Client

RFC 6960 OCSP codec.

Namespace: Com\Tecnick\Pdf\Sign\Ocsp

final class Client

Source: src/Ocsp/Client.php:53

RFC 6960 OCSP codec. build() assembles an OCSPRequest with a SHA-1 CertID over the issuer’s subject Name and public key and the target’s serial number. parseResponse() applies the RFC 6960 section 3.2 acceptance rules before a response is used: successful status, a basic response type, a signature that verifies against a responder the issuer authorised and that is itself inside its validity period, a CertID matching the request, a good certificate status, and a validity interval that covers the moment of use.

Rule 5, that thisUpdate is sufficiently recent, is applied whether or not the response carries a nextUpdate: a response is accepted only while it is younger than $maxAge.

HTTP transport is injected into fetch(), so the codec performs no network access and the host controls networking and SSRF protection.

Constants

CLOCK_SKEW

Default clock skew tolerated when checking the response validity interval, in seconds. Timestamp\Client and Ltv\Crl read the same value.

public const CLOCK_SKEW = 300

Source: src/Ocsp/Client.php:102

DEFAULT_MAX_AGE

Default age limit applied to thisUpdate, in seconds.

public const DEFAULT_MAX_AGE = 604800

Source: src/Ocsp/Client.php:107

MAX_RESPONDER_CERTIFICATES

Most certificates accepted in the certs [0] bag of a response.

Read from Cms\Certificate, as Signer::MAX_PATH_CERTIFICATES is, so every unauthenticated certificate bag is held to the same bound.

public const MAX_RESPONDER_CERTIFICATES = \Com\Tecnick\Pdf\Sign\Cms\Certificate::MAX_EMBEDDED_CERTIFICATES

Source: src/Ocsp/Client.php:115

Methods

__construct()

public __construct(
    ?Asn1 $asn1 = null,
    ?Certificate $certificate = null,
    ?SignatureVerifier $verifier = null,
    int $maxAge = \self::DEFAULT_MAX_AGE,
    int $clockSkew = \self::CLOCK_SKEW
)

Parameters:

  • $asn1 (?Asn1)
  • $certificate (?Certificate)
  • $verifier (?SignatureVerifier)
  • $maxAge (int): Age limit applied to thisUpdate, in seconds. Zero disables the bound.
  • $clockSkew (int): Skew tolerated between the response validity interval and the moment of use, in seconds.

Throws:

  • Exception: If the age limit or the skew is negative.

Source: src/Ocsp/Client.php:131

build()

Build an RFC 6960 OCSPRequest for a single certificate.

No nonce extension is sent: RFC 6960 section 4.4.1 makes it optional and many responders pre-sign and reject it. The response age is bounded by $maxAge instead.

public build(string $issuerDer, string $leafDer): Request

Parameters:

  • $issuerDer (string): DER of the issuing certificate.
  • $leafDer (string): DER of the certificate whose status is queried.

Returns: Request: The DER request and the CertID a response has to quote back.

Throws:

  • Exception: If either certificate cannot be parsed or encoded, or the issuer did not issue the leaf.

Source: src/Ocsp/Client.php:166

fetch()

Build the request, submit it through the transport, and validate the response.

public fetch(
    string $url,
    string $issuerDer,
    string $leafDer,
    callable $transport,
    int|null $now = null
): string

Parameters:

  • $url (string): OCSP responder URL.
  • $issuerDer (string): DER of the issuing certificate.
  • $leafDer (string): DER of the target certificate.
  • $transport (callable): Receives (url, DER request) and must return the DER response string.
  • $now (int|null): Unix time the validity interval is checked against; defaults to the current time.

Returns: string: The DER response bytes, once accepted.

Throws:

  • Exception: If building, transport, or validation fails.

Source: src/Ocsp/Client.php:232

parseResponse()

Validate a DER OCSPResponse against the request it answers.

Applies the RFC 6960 section 3.2 acceptance rules. A response that fails any of them is rejected rather than returned.

public parseResponse(string $response, Request $request, int|null $now = null): string

Parameters:

  • $response (string): DER-encoded OCSPResponse.
  • $request (Request): The request this response answers.
  • $now (int|null): Unix time the validity interval is checked against; defaults to the current time.

Returns: string: The response bytes unchanged, once accepted.

Throws:

  • RevokedException: If the responder states that the certificate is revoked.
  • Exception: If the response is malformed, unsuccessful, unmatched, not good, or outside its validity interval.

Source: src/Ocsp/Client.php:267