You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

签署PDF文件时如何为证书详情添加Timestamp属性

你现有代码的核心逻辑是正确的,只需要修正几个细节、完成必要配置,即可在签名中生成可被证书查看工具识别的Timestamp属性:

核心配置说明

  • 你要展示的Timestamp属性对应PKCS#7规范中的签名时间戳令牌(Signature TimeStamp Token),属于签名的未签名属性(Unsigned Attributes),你当前选用的OID PKCSObjectIdentifiers.id_aa_signatureTimeStampToken 完全符合标准要求
  • 确认TSA接口返回值合法:需要保证this.tsaClient.getTimeStampToken返回的字节数组是标准DER编码的完整TSP时间戳令牌结构,不能是仅提取出的时间字段值,否则无法被工具识别解析
  • 若该签名用于PDF场景,需额外将签名字典的SubFilter设置为adbe.pkcs7.detached或ETSI.CAdES.detached,这两类签名格式支持时间戳属性的展示
  • 最终导出的CMS签名结构需要携带完整的签名证书链,否则查看工具无法关联验证时间戳属性,不会在证书详情页展示对应Timestamp项

修正后的参考代码

(仅修正了易混淆的变量名,核心逻辑无需调整)

private SignerInformation signTimeStamp(SignerInformation signer) throws IOException, TSPException {
    AttributeTable unsignedAttributes = signer.getUnsignedAttributes();

    ASN1EncodableVector vector = new ASN1EncodableVector();
    if (unsignedAttributes != null) {
        vector = unsignedAttributes.toASN1EncodableVector();
    }

    // 确保此处返回标准DER编码的TimeStampToken完整结构
    byte[] token = this.tsaClient.getTimeStampToken(signer.getSignature());

    ASN1ObjectIdentifier oid = PKCSObjectIdentifiers.id_aa_signatureTimeStampToken;
    ASN1Encodable signatureTimeStamp = new Attribute(oid, new DERSet(ASN1Primitive.fromByteArray(token)));

    vector.add(signatureTimeStamp);
    // 修正变量名,明确是未签名属性集合,避免维护混淆
    Attributes newUnsignedAttributes = new Attributes(vector);
    return SignerInformation.replaceUnsignedAttributes(signer, new AttributeTable(newUnsignedAttributes));
}

内容的提问来源于stack exchange,提问作者Dinh Chu

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 21:24:06