Config

Immutable RFC 3161 Time Stamping Authority (TSA) configuration.

Namespace: Com\Tecnick\Pdf\Sign\Timestamp

final class Config

Source: src/Timestamp/Config.php:41

Immutable RFC 3161 Time Stamping Authority (TSA) configuration. The codec fields (hash algorithm, policy OID, nonce) drive request construction; the transport fields (host, timeout, credentials, CA file, peer verification) are consumed by the caller-provided transport.

Constants

HASH_ALGORITHMS

Supported TSA message-imprint digest algorithms.

Derived from DigestAlgorithm, which is the closed set the constructor enforces and which the CMS side shares.

public const HASH_ALGORITHMS = [\Com\Tecnick\Pdf\Sign\DigestAlgorithm::Sha256->value, \Com\Tecnick\Pdf\Sign\DigestAlgorithm::Sha384->value, \Com\Tecnick\Pdf\Sign\DigestAlgorithm::Sha512->value]

Source: src/Timestamp/Config.php:51

URL_PATTERN

The shape a URL this library hands to a host transport has to have.

Anchored at both ends, so no control character reaches the host’s transport. The end anchor is \z, not $, which PCRE matches before a final newline. The authority is held to the same character class as the path.

It gates the TSA endpoint a host supplies and the OCSP and CRL URLs Ltv\ValidationMaterial reads out of a certificate extension.

public const URL_PATTERN = '~^https?://[^\x00-\x20\x7F/?#]+(?:[/?#][^\x00-\x20\x7F]*)?\z~i'

Source: src/Timestamp/Config.php:67

Properties

$cert

public $cert = ''

Source: src/Timestamp/Config.php:102

$hashAlgorithm

Selected message-imprint digest algorithm (one of the DigestAlgorithm backing values).

public string $hashAlgorithm

Source: src/Timestamp/Config.php:73

$host

public $host

Source: src/Timestamp/Config.php:93

$nonceEnabled

public $nonceEnabled = true

Source: src/Timestamp/Config.php:96

$password

public $password = ''

Source: src/Timestamp/Config.php:100

$policyOid

public $policyOid = ''

Source: src/Timestamp/Config.php:95

$timeout

public $timeout = 5

Source: src/Timestamp/Config.php:97

$username

public $username = ''

Source: src/Timestamp/Config.php:99

$verifyPeer

public $verifyPeer = true

Source: src/Timestamp/Config.php:98

Methods

__construct()

The codec reads hashAlgorithm, policyOid, and nonceEnabled. The remaining entries describe the transport, which this library does not perform: the host receives them here and has to apply them to its own HTTP client.

public __construct(
    string $host,
    string|DigestAlgorithm $hashAlgorithm = 'sha256',
    string $policyOid = '',
    bool $nonceEnabled = true,
    int $timeout = 5,
    bool $verifyPeer = true,
    string $username = '',
    string $password = '',
    string $cert = ''
)

Parameters:

  • $host (string): TSA endpoint URL (http or https).
  • $hashAlgorithm (string|DigestAlgorithm): Message-imprint digest name or enum case.
  • $policyOid (string): Optional requested TSA policy OID (dotted form).
  • $nonceEnabled (bool): Add a random nonce to the request.
  • $timeout (int): Transport timeout in seconds (>= 1), for the host.
  • $verifyPeer (bool): Validate the TSA TLS certificate, for the host.
  • $username (string): Optional HTTP basic-auth username, for the host.
  • $password (string): Optional HTTP basic-auth password, for the host.
  • $cert (string): Optional CA bundle path, for the host.

Throws:

Source: src/Timestamp/Config.php:92

__debugInfo()

Keep the basic-auth password out of var_dump() and print_r() output.

public __debugInfo(): array<string,mixed>

Returns: array<string,mixed>

Source: src/Timestamp/Config.php:141