ValidationMaterial

Collects the long-term validation (LTV) material embedded in a PDF Document Security Store (DSS): the certificate DERs, OCSP responses, and CRLs.

Namespace: Com\Tecnick\Pdf\Sign\Ltv

final class ValidationMaterial

Source: src/Ltv/ValidationMaterial.php:52

Collects the long-term validation (LTV) material embedded in a PDF Document Security Store (DSS): the certificate DERs, OCSP responses, and CRLs. URL discovery decodes the certificate AIA and CRL distribution point extensions from their DER rather than from OpenSSL’s rendering of them. Network retrieval is delegated to injected transport callables, so this class chooses the URL and the host decides whether to fetch it and carries the SSRF question. The VRI key (SHA-1 of the signature Contents) is not computed here: it belongs to the DSS writer, which holds the final signature bytes.

Collection is best-effort: a URL that cannot be reached, or that answers with something the codecs reject, is skipped so the next one can be tried. Every skip is reported to the optional $onSkip observer, with a SkipReason separating a revoked verdict from an unreachable responder.

Constants

MAX_URLS

Most revocation URLs taken from one certificate extension.

Every URL becomes a call to the host’s transport. The excess is reported through $onSkip rather than dropped.

public const MAX_URLS = 8

Source: src/Ltv/ValidationMaterial.php:80

Methods

__construct()

public __construct(
    ?Client $ocsp = null,
    ?Crl $crl = null,
    ?Certificate $certificate = null,
    ?Asn1 $asn1 = null
)

Parameters:

Throws:

  • Exception: If a default codec cannot be constructed.

Source: src/Ltv/ValidationMaterial.php:93

certificateCrlUrls()

Extract the CRL distribution point URLs from a certificate.

Returns an empty list when the certificate has no CRL distribution point or cannot be parsed (LTV collection is best-effort; see extensionMembers).

public certificateCrlUrls(string $certPem, callable|null $onSkip = null): list<string>

Parameters:

  • $certPem (string)
  • $onSkip (callable|null): Receives every URL the caller will not be given: the ones past MAX_URLS, and the ones whose scheme no HTTP transport can be handed.

Returns: list<string>

Source: src/Ltv/ValidationMaterial.php:194

certificateOcspUrls()

Extract the OCSP responder URLs from a certificate’s AIA extension.

Returns an empty list when the certificate has no AIA extension or cannot be parsed (LTV collection is best-effort; see extensionMembers).

public certificateOcspUrls(string $certPem, callable|null $onSkip = null): list<string>

Parameters:

  • $certPem (string)
  • $onSkip (callable|null): Receives every URL the caller will not be given: the ones past MAX_URLS, and the ones whose scheme no HTTP transport can be handed.

Returns: list<string>

Source: src/Ltv/ValidationMaterial.php:148

certificates()

Convert a list of PEM certificates to deduplicated DER strings.

Each entry is parsed as a certificate, not merely decoded.

public certificates(list<string> $certsPem): list<string>

Parameters:

  • $certsPem (list<string>)

Returns: list<string>

Throws:

  • Exception: If any entry is not a string, or is not one PEM certificate.

Source: src/Ltv/ValidationMaterial.php:116

fetchCrl()

Fetch CRLs from the given distribution point URLs.

Every CRL is validated against the certificate that issued it before it is kept, so the issuer is required.

public fetchCrl(
    list<string> $urls,
    callable $transport,
    string $issuerDer,
    string|null $subjectDer,
    int|null $now = null,
    callable|null $onSkip = null
): list<string>

Parameters:

  • $urls (list<string>)
  • $transport (callable): Receives (url) and returns the CRL bytes.
  • $issuerDer (string): DER of the issuing certificate.
  • $subjectDer (string|null): DER of the certificate the lists are fetched for, so a list that revokes it is reported rather than embedded, or null to skip the revocation lookup.
  • $now (int|null): Unix time the CRLs are checked against.
  • $onSkip (callable|null): Receives (source, url, reason, code) for every URL whose answer was discarded.

Returns: list<string>: Deduplicated, validated CRL bytes.

Throws:

Source: src/Ltv/ValidationMaterial.php:306

fetchOcsp()

Fetch OCSP responses for a certificate from the given responder URLs.

Every response is validated against the request before it is kept. A URL whose response fails validation is skipped, like an unreachable one.

public fetchOcsp(
    string $issuerDer,
    string $leafDer,
    list<string> $urls,
    callable $transport,
    int|null $now = null,
    callable|null $onSkip = null
): list<string>

Parameters:

  • $issuerDer (string)
  • $leafDer (string)
  • $urls (list<string>)
  • $transport (callable): Receives (url, DER request) and returns the DER response.
  • $now (int|null): Unix time the responses are checked against.
  • $onSkip (callable|null): Receives (source, url, reason, code) for every URL whose answer was discarded.

Returns: list<string>: Deduplicated, validated OCSP response bytes.

Throws:

  • Exception: If the OCSP request cannot be built, or a URL is not a string.

Source: src/Ltv/ValidationMaterial.php:256

reportNotAttempted()

Report URLs that were not tried.

public reportNotAttempted(
    string $source,
    list<string> $urls,
    string $reason,
    callable|null $onSkip
): void

Parameters:

  • $source (string)
  • $urls (list<string>)
  • $reason (string)
  • $onSkip (callable|null)

Throws:

Source: src/Ltv/ValidationMaterial.php:338