Client

RFC 3161 timestamp codec.

Namespace: Com\Tecnick\Pdf\Sign\Timestamp

final class Client

Source: src/Timestamp/Client.php:56

RFC 3161 timestamp codec. Builds a TimeStampReq for a signature, parses a TimeStampResp to extract the timestamp token, and maps digest algorithms to their OIDs. HTTP transport is injected into requestToken(), so the codec performs no network access and the host controls networking and SSRF protection.

A returned token is verified before it is embedded: its SignerInfo signature must check out against the TSA certificate the token carries, and its TSTInfo must answer the request that was sent, per RFC 3161 section 2.4.2. That means the same message imprint, the same policy when one was requested, the nonce echoed unchanged, and a genTime near the moment of the request.

The certificate that signed it must be a TSA certificate reserved for timestamping (RFC 3161 section 2.3), and must have been inside its validity period at the instant the token attests.

Constants

CLOCK_SKEW

Default clock skew tolerated between the token’s genTime and the moment of use, in seconds. Ltv\Crl reads the same value.

public const CLOCK_SKEW = \Com\Tecnick\Pdf\Sign\Ocsp\Client::CLOCK_SKEW

Source: src/Timestamp/Client.php:67

Methods

__construct()

public __construct(
    Config $config,
    ?Asn1 $asn1 = null,
    ?Certificate $certificate = null,
    ?SignedDataVerifier $verifier = null,
    int $clockSkew = \self::CLOCK_SKEW
)

Parameters:

Throws:

Source: src/Timestamp/Client.php:81

buildRequest()

Build an RFC 3161 TimeStampReq for the given signature bytes.

public buildRequest(string $signature): Request

Parameters:

  • $signature (string): Signature (or any bytes) to be timestamped.

Returns: Request: The DER request and the imprint and nonce a token must match.

Throws:

  • Exception: If encoding fails or a nonce cannot be generated.

Source: src/Timestamp/Client.php:113

hashAlgorithmOid()

Map a digest algorithm name to its OID.

public hashAlgorithmOid(string $algorithm): string

Parameters:

  • $algorithm (string)

Returns: string

Throws:

  • Exception: If the algorithm is not supported.

Source: src/Timestamp/Client.php:622

parseResponse()

Extract and validate the timestamp token of a DER-encoded TimeStampResp.

The status is checked first, then the token’s TSTInfo is matched against the request: the messageImprint must be the digest that was sent under the same algorithm, and the nonce must come back unchanged.

public parseResponse(string $response, Request $request, int|null $now = null): string

Parameters:

  • $response (string): DER-encoded timestamp response.
  • $request (Request): The request this response answers.
  • $now (int|null): Unix time the token’s genTime is checked against; defaults to the current time.

Returns: string: DER-encoded timestamp token (ContentInfo).

Throws:

  • Exception: If the response is empty, malformed, rejected, or does not match the request.

Source: src/Timestamp/Client.php:164

requestToken()

Build the request, submit it through the given transport, and validate the returned token.

public requestToken(string $signature, callable $transport, int|null $now = null): string

Parameters:

  • $signature (string): Signature bytes to timestamp.
  • $transport (callable): Receives the DER request string and must return the DER response string.
  • $now (int|null): Unix time the token’s genTime is checked against; defaults to the current time.

Returns: string

Throws:

  • Exception: If encoding, transport, or validation fails.

Source: src/Timestamp/Client.php:231

tokenCertificates()

Extract the certificates a timestamp token embeds.

The TSA certificate chain is validation material a PAdES B-LT document needs in its Document Security Store, alongside the signer’s own chain. An entry that is not a certificate is dropped by Cms\Certificate::fromSignedData().

public tokenCertificates(string $tokenDer): list<string>

Parameters:

  • $tokenDer (string)

Returns: list<string>: DER certificates, empty when the token embeds none.

Throws:

Source: src/Timestamp/Client.php:255