Attila,

aszomor wrote
> Which date we used in PdfPKCS7.VerifyCertificates for  PAdES-LTV
> TimeStampDate or the latest SignDate from sugnatures ?

Are you asking which date you _should_ use as parameter for
VerifyCertificates?

If the validation model for the PKIs in question is 'shell', you either have
to use the current date or at least (if by verifying backwards the
timestamps as recommended in the PAdES specification you know you can trust
them) a date not older than that of the earliest document time stamp added
after the signature in question.

If the validation model is 'chain', you have to tweak that method to for
each certificate use the date of its usage (signing of document or of child
certificate in the certificate path) as far as you can trust it. Depending
on the cirsumstances (e.g. legal requirements), 'trust' may or may not
require timestamps.

If the circumstances require you to not only check for revocation but also
for existence, the dates you can use may even be more restricted.

Regards,   Michael

--
View this message in context: 
http://itext-general.2136553.n4.nabble.com/TSA-sha-2-RSA-algoritm-tp4498440p4503040.html
Sent from the iText - General mailing list archive at Nabble.com.

------------------------------------------------------------------------------
This SF email is sponsosred by:
Try Windows Azure free for 90 days Click Here 
http://p.sf.net/sfu/sfd2d-msazure
_______________________________________________
iText-questions mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/itext-questions

iText(R) is a registered trademark of 1T3XT BVBA.
Many questions posted to this list can (and will) be answered with a reference 
to the iText book: http://www.itextpdf.com/book/
Please check the keywords list before you ask for examples: 
http://itextpdf.com/themes/keywords.php

Reply via email to