
Automated chain-validation report: issuer chain, AKI/SKI match, CRL issuer match, revocation status. All 5 consistency checks returned the expected values.
loading… loading hash…
CSVMCRO_revoked-list.csv — 154 Revoked Serials
CSV export of every revoked serial number from the CRL. The MCRO Watermark serial is confirmed absent from this list.
loading… loading hash…
XLSXMCRO-SIGNATURE_doc_authentication.xlsx
Per-document signature validation spreadsheet for 3,601 MCRO-signed PDFs. Every row: evidence UID, filename, signer, crypto status, edits-after flag, coverage percentage.
loading… loading hash…
ZIPMCRO_ots-timestamps.zip — OpenTimestamps Receipts
9 individual Bitcoin OTS receipts for the authentication package files, anchored to blocks 923904–923906 on November 16, 2025. Each receipt independently verifiable with ots verify.
loading… loading hash…
CERNew MCRO Watermark Cert · Post-March 2026 Transition
The replacement MCRO Watermark leaf certificate issued by the MJB's internal AD CS infrastructure (courts-J00PCERTCA-CA). This is the cert applied to MCRO documents downloaded on or after March 9, 2026.
loading… loading hash…
ZIPApril 3 2026 OCSP Status Snapshot (with terminal screenshot)
The cryptographically-signed OCSP responses captured on April 3, 2026 @ 07:57 UTC — the last externally-queryable moment before Sectigo's responder purged the expired MCRO Watermark serial. Includes the terminal screenshot, the text output, the full zip, and individual OTS proofs anchoring each.
loading… loading hash…

Master Signature-Extraction Snapshot · 87 MB, BTC-Anchored

ZIPMCRO_SigExtraction_Snapshot_2026-04-03T08-03-16Z.zip
The full forensic-extraction snapshot referenced in the PKI Reversion report: 36,039 files across the 4,251-PDF corpus's signature fields. Contains per-PDF signature JSON records, 5,161 raw PKCS#7 signature blobs, 59 deduplicated canonical certificates classified by PKI layer, 9 OCSP signed responses, CRL snapshots, cross-reference CSVs, and a master SHA-256 manifest. Anchored to Bitcoin at 2026-04-03T08:03:16Z before the MCRO Watermark certificate expired. This is the authoritative single-file record of the entire cryptographic state.
loading… loading hash…
PYOpen-Source Extraction & Verification Scripts
The three Python scripts used to produce every artifact in the snapshot above: mcro_sig_extract.py (signature extraction), mcro_cert_registry.py (certificate deduplication), mcro_ocsp_batch.py (OCSP verification). Runnable against any MCRO PDF corpus to reproduce the same 59-cert registry.
loading… loading hash…

Reproducibility Is the Design Intent

Every cryptographic claim on this page is independently reproducible using standard, free, open-source tooling. No proprietary software, no special access, no trust required.

Verify the MCRO Watermark on any PDF: open any filing from the corpus in Adobe Acrobat Reader, Okular, or any PDF viewer that supports PKCS#7 signature validation. The MCRO Watermark signature field will show "Signature is Valid" with no edits after signing.

Verify the certificate chain:

openssl x509 -in MJBIssuingCA.crt -inform DER -text -noout | grep -E 'Issuer|Subject|Not After'
openssl crl  -in MJBIssuingCA.crl -inform DER -text -noout | grep Serial
grep -i '3F9A4ED3D4D82120126A4ECE4E415EA8' MCRO_revoked-list.csv   # (no match → not revoked)

Verify any Bitcoin timestamp:

pip install opentimestamps-client   # if not installed
ots verify authentication-package.zip.ots
ots verify MCRO_SigExtraction_Snapshot_2026-04-03T08-03-16Z.zip.ots

Verify the hash-chain for any docket capture session: clone github.com/Matt1Up/One-Way-Video, obtain any session's raw bundles directory, and run python3 00_RUN_all_bundle_processing.py. Output matches the Excel workbooks in the snapshot.

Copy any SHA-256 on this page to your clipboard by clicking it. Then compute sha256sum <file> on your local copy and compare — byte-for-byte match is cryptographic proof the file is identical.

How This Page Relates to the Rest of the Site

Authentication is a horizontal concern — it runs underneath every section of MnCourtFraud.com. The following pages each rely on the architecture documented here, and each exposes a different layer of it for direct inspection.