Table of contents
Namespace: Com\Tecnick\Pdf\Sign\Ocsp
final class Client
Source: src/Ocsp/Client.php:53
RFC 6960 OCSP codec. build() assembles an OCSPRequest with a SHA-1 CertID over the issuer’s subject Name and public key and the target’s serial number. parseResponse() applies the RFC 6960 section 3.2 acceptance rules before a response is used: successful status, a basic response type, a signature that verifies against a responder the issuer authorised and that is itself inside its validity period, a CertID matching the request, a good certificate status, and a validity interval that covers the moment of use.
Rule 5, that thisUpdate is sufficiently recent, is applied whether or not the response carries a nextUpdate: a response is accepted only while it is younger than $maxAge.
HTTP transport is injected into fetch(), so the codec performs no network access and the host controls networking and SSRF protection.
Constants
CLOCK_SKEW
Default clock skew tolerated when checking the response validity interval, in seconds. Timestamp\Client and Ltv\Crl read the same value.
public const CLOCK_SKEW = 300
Source: src/Ocsp/Client.php:102
DEFAULT_MAX_AGE
Default age limit applied to thisUpdate, in seconds.
public const DEFAULT_MAX_AGE = 604800
Source: src/Ocsp/Client.php:107
MAX_RESPONDER_CERTIFICATES
Most certificates accepted in the certs [0] bag of a response.
Read from Cms\Certificate, as Signer::MAX_PATH_CERTIFICATES is, so every unauthenticated certificate bag is held to the same bound.
public const MAX_RESPONDER_CERTIFICATES = \Com\Tecnick\Pdf\Sign\Cms\Certificate::MAX_EMBEDDED_CERTIFICATES
Source: src/Ocsp/Client.php:115
Methods
__construct()
public __construct(
?Asn1 $asn1 = null,
?Certificate $certificate = null,
?SignatureVerifier $verifier = null,
int $maxAge = \self::DEFAULT_MAX_AGE,
int $clockSkew = \self::CLOCK_SKEW
)
Parameters:
$asn1(?Asn1)$certificate(?Certificate)$verifier(?SignatureVerifier)$maxAge(int): Age limit applied to thisUpdate, in seconds. Zero disables the bound.$clockSkew(int): Skew tolerated between the response validity interval and the moment of use, in seconds.
Throws:
- Exception: If the age limit or the skew is negative.
Source: src/Ocsp/Client.php:131
build()
Build an RFC 6960 OCSPRequest for a single certificate.
No nonce extension is sent: RFC 6960 section 4.4.1 makes it optional and many responders pre-sign and reject it. The response age is bounded by $maxAge instead.
public build(string $issuerDer, string $leafDer): Request
Parameters:
$issuerDer(string): DER of the issuing certificate.$leafDer(string): DER of the certificate whose status is queried.
Returns: Request: The DER request and the CertID a response has to quote back.
Throws:
- Exception: If either certificate cannot be parsed or encoded, or the issuer did not issue the leaf.
Source: src/Ocsp/Client.php:166
fetch()
Build the request, submit it through the transport, and validate the response.
public fetch(
string $url,
string $issuerDer,
string $leafDer,
callable $transport,
int|null $now = null
): string
Parameters:
$url(string): OCSP responder URL.$issuerDer(string): DER of the issuing certificate.$leafDer(string): DER of the target certificate.$transport(callable): Receives (url, DER request) and must return the DER response string.$now(int|null): Unix time the validity interval is checked against; defaults to the current time.
Returns: string: The DER response bytes, once accepted.
Throws:
- Exception: If building, transport, or validation fails.
Source: src/Ocsp/Client.php:232
parseResponse()
Validate a DER OCSPResponse against the request it answers.
Applies the RFC 6960 section 3.2 acceptance rules. A response that fails any of them is rejected rather than returned.
public parseResponse(string $response, Request $request, int|null $now = null): string
Parameters:
$response(string): DER-encoded OCSPResponse.$request(Request): The request this response answers.$now(int|null): Unix time the validity interval is checked against; defaults to the current time.
Returns: string: The response bytes unchanged, once accepted.
Throws:
- RevokedException: If the responder states that the certificate is revoked.
- Exception: If the response is malformed, unsuccessful, unmatched, not good, or outside its validity interval.
Source: src/Ocsp/Client.php:267