Verifying a CMS timestamp with TElMessageVerifier

Posted: 03/19/2013 05:45:04
by Vsevolod Ievgiienko (Team)

There is a property .IgnoreBadSignature which defaults to true. Should I set that to false before calling .ParseCMS ?

This property triggers TSP server certificate validation if its set to 'false'.

Certificate validation of TElClientTSPInfo.Certificates probably works...

This property is used to retrieve certificates received from server. Note, that certificates are present only if they were requested using TSPClient.IncludeCertificates.
Posted: 03/19/2013 06:48:50
by Frank Munsberg (Standard support level)
OK, I tried setting the .IgnoreBadSignatures to false and ParseCMS still worked.
All of the timestamps do have certificates inside. This is most likely specified in our national "SigG" signature law.

For validation I'll have a look at the TElX509CertificateValidator later but being able to check the hashes on the fly is one big step forward already.
Without SBB the process was really really cumbersome.



