tc-lib-pdf-sign

tc-lib-pdf-sign API reference

Com\Tecnick\Pdf\Sign

Classes:

  • Config: Immutable signature configuration value object.
  • Exception: Custom Exception class for the PDF signature library.
  • RevokedException: Thrown when a responder or a CRL states that a certificate is revoked.
  • Signer: Package-internal orchestration entry point that ties the CMS builder, the RFC 3161 timestamp codec, and the LTV material collector together behind two host-facing calls.

Enums:

Com\Tecnick\Pdf\Sign\Cms

Classes:

  • Asn1: Minimal DER ASN.1 encoder/decoder used to assemble and inspect CMS/CAdES structures, RFC 3161 timestamp messages, and OCSP requests.
  • Builder: Native builder for a detached CAdES-BES CMS SignedData, suitable for a PAdES B-B signature (/SubFilter /ETSI.CAdES.detached).
  • Certificate: Reads the TBSCertificate fields that CMS and OCSP structures quote verbatim: the issuer and subject Names, the serial number, and the public key bits.
  • Oid: The object identifiers of the CMS content types and signed attribute types this library emits and reads.
  • SignatureVerifier: Verifies the signature of a DER structure that follows the X.509 shape of a signed body, an AlgorithmIdentifier, and a signature BIT STRING.
  • SignedDataVerifier: Verifies a CMS SignedData that carries its own content, which is the shape of an RFC 3161 timestamp token.
  • SigningRequest: Validated, immutable record of everything the CMS signed attributes are derived from.

Enums:

  • SignatureEncoding: Backed enum for the encoding of a signature handed to Builder::buildFromSignature().

Com\Tecnick\Pdf\Sign\Ltv

Classes:

  • Crl: RFC 5280 CertificateList reader.
  • ValidationMaterial: Collects the long-term validation (LTV) material embedded in a PDF Document Security Store (DSS): the certificate DERs, OCSP responses, and CRLs.

Enums:

  • SkipReason: Machine-readable classification of a discarded revocation URL, passed to the $onSkip observer alongside the human-readable message.

Com\Tecnick\Pdf\Sign\Ocsp

Classes:

  • Client: RFC 6960 OCSP codec.
  • Request: An OCSP request together with the CertID it asks about, which RFC 6960 section 3.2 requires the response to be matched against before it is accepted.

Com\Tecnick\Pdf\Sign\Output

Classes:

  • DocTimeStamp: Emits a document timestamp value object (/Type /DocTimeStamp, /SubFilter /ETSI.RFC3161) whose /Contents is a bare RFC 3161 timestamp token.
  • Dss: Emits the Document Security Store (DSS) PDF objects for a signature: the certificate, OCSP, and CRL streams, a VRI entry, and the DSS dictionary.
  • PdfString: Encodes a text value as a PDF string token, either through a host-supplied encoder (which may apply UTF-16, escaping, and encryption) or, when none is given, a built-in fallback.
  • Signature: Emits the /Sig value dictionary (the object referenced by a signature field’s /V): the fixed skeleton, the /SubFilter, and the /ByteRange and /Contents placeholders that the host rewrites while signin
  • Widget: Emits a signature field’s widget annotation (/Subtype /Widget, /FT /Sig).

Com\Tecnick\Pdf\Sign\Timestamp

Classes:

  • Client: RFC 3161 timestamp codec.
  • Config: Immutable RFC 3161 Time Stamping Authority (TSA) configuration.
  • Request: A TimeStampReq together with the message imprint and nonce it carries, which RFC 3161 section 2.4.2 requires the requester to check against the returned token.