Long-term archiving and audit data
Long-term archiving preserves the evidence needed to validate electronic signatures beyond the lifetime of the original certificates and algorithms.
Long-term validation requires that a signed document be stored along with the audit data that was valid at the time of signing. This audit data enables future verification of the signature even after the signing certificate has expired or algorithms have become obsolete.
When storing a signed document, the parameters required depend on the nature of the signature. The ImplicitSignatureInfo, ExplicitSignatureInfo, and ExplicitAuditDataInfo sub-elements of the Document type are mutually exclusive. You can't set more than one per stored document. For unsigned documents, you must not use any of these elements.
See valid combinations of document formats, signature formats, and audit categories.
Signature audit categories
Audit categories identify the types of standardized electronic signatures that TrustWeaver Compliant e-Invoicing can create and validate.
See Supported signature formats for more details.
| Audit category | Description |
|---|---|
| CAdES-EPES, CAdES-T | Doesn't contain long-term audit data but may be promoted to CAdES-A. |
| CAdES-A | A format for preservation of long-term audit data based on CMS signatures. |
| XAdES-BES, XAdES-EPES, XAdES-T | Doesn't contain long-term audit data but might be promoted to XAdES-A. |
| XAdES-A | A format for preservation of long-term audit data based on XML signatures. |
| PAdES-EPES | Doesn't contain long-term audit data but might be promoted to PAdES-LTV. |
| PAdES-LTV | A format for preservation of long-term audit data for signed PDF documents. Unlike CAdES-A style PDF signatures, audit data is stored as native PDF objects. A CAdES-T, CAdES-A, or PAdES-EPES PDF signature might be promoted to PAdES-LTV. |
| EVIDENCE | A format for preservation of explicit CAdES-A long-term audit data from formats that don't support it implicitly, such as EDIFACT formats (GS1AT, IDEAL, AECOC). Evidence can also be extracted from a PDF when a CAdES-A can't be constructed due to insufficient space in the PDF allocated at signature time. |
The Details parameter
The Details output parameter contains information about the signature and the corresponding validation process, returned when a long-term verifiable signature is created. This parameter is also known as a validation report.
The Details element is included in the response when the job type is CADESA, XADESA, PADESLTV, or EVIDENCE. When two signatures are applied, the details element contains two signature elements.
To request audit details when using the Corroborate operation, set the CreateAuditDetails element to true. This element must be set to false when signing only and using an audit category that includes no audit data.
Ingoing namespaces
| Namespace | Prefix | Description |
|---|---|---|
| http://www.trustweaver.com/ts/validationReportTypes | Default TrustWeaver namespace | |
| http://www.w3.org/2000/09/xmldsig# | ds | XMLDSIG namespace |
| http://www.w3.org/2001/XMLSchema | xs | XMLSchema namespace |
ArchiveDetails
The outer element of type ArchiveDetails has the name details.
| Node name | Type | Description |
|---|---|---|
| validationTime | dateTime | The time the validation was performed. Included only when no archive time-stamp is available. |
| signature | SignatureInfo | One element for each signature in the long-term verifiable signature (one or two). |
| otherTimestamps | TimestampInfo | The collection of document timestamps (PDF PAdES-LTV) covering the signed document. Included only when there is more than one document timestamp. The collection is ordered by the time the timestamps were applied. |
| signature (ds) | ds:signature | XMLDSIG signature element. Required if the signing certificate is qualified with respect to eIDAS regulations. |
SignatureInfo
| Node name | Type | Description |
|---|---|---|
| time | dateTime | The time the signature was created. |
| signingPolicyOid | xs:string | The OID of the policy under which the signature was created. |
| signingPolicyUrl | xs:string | The URL of the policy definition under which the signature was created. |
| validationPolicyOid | xs:string | The OID of the policy under which the signature was validated. |
| validationPolicyUrl | xs:string | The URL of the policy definition under which the signature was validated. |
| algorithmInfo | AlgorithmInfo | Information on the algorithms used for creating the signature. |
| signingCertificateInfo | CertificateInfo | Information on the certificate used for creating the signature. |
| signatureTimestamp | TimestampInfo | Information on the timestamp made at the time of signing. This timestamp covers only the signature itself. |
| archiveTimestamp | TimestampInfo | Information on the timestamp made when creating the long-term verifiable signature. This timestamp covers both the signature and the validation data. |
| validationReport | ValidationReport | The eIDAS-regulated validation report. |
| id | xs:ID | Element unique identifier. |
| isQualified | xs:boolean | True if the signature is qualified according to eIDAS regulations. |
| validationStatus | xs:string | The result of validating the signature. Possible values: SignerInvalid or SignatureInvalid. |
| hashAlgorithm | xs:string | The hash algorithm used for the signature, for example SHA1. This attribute duplicates the same-named attribute in algorithmInfo and exists for legacy reasons. |
| signatureAlgorithm | xs:string | The signature algorithm used when creating the signature. This attribute duplicates the same-named attribute in algorithmInfo and exists for legacy reasons. |
| validationModel | xs:string | The validation model used. Possible values: Shell validation model or Chain validation model. |
| keyLength | xs:int | The length in bits of the key used to create the signature. This attribute duplicates the same-named attribute in algorithmInfo and exists for legacy reasons. |
CertificateInfo
| Node name | Type | Description |
|---|---|---|
| qcStatements | QcStatements | The qualified statements of the certificate. |
| validity | ValidityInfo | The validity period of the certificate. |
| serialNumber | xs:string | The serial number of the certificate in hexadecimal digits. |
| issuerDn | xs:string | A human-readable string representation of the issuer distinguished name. |
| subjectDn | xs:string | A human-readable string representation of the subject distinguished name. |
| policyOid | xs:string | The OID of the policy under which the certificate was issued. |
| policyUrl | xs:string | The URL of the policy definition under which the certificate was issued. |
| rawCertificate | xs:string | The entire Base64-encoded certificate. |
| algorithmInfo | AlgorithmInfo | Information on the algorithms used for signing the certificate. |
| caChain | CaChain | The entire Certificate Authority (CA) chain for the certificate. Not used for certificates that are already inside a CA chain. |
| ocspResponse | OcspResponseInfo | Information on the Online Certificate Status Protocol (OCSP) response used when validating the certificate. Not present when a Certificate Revocation List (CRL) was used. |
| crl | CrlInfo | Information on the CRL used when validating the certificate. Not present when an OCSP response was used. |
| id | xs:ID | Element unique identifier. |
| revocationCheck | xs:bool | Indicates whether a revocation check was performed for this certificate. Default is true. If the attribute is absent, a revocation check was successfully performed. |
QCStatements
The qcStatements extension, as defined in ETSI EN 319 412-5. This extension contains qcStatement1 through qcStatement6 elements identified by their respective Object Identifiers (OIDs):
| Node name | Type | Description |
|---|---|---|
| id | xs:ID | Element unique identifier. |
| qcStatement1 | QCStatement | Identified by oid 0.4.0.1862.1.1. |
| qcStatement2 | QCStatement | Identified by oid 0.4.0.1862.1.2. |
| qcStatement3 | QCStatement | Identified by oid 0.4.0.1862.1.3. |
| qcStatement4 | QCStatement | Identified by oid 0.4.0.1862.1.4. |
| qcStatement5 | QCStatement | Identified by oid 0.4.0.1862.1.5. |
| qcStatement6 | QCStatement | Identified by oid 0.4.0.1862.1.6. |
QCStatement
| Node nome | Type | Description |
|---|---|---|
| oid | xs:string | The OID identifying a particular QCStatement. |
TimestampInfo
| Node name | Type | Description |
|---|---|---|
| time | xs:dateTime | When the timestamp was created. |
| serialNumber | xs:string | The timestamp serial number. |
| imprint | xs:string | The hex-encoded timestamp imprint. |
| policyOid | xs:string | The OID of the policy under which the timestamp token was issued. |
| signingCertificateInfo | CertificateInfo | Information on the certificate used to sign the timestamp. Present when the certificate is not already referenced elsewhere in the details structure. |
| signingCertificateRef | CertificateRefType | Reference to a signingCertificateInfo element with a matching id. Used when the certificate is already represented elsewhere in the details structure. |
| id | xs:ID | Unique element identifier. |
| type | TimestampType | The type of timestamp. Possible values: SignatureTimestamp, ArchiveTimestamp, or DocumentTimestamp. |
The signing certificate is represented by either signingCertificateInfo or signingCertificateRef, not both.
AlgorithmInfo
| Node name | Type | Description |
|---|---|---|
| isAlgorithmCombinationExpired (SigG only) | xs:boolean | It is true if the expiry time of at least one algorithm has passed during validation. |
| signatureAlgorithm | xs:string | The signature algorithm used when creating the signature. |
| keyLength | xs:int | The length in bits of the key used to create the signature. |
| signatureAlgorithmExpiryTime (SigG only) | xs:dateTime | The date and time when the signature algorithm expires. The value 0001-01-01T00:00:00Z indicates the algorithm is unknown to SigGLib. The value 9999-12-31T23:59:59.9999999Z indicates no expiration. |
| hashAlgorithm | xs:string | The hash algorithm used for the signature, for example SHA1. |
| hashAlgorithmExpiryTime (SigG only) | xs:dateTime | The date and time when the hash algorithm expires. Same value conventions as signatureAlgorithmExpiryTime. |
Validation report types
The validationReport element in SignatureInfo contains an eIDAS-regulated validation report structured as a hierarchy of typed blocks. Each block conveys the validation status of a target element identified by an xs:IDREF reference to that element's id attribute.
The inheritance relationships are as follows:
-
ValidationReportInfoextendsValidationStatusBlock -
SignatureReportextendsValidationStatusBlock -
CertificateReportextendsValidationStatusBlock -
TimestampReportextendsSignatureReport
- ValidationReport
-
A wrapper element that contains the validation report for a single signature. It references elements elsewhere in the details structure using
xs:IDandxs:IDREFattributes.Node name Type Description validationReport ValidationReportInfo The validation report for the signature referenced by the corresponding validation block. - ValidationReportInfo (of type ValidationStatusBlock)
-
Extends
ValidationStatusBlockand contains the full validation report for a single signature, including its timestamps.Node name Type Description signature SignatureReport The signature validation report. timestamps TimestampReport A sequence of timestamp signature validation reports contained within this signature. - SignatureReport (of type ValidationStatusBlock)
-
Extends
ValidationStatusBlockand conveys the validation status of a signature and its certificate chain.Node name Type Description qcStatus QcStatusConstraint The eIDAS qualification status of the signature. Refer to the default TrustWeaver schema for the enumeration values. format N/A The base signature format. Refer to the default TrustWeaver schema for details. signingCertificate ValidationStatusBlock The validation status of the signing certificate. cryptographicVerification ValidationStatusBlock The cryptographic verification status of the signature. validationTime ValidationStatusBlock The validation status when the signature is validated. certificates CertificateReport A sequence of certificate validation reports constituting the certificate chain, including the signing certificate. - CertificateReport (of type ValidationStatusBlock)
-
Extends
ValidationStatusBlockand conveys the validation status of a single certificate in the chain.Node name Type Description revocationFreshness ValidationStatusBlock The validation status of the certificate with respect to the revocation resource used (OCSP or CRL). - TimestampReport (of type SignatureReport)
-
Extends
SignatureReportand conveys the validation status of a timestamp signature.Node name Type Description timestampType TimestampType The timestamp type. Currently always RFC3161. Refer to the default TrustWeaver schema for the full enumeration. - ValidationStatusBlock
-
The base type shared by
ValidationReportInfo,SignatureReport,CertificateReport, andTimestampReport.ValidationStatusBlockConveys the validation status of a target element identified by anxs:IDREFreference.Node name Type Description target xs:IDREF Reference to the element in this document whose idattribute matches this value. Identifies the element whose validation status this block describes.status xs:string The validation status code. Possible values: PASSED,FAILED, orINDETERMINATE.subStatus xs:string A detailed status code. Always present when statusisFAILED, it might be present whenstatusisINDETERMINATE.
Supporting types
- ValidityInfo
-
This type contains
from(xs:dateTime) andto(xs:dateTime) elements specifying the start and end of a certificate's validity period. - CaChain
-
This type contains one
certificateInfoelement per Certificate Authority (CA) certificate, ordered from the issuing CA to the root CA (root CA is the last element). - OcspResponseInfo
-
This type contains:
-
signingCertificateInfo(CertificateInfo) -
algorithmInfo(AlgorithmInfo) -
id(xs:ID) -
result(xs:string, eitherGOODorREVOKED) -
producedAt(xs:dateTime, production time of the OCSP response)
-
- CrlInfo
-
This type contains:
-
issuerName(xs:string) -
serialNumber(xs:string) -
thisUpdate(xs:dateTime) -
nextUpdate(xs:dateTime) -
algorithmInfo(AlgorithmInfo) -
id(xs:ID)
-
