Table of contents
Namespace: Com\Tecnick\Pdf\Sign\Ltv
final class Crl
Source: src/Ltv/Crl.php:52
RFC 5280 CertificateList reader. It checks what has to hold before a CRL is embedded in a Document Security Store as evidence: the bytes are one complete DER CertificateList, the issuer Name is the one that issued the certificate the distribution point came from, the two signature AlgorithmIdentifiers agree, the validity interval covers the moment of use, the list is a complete one rather than a delta or a scoped partition, and the signature verifies against the issuer’s public key.
The issuer certificate is required, none of the above being establishable without it. Given the certificate the list is being fetched for, its serial is looked up among the revoked entries as well, and a match is reported as a RevokedException.
Constants
CLOCK_SKEW
Default clock skew tolerated when checking the validity interval, in seconds.
Ocsp\Client and Timestamp\Client read the same value.
public const CLOCK_SKEW = \Com\Tecnick\Pdf\Sign\Ocsp\Client::CLOCK_SKEW
Source: src/Ltv/Crl.php:58
DEFAULT_MAX_AGE
Default age limit applied to thisUpdate, in seconds.
public const DEFAULT_MAX_AGE = \Com\Tecnick\Pdf\Sign\Ocsp\Client::DEFAULT_MAX_AGE
Source: src/Ltv/Crl.php:63
Methods
__construct()
public __construct(
?Asn1 $asn1 = null,
?Certificate $certificate = null,
?SignatureVerifier $verifier = null,
int $maxAge = \self::DEFAULT_MAX_AGE,
int $clockSkew = \self::CLOCK_SKEW
)
Parameters:
$asn1(?Asn1)$certificate(?Certificate)$verifier(?SignatureVerifier)$maxAge(int): Age limit applied to thisUpdate, in seconds. Zero disables the bound.$clockSkew(int): Skew tolerated between the validity interval and the moment of use, in seconds.
Throws:
- Exception: If the age limit or the skew is negative.
Source: src/Ltv/Crl.php:118
validate()
Validate a DER CertificateList against the certificate that issued it.
public validate(
string $crlDer,
string $issuerDer,
string|null $subjectDer,
int|null $now = null
): string
Parameters:
$crlDer(string): DER-encoded CertificateList.$issuerDer(string): DER of the issuing certificate.$subjectDer(string|null): DER of the certificate the list is being fetched for, or null to run the structural checks alone and skip the revocation lookup.$now(int|null): Unix time the validity interval is checked against; defaults to the current time.
Returns: string: The CRL bytes unchanged, once accepted.
Throws:
- RevokedException: If $subjectDer is listed as revoked.
- Exception: If the CRL is malformed, issued by another authority or by a certificate that may not sign CRLs, outside its validity interval, incomplete in scope, or not correctly signed.
Source: src/Ltv/Crl.php:156