Table of contents
Namespace: Com\Tecnick\Pdf\Sign\Timestamp
final class Client
Source: src/Timestamp/Client.php:56
RFC 3161 timestamp codec. Builds a TimeStampReq for a signature, parses a TimeStampResp to extract the timestamp token, and maps digest algorithms to their OIDs. HTTP transport is injected into requestToken(), so the codec performs no network access and the host controls networking and SSRF protection.
A returned token is verified before it is embedded: its SignerInfo signature must check out against the TSA certificate the token carries, and its TSTInfo must answer the request that was sent, per RFC 3161 section 2.4.2. That means the same message imprint, the same policy when one was requested, the nonce echoed unchanged, and a genTime near the moment of the request.
The certificate that signed it must be a TSA certificate reserved for timestamping (RFC 3161 section 2.3), and must have been inside its validity period at the instant the token attests.
Constants
CLOCK_SKEW
Default clock skew tolerated between the token’s genTime and the moment of use, in seconds. Ltv\Crl reads the same value.
public const CLOCK_SKEW = \Com\Tecnick\Pdf\Sign\Ocsp\Client::CLOCK_SKEW
Source: src/Timestamp/Client.php:67
Methods
__construct()
public __construct(
Config $config,
?Asn1 $asn1 = null,
?Certificate $certificate = null,
?SignedDataVerifier $verifier = null,
int $clockSkew = \self::CLOCK_SKEW
)
Parameters:
$config(Config)$asn1(?Asn1)$certificate(?Certificate)$verifier(?SignedDataVerifier)$clockSkew(int): Skew tolerated between the token’s genTime and the moment of the request, in seconds.
Throws:
- Exception: If the skew is negative.
Source: src/Timestamp/Client.php:81
buildRequest()
Build an RFC 3161 TimeStampReq for the given signature bytes.
public buildRequest(string $signature): Request
Parameters:
$signature(string): Signature (or any bytes) to be timestamped.
Returns: Request: The DER request and the imprint and nonce a token must match.
Throws:
- Exception: If encoding fails or a nonce cannot be generated.
Source: src/Timestamp/Client.php:113
hashAlgorithmOid()
Map a digest algorithm name to its OID.
public hashAlgorithmOid(string $algorithm): string
Parameters:
$algorithm(string)
Returns: string
Throws:
- Exception: If the algorithm is not supported.
Source: src/Timestamp/Client.php:622
parseResponse()
Extract and validate the timestamp token of a DER-encoded TimeStampResp.
The status is checked first, then the token’s TSTInfo is matched against the request: the messageImprint must be the digest that was sent under the same algorithm, and the nonce must come back unchanged.
public parseResponse(string $response, Request $request, int|null $now = null): string
Parameters:
$response(string): DER-encoded timestamp response.$request(Request): The request this response answers.$now(int|null): Unix time the token’s genTime is checked against; defaults to the current time.
Returns: string: DER-encoded timestamp token (ContentInfo).
Throws:
- Exception: If the response is empty, malformed, rejected, or does not match the request.
Source: src/Timestamp/Client.php:164
requestToken()
Build the request, submit it through the given transport, and validate the returned token.
public requestToken(string $signature, callable $transport, int|null $now = null): string
Parameters:
$signature(string): Signature bytes to timestamp.$transport(callable): Receives the DER request string and must return the DER response string.$now(int|null): Unix time the token’s genTime is checked against; defaults to the current time.
Returns: string
Throws:
- Exception: If encoding, transport, or validation fails.
Source: src/Timestamp/Client.php:231
tokenCertificates()
Extract the certificates a timestamp token embeds.
The TSA certificate chain is validation material a PAdES B-LT document needs in its Document Security Store, alongside the signer’s own chain. An entry that is not a certificate is dropped by Cms\Certificate::fromSignedData().
public tokenCertificates(string $tokenDer): list<string>
Parameters:
$tokenDer(string)
Returns: list<string>: DER certificates, empty when the token embeds none.
Throws:
- Exception: If the token cannot be parsed.
Source: src/Timestamp/Client.php:255