setasign\SetaPDF2\Signer

DocumentSecurityStore Class representing a "Document Security Store" in a PDF document.

File: /SetaPDF v2/Signer/DocumentSecurityStore.php
Old class name (alias): \SetaPDF_Signer_DocumentSecurityStore

Class hierarchy

Summary

Properties

$_document

$_optimizeOcspResponses

Defines whether OCSP responses should be embedded including their optional certificates (false) or not (true).


Methods

__construct()

The constructor.

Parameters
$document: \setasign\SetaPDF2\Core\Document
 

_addStream()

Adds a stream to the DSS.

Parameters
$type: string

The type/key to which the data should be added.

$data: string
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

_ensureArrayByType()

_getStreams()

protected DocumentSecurityStore::_getStreams (
string $type
): array

Get a stream by its type from the DSS dictionary.

Parameters
$type: string
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

_getVriDictionary()

protected DocumentSecurityStore::_getVriDictionary (
string $vriKey,
bool $create = false
): false|\setasign\SetaPDF2\Core\Type\PdfDictionary
Parameters
$vriKey: string
 
$create: bool
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

addCRLs()

public DocumentSecurityStore::addCRLs (
string[]|X509\Crl[] $crls
): void

Add CRLs to the CRLs entry in the DSS dictionary.

Parameters
$crls: string[]|X509\Crl[]
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

addCertificates()

public DocumentSecurityStore::addCertificates (
string[]|X509\Certificate[] $certificates
): void

Add certificates to the Certs entry in the DSS dictionary.

Parameters
$certificates: string[]|X509\Certificate[]
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

addForeignStreamArtifact()

This method allows you to add foreign stream artifacts to the DSS dictionary.

This method can be used to e.g. add individual artifacts such as defined by the Brazil ICP: PBAD_PolicyArtifacts, PBAD_LpaArtifacts or PBAD_LpaSignatures.

Parameters
$type: string

The foreigh type name

$data: string

The stream data

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

addForeignStreamArtifactValidationRelatedInfo()

Add foreign stream artifacts to a VRI dictionary.

Parameters
$vriKey: string

The VRI key

$type: string

The foreigh type name

$data: string

The stream data

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

addOCSPs()

public DocumentSecurityStore::addOCSPs (
array<string|Ocsp\Response> $ocsps
): void

Add OCSP responses to the OCSPs entry in the DSS dictionary.

Parameters
$ocsps: array<string|Ocsp\Response>
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

Throws Exception

addValidationRelatedInfo()

Add validation related information to the VRI dictionary of the DSS dictionary.

Parameters
$key: string

The sha1 digest of the signature.

$crls: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|X509\Crl>

An array of strings, X509\Crl instances or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the CRLs.

$ocsps: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|Ocsp\Response>

An array of strings, Ocsp\Response instances or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the OCSPs.

$certs: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|X509\Certificate>

An array of strings, X509\Certificate instances or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the certs.

$timestamp: null|\setasign\SetaPDF2\Core\DataStructure\Date|\DateTime|string
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

Throws Exception

Throws \Exception

addValidationRelatedInfoByField()

WARNING: This method is marked as deprecated!

Use DocumentSecurityStore::addValidationRelatedInfoByFieldName() instead.

Parameters
$fieldName: string

The signature field name.

$crls: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|X509\Crl>

An array of strings or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the CRLs.

$ocsps: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|Ocsp\Response>

An array of strings or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the OCSPs.

$certs: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|X509\Certificate>

An array of strings or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the certs.

$timestamp: null|\setasign\SetaPDF2\Core\DataStructure\Date|\DateTime|string
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

Throws Exception

See

addValidationRelatedInfoByFieldName()

Add validation related information to the VRI dictionary of the DSS dictionary by a specific signature field.

Parameters
$fieldName: string

The signature field name.

$crls: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|X509\Crl>

An array of strings or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the CRLs.

$ocsps: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|Ocsp\Response>

An array of strings or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the OCSPs.

$certs: array<string|\setasign\SetaPDF2\Core\Type\IndirectObjectInterface|X509\Certificate>

An array of strings or \setasign\SetaPDF2\Core\Type\IndirectObjectInterface to streams of the certs.

$timestamp: null|\setasign\SetaPDF2\Core\DataStructure\Date|\DateTime|string
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

Throws Exception

addValidationRelatedInfoResultByField()

Parameters
$fieldName: string

The signature field name.

$result: ValidationRelatedInfo\Result

The VRI result object with data for the given field.

Exceptions

Throws Asn1\Exception

Throws Exception

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

cleanUp()

public DocumentSecurityStore::cleanUp (
void
): void

Release cycled references.

getCRLs()

public DocumentSecurityStore::getCRLs (
void
): string[]

Get all CRLs the OCSPs entry in the DSS dictionary.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

getCertificates()

public DocumentSecurityStore::getCertificates (
void
): string[]

Get all certificates from the Certs entry in the DSS dictionary.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

getDictionary()

Get and/or creates the DSS dictionary.

Parameters
$create: bool
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

getForeignStreamArtifactValidationRelatedInfo()

public DocumentSecurityStore::getForeignStreamArtifactValidationRelatedInfo (
string $vriKey,
string $type
): array

Get foreign stream artifacts to a VRI dictionary.

Parameters
$vriKey: string
 
$type: string
 
Exceptions

Throws Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

getForeignStreamArtifacts()

public DocumentSecurityStore::getForeignStreamArtifacts (
string $type
): array

Get foreign artifacts from the main DSS dictionary by a foreign type name.

Parameters
$type: string
 
Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

getOCSPs()

public DocumentSecurityStore::getOCSPs (
void
): string[]

Get all OCSP responses from the OCSPs entry in the DSS dictionary.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

getOptimizeOcspResponses()

Get whether OCSP responses should be optimized or not.

See

getValidationRelatedInfo()

public DocumentSecurityStore::getValidationRelatedInfo (
?string $vriKey = null
): array<string, array|false>|array{certs: array, crls: array, ocsps: array, timestamp: \DateTimeInterface}|false

Get validation related information.

Parameters
$vriKey: ?string

The sha1 digest of the signature to get specific information. Otherwise, all found validation data is returned.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

getValidationRelatedInfoByField()

WARNING: This method is marked as deprecated!

Use DocumentSecurityStore::getValidationRelatedInfoByFieldName() instead.

public DocumentSecurityStore::getValidationRelatedInfoByField (
string $fieldName
): array<string, array|false>|array{certs: array, crls: array, ocsps: array, timestamp: \DateTimeInterface}|false
Parameters
$fieldName: string

The signature field name.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

See

getValidationRelatedInfoByFieldName()

public DocumentSecurityStore::getValidationRelatedInfoByFieldName (
string $fieldName
): array<string, array|false>|array{certs: array, crls: array, ocsps: array, timestamp: \DateTimeInterface}|false

Get validation related information by a signature field name.

Parameters
$fieldName: string

The signature field name.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Exception

Throws \setasign\SetaPDF2\NotImplementedException

Throws Asn1\Exception

getVriName()

public DocumentSecurityStore::getVriName (
Asn1\Signed $object
): string

Get the signature digest of a CRL or OCSP response which can be used as an index in the VRI dictionary.

Parameters
$object: Asn1\Signed
 

getVriNameByFieldName()

public DocumentSecurityStore::getVriNameByFieldName (
string $fieldName
): string

Get the signature digest of a signature field, which can be used as an index in the VRI dictionary.

For a document signature the bytes that are hashed are those of the signature's DER-encoded PKCS#7 (and its derivatives) binary data object (base-16 decoded byte string in the Contents entry in the signature dictionary).

For the signatures of the CRL and OCSP response, it is the respective signature object represented as a BER-encoded OCTET STRING encoded with primitive encoding.

For a Time-stamp's signature it is the bytes of the Time-stamp itself since the Time-stamp token is a signed data object.
Parameters
$fieldName: string
 
Exceptions

Throws \setasign\SetaPDF2\Core\Exception

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

Throws \setasign\SetaPDF2\Core\Type\IndirectReference\Exception

Throws Asn1\Exception

Throws Exception

remove()

public DocumentSecurityStore::remove (
void
): bool

Removes the DSS entry from the catalog dictionary.

Return Values

True if the entry existed or false if not.

Exceptions

Throws \setasign\SetaPDF2\Core\SecHandler\Exception

Throws \setasign\SetaPDF2\Core\Type\Exception

setOptimizeOcspResponses()

public DocumentSecurityStore::setOptimizeOcspResponses (
bool $optimizeOcspResponses
): void

Define whether OCSP responses should be optimized or not.

By optimizing (default = true) the OCSP responses the certificates are removed as they are normally embedded via addCertificates(), too. By doing this the certificates are not embedded twice.

Anyhow, there are validation enginges on the road which EXPECTS this optional field to be available.

Parameters
$optimizeOcspResponses: bool