OPENSSL-TS(1ssl) OpenSSL OPENSSL-TS(1ssl) openssl-ts - openssl ts -help openssl ts -query [-config _] [-data _] [-digest _] [-] [-tspolicy _] [-no_nonce] [-cert] [-in request.tsq] [-out request.tsq] [-text] [-rand ] [-writerand ] [-provider ] [-provider-path ] [-provparam [name:]key=value] [-propquery propq] openssl ts -reply [-config _] [-section _tsa] [-queryfile request.tsq] [-passin __] [-signer tsa_cert.pem] [-inkey _|_] [-] [-chain certs_file.pem] [-tspolicy _] [-in response.tsr] [-token_in] [-out response.tsr] [-token_out] [-text] [-engine id] [-provider ] [-provider-path ] [-provparam [name:]key=value] [-propquery propq] openssl ts -verify [-data _] [-digest _] [-queryfile request.tsq] [-in response.tsr] [-token_in] [-untrusted |_] [-CAfile ] [-CApath ] [-CAstore _] [-allow_proxy_certs] [-attime _] [-no_check_time] [-check_ss_sig] [-crl_check] [-crl_check_all] [-explicit_policy] [-extended_crl] [-ignore_critical] [-inhibit_any] [-inhibit_map] [-partial_chain] [-policy ] [-policy_check] [-policy_print] [-purpose ] [-suiteB_128] [-suiteB_128_only] [-suiteB_192] [-trusted_first] [-no_alt_chains] [-use_deltas] [-auth_level ] [-verify_depth ] [-verify_email ] [-verify_hostname _] [-verify_ip ip] [-verify_name ] [-x509_strict] [-issuer_checks] [-provider ] [-provider-path ] [-provparam [name:]key=value] [-propquery propq] (TSA) RFC 3161 ( TSP). TSA PKI . : 1. TSA (hash) TSA. 2. TSA (timestamp token) . TSA . 3. TSA . TSA. DER TSA . : . / HTTP TCP RFC 3161. ftp . -help . -query . " ". -reply . " ". -verify . " ". -query : -config _ . " " openssl(1). -data _ . stdin -data -digest. () -digest _ . ( 1A:F6:01:... 1AF601...). . () - . openssl-dgst(1). SHA-256. () -tspolicy _ TSA . OID OID . TSA . () -no_nonce (nonce) . nonce 64 . nonce . () -cert TSA . () -in request.tsq DER . . () -out request.tsq . stdout. () -text DER. () -rand -writerand " " openssl(1) . (TimeStampResp) (ContentInfo) . -reply / . -token_out (TimeStampResp) (ContentInfo). -config _ . " " openssl(1). " " . -section _tsa . TSA " " . () -queryfile request.tsq DER. () -passin __ TSA. openssl(1). () -signer tsa_cert.pem TSA PEM. TSA : timeStamping. (critical) . signer_cert . () -inkey _|_ TSA PEM. signer_key . () - . signer_digest . ( ) -chain certs_file.pem PEM -cert . . -reply . () -tspolicy _ TSA . OID . default_policy . () -in response.tsr ( -token_in ) DER . . 'granted' () . () -token_in -in DER (ContentInfo) (TimeStampResp). () -out response.tsr . ( -text -token_out). (stdout) . () -token_out (ContentInfo) (TimeStampResp). () -text DER. () -engine id " " openssl(1). . -provider name -provider-path path -provparam [name:]key=value -propquery propq " " openssl(1) provider(7) property(7). -verify . -verify . -data _ file_to_hash. (hashed) . -digest -queryfile . () -digest _ . . -data -queryfile . () -queryfile request.tsq DER. -data -digest . () -in response.tsr DER. () -token_in -in DER (ContentInfo) (TimeStampResp). () -untrusted files|uris TSA. TSA CA . () / . . -CAfile file -CApath dir -CAstore uri " " openssl-verification-options(1) . -CAfile -CApath -CAstore. -allow_proxy_certs -attime -no_check_time -check_ss_sig -crl_check -crl_check_all -explicit_policy -extended_crl -ignore_critical -inhibit_any -inhibit_map -no_alt_chains -partial_chain -policy -policy_check -policy_print -purpose -suiteB_128 -suiteB_128_only -suiteB_192 -trusted_first -use_deltas -auth_level -verify_depth -verify_email -verify_hostname -verify_ip -verify_name -x509_strict -issuer_checks . " " openssl-verification-options(1) . . -query -reply . config(5) . -query OID . -reply . . tsa default_tsa -reply. -section. () oid_file (OBJECT IDENTIFIERS) . . () oid_section . = . . () RANDFILE 256 . (: RANDFILE "HISTORY". serial . 1 . 1. () crypto_device OpenSSL . built-in OpenSSL ( chil NCipher HSM). () signer_cert TSA PEM. -signer. () certs PEM . -chain. () signer_key TSA PEM. -inkey. () signer_digest . -digest. ( ) default_policy . -tspolicy. () other_policies TSA . () digests TSA. . () accuracy TSA . secs:1 millisecs:500 microsecs:100. . () clock_precision_digits . . UNIX. 6 0. () ordering yes TSA . no. () tsa_name yes TSA TSA . no. () ess_cert_id_chain SignedData TSA ( RFC 2634 ). no SigningCertificate . yes certs -chain -chain certs. no. () ess_cert_id_alg (hash) TSA. sha256. () OPENSSL_CONF openssl/apps/openssl.cnf . design1.txt SHA-256 nonce : openssl ts -query -data design1.txt -no_nonce \ -out design1.tsq : openssl ts -query -digest b7e5d3f93198b38379852f2c04e78d73abdd0f4b \ -no_nonce -out design1.tsq : openssl ts -query -in design1.tsq -text SHA-512 design2.txt nonce ( tsa_policy1 OID ): openssl ts -query -data design2.txt -sha512 \ -tspolicy tsa_policy1 -cert -out design2.tsq (TSA) timeStamping . extendedKeyUsage = critical,timeStamping openssl-req(1) openssl-ca(1) openssl-x509(1) . cacert.pem (CA) tsacert.pem cacert.pem tsakey.pem (TSA). : openssl ts -reply -queryfile design1.tsq -inkey tsakey.pem \ -signer tsacert.pem -out design1.tsr : openssl ts -reply -queryfile design1.tsq -out design1.tsr : openssl ts -reply -in design1.tsr -text : openssl ts -reply -queryfile design1.tsq -out design1_token.der -token_out : openssl ts -reply -in design1_token.der -token_in -text -token_out : openssl ts -reply -in design1.tsr -out design1_token.der -token_out 'granted' () : openssl ts -reply -in design1_token.der -token_in -out design1.tsr : openssl ts -verify -queryfile design1.tsq -in design1.tsr \ -CAfile cacert.pem -untrusted tsacert.pem : openssl ts -verify -queryfile design2.tsq -in design2.tsr \ -CAfile cacert.pem : openssl ts -verify -data design2.txt -in design2.tsr \ -CAfile cacert.pem : openssl ts -verify -digest b7e5d3f93198b38379852f2c04e78d73abdd0f4b \ -in design2.tsr -CAfile cacert.pem 'test' . o SMTP (TSA) procmail(1) perl(1). HTTP apache . HTTP tsget(1). TCP/IP . o . openssl(1) . apache . o FIXME . o . o ( test/testtsa). OpenSSL 1.1.1 (CSPRNG) . RANDFILE . . -engine OpenSSL 3.0. openssl(1), tsget(1), openssl-req(1), openssl-x509(1), openssl-ca(1), openssl-genrsa(1), config(5), ossl_store-file(7) 2006-2025 OpenSSL. . Apache 2.0 ( ""). . LICENSE . 3 . . : . 3.6.2 7 2026 OPENSSL-TS(1ssl)