Sample code for 30+ languages & platforms
Delphi ActiveX Requires Chilkat v11.0.0+

RFC3161 Timestamp Client - Fetch from Timestamp Authority (TSA) and Verify

See more HTTP Examples

Sends an RFC 3161 timestamp request to a TSA (Timestamp Authority) server and validates the timestamp token response.

Chilkat Delphi ActiveX Downloads

Delphi ActiveX
var
success: Integer;
crypt: TChilkatCrypt2;
base64Hash: WideString;
http: TChilkatHttp;
requestToken: TChilkatBinData;
optionalPolicyOid: WideString;
addNonce: Integer;
requestTsaCert: Integer;
tsaUrl: WideString;
resp: TChilkatHttpResponse;
timestampReply: TChilkatBinData;
tsaCert: TChilkatCert;
pkiStatus: Integer;
json: TChilkatJsonObject;
signingTime: TDtObj;
authAttrSigningTimeUtctime: TDtObj;
strVal: WideString;
certSerialNumber: WideString;
certIssuerCN: WideString;
certDigestAlgOid: WideString;
certDigestAlgName: WideString;
contentType: WideString;
messageDigest: WideString;
signingAlgOid: WideString;
signingAlgName: WideString;
authAttrContentTypeName: WideString;
authAttrContentTypeOid: WideString;
authAttrSigningTimeName: WideString;
authAttrSigningCertificateName: WideString;
authAttrSigningCertificateDer: WideString;
authAttrMessageDigestName: WideString;
authAttrMessageDigestDigest: WideString;
timestampReplyPkiStatusValue: Integer;
timestampReplyPkiStatusMeaning: WideString;
i: Integer;
count_i: Integer;

begin
success := 0;

//  This requires the Chilkat API to have been previously unlocked.
//  See Global Unlock Sample for sample code.

//  First sha-256 hash the data that is to be timestamped.
//  In this example, the data is the string "Hello World"

crypt := TChilkatCrypt2.Create(Self);
crypt.HashAlgorithm := 'sha256';
crypt.EncodingMode := 'base64';
base64Hash := crypt.HashStringENC('Hello World');

http := TChilkatHttp.Create(Self);

requestToken := TChilkatBinData.Create(Self);
optionalPolicyOid := '';
addNonce := 0;
requestTsaCert := 1;

//  Create a time-stamp request token
success := http.CreateTimestampRequest('sha256',base64Hash,optionalPolicyOid,addNonce,requestTsaCert,requestToken.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(http.LastErrorText);
    Exit;
  end;

//  Send the time-stamp request token to the TSA.
//  This is the equivalent of the following CURL command:
//  curl -H "Content-Type: application/timestamp-query" --data-binary '@file.tsq' https://freetsa.org/tsr > file.tsr
tsaUrl := 'https://freetsa.org/tsr';
//  Another timestamp server you could try is: http://timestamp.digicert.com
tsaUrl := 'http://timestamp.digicert.com';
resp := TChilkatHttpResponse.Create(Self);
success := http.HttpBd('POST',tsaUrl,requestToken.ControlInterface,'application/timestamp-query',resp.ControlInterface);
if (success = 0) then
  begin
    Memo1.Lines.Add(http.LastErrorText);
    Exit;
  end;

//  Get the timestamp reply from the HTTP response object.
timestampReply := TChilkatBinData.Create(Self);
resp.GetBodyBd(timestampReply.ControlInterface);

//  Show the base64 encoded timestamp reply.
Memo1.Lines.Add(timestampReply.GetEncoded('base64'));

//  Let's verify the timestamp reply against the TSA's cert, which we've previously downloaded.
//  See https://freetsa.org/index_en.php
tsaCert := TChilkatCert.Create(Self);
success := tsaCert.LoadFromFile('qa_data/certs/freetsa.org.cer');
if (success = 0) then
  begin
    Memo1.Lines.Add(tsaCert.LastErrorText);
    Exit;
  end;

//  The VerifyTimestampReply method will return one of the following values:
//  -1:  The timestampReply does not contain a valid timestamp reply.
//  -2: The  timestampReply is a valid timestamp reply, but failed verification using the public key of the tsaCert.
//  0:  Granted and verified.
//  1: Granted and verified, with mods (see RFC 3161)
//  2: Rejected.
//  3: Waiting.
//  4: Revocation Warning
//  5: Revocation Notification
pkiStatus := http.VerifyTimestampReply(timestampReply.ControlInterface,tsaCert.ControlInterface);
if (pkiStatus < 0) then
  begin
    Memo1.Lines.Add(http.LastErrorText);
    Exit;
  end;

Memo1.Lines.Add('pkiStatus = ' + IntToStr(pkiStatus));

json := TChilkatJsonObject.Create(Self);
http.GetLastJsonData(json.ControlInterface);

json.EmitCompact := 0;
Memo1.Lines.Add(json.Emit());

//  The JSON looks like the following.

//  Use this online tool to generate parsing code from sample JSON: 
//  Generate Parsing Code from JSON

//  {
//    "timestampReply": {
//      "pkiStatus": {
//        "value": 0,
//        "meaning": "granted"
//      }
//    },
//    "pkcs7": {
//      "verify": {
//        "digestAlgorithms": [
//          "sha256"
//        ],
//        "signerInfo": [
//          {
//            "cert": {
//              "serialNumber": "04CD3F8568AE76C61BB0FE7160CCA76D",
//              "issuerCN": "DigiCert SHA2 Assured ID Timestamping CA",
//              "digestAlgOid": "2.16.840.1.101.3.4.2.1",
//              "digestAlgName": "SHA256"
//            },
//            "contentType": "1.2.840.113549.1.9.16.1.4",
//            "signingTime": "200405023019Z",
//            "messageDigest": "f14zOsdnN9vyyV3HjjBiLzNDi1PF28hAFMODxNkNRZs=",
//            "signingAlgOid": "1.2.840.113549.1.1.1",
//            "signingAlgName": "RSA-PKCSV-1_5",
//            "authAttr": {
//              "1.2.840.113549.1.9.3": {
//                "name": "contentType",
//                "oid": "1.2.840.113549.1.9.16.1.4"
//              },
//              "1.2.840.113549.1.9.5": {
//                "name": "signingTime",
//                "utctime": "200405023019Z"
//              },
//              "1.2.840.113549.1.9.16.2.12": {
//                "name": "signingCertificate",
//                "der": "MBowGDAWBBQDJb1QXtqWMC3CL0+gHkwovig0xQ=="
//              },
//              "1.2.840.113549.1.9.4": {
//                "name": "messageDigest",
//                "digest": "f14zOsdnN9vyyV3HjjBiLzNDi1PF28hAFMODxNkNRZs="
//              }
//            }
//          }
//        ]
//      }
//    }
//  }

signingTime := TDtObj.Create(Self);
authAttrSigningTimeUtctime := TDtObj.Create(Self);

timestampReplyPkiStatusValue := json.IntOf('timestampReply.pkiStatus.value');
timestampReplyPkiStatusMeaning := json.StringOf('timestampReply.pkiStatus.meaning');
i := 0;
count_i := json.SizeOfArray('pkcs7.verify.digestAlgorithms');
while i < count_i do
  begin
    json.I := i;
    strVal := json.StringOf('pkcs7.verify.digestAlgorithms[i]');
    i := i + 1;
  end;

i := 0;
count_i := json.SizeOfArray('pkcs7.verify.signerInfo');
while i < count_i do
  begin
    json.I := i;
    certSerialNumber := json.StringOf('pkcs7.verify.signerInfo[i].cert.serialNumber');
    certIssuerCN := json.StringOf('pkcs7.verify.signerInfo[i].cert.issuerCN');
    certDigestAlgOid := json.StringOf('pkcs7.verify.signerInfo[i].cert.digestAlgOid');
    certDigestAlgName := json.StringOf('pkcs7.verify.signerInfo[i].cert.digestAlgName');
    contentType := json.StringOf('pkcs7.verify.signerInfo[i].contentType');
    json.DtOf('pkcs7.verify.signerInfo[i].signingTime',0,signingTime.ControlInterface);
    messageDigest := json.StringOf('pkcs7.verify.signerInfo[i].messageDigest');
    signingAlgOid := json.StringOf('pkcs7.verify.signerInfo[i].signingAlgOid');
    signingAlgName := json.StringOf('pkcs7.verify.signerInfo[i].signingAlgName');
    authAttrContentTypeName := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.3".name');
    authAttrContentTypeOid := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.3".oid');
    authAttrSigningTimeName := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.5".name');
    json.DtOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.5".utctime',0,authAttrSigningTimeUtctime.ControlInterface);
    authAttrSigningCertificateName := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.16.2.12".name');
    authAttrSigningCertificateDer := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.16.2.12".der');
    authAttrMessageDigestName := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.4".name');
    authAttrMessageDigestDigest := json.StringOf('pkcs7.verify.signerInfo[i].authAttr."1.2.840.113549.1.9.4".digest');
    i := i + 1;
  end;