e-invoicing

Long-term archiving and audit data

Long-term archiving preserves the evidence needed to validate electronic signatures beyond the lifetime of the original certificates and algorithms.

Long-term validation requires that a signed document be stored along with the audit data that was valid at the time of signing. This audit data enables future verification of the signature even after the signing certificate has expired or algorithms have become obsolete.

When storing a signed document, the parameters required depend on the nature of the signature. The ImplicitSignatureInfo, ExplicitSignatureInfo, and ExplicitAuditDataInfo sub-elements of the Document type are mutually exclusive. You can't set more than one per stored document. For unsigned documents, you must not use any of these elements.

See valid combinations of document formats, signature formats, and audit categories.

Signature audit categories

Audit categories identify the types of standardized electronic signatures that TrustWeaver Compliant e-Invoicing can create and validate.

Note:

See Supported signature formats for more details.

Audit category Description
CAdES-EPES, CAdES-T Doesn't contain long-term audit data but may be promoted to CAdES-A.
CAdES-A A format for preservation of long-term audit data based on CMS signatures.
XAdES-BES, XAdES-EPES, XAdES-T Doesn't contain long-term audit data but might be promoted to XAdES-A.
XAdES-A A format for preservation of long-term audit data based on XML signatures.
PAdES-EPES Doesn't contain long-term audit data but might be promoted to PAdES-LTV.
PAdES-LTV A format for preservation of long-term audit data for signed PDF documents. Unlike CAdES-A style PDF signatures, audit data is stored as native PDF objects. A CAdES-T, CAdES-A, or PAdES-EPES PDF signature might be promoted to PAdES-LTV.
EVIDENCE A format for preservation of explicit CAdES-A long-term audit data from formats that don't support it implicitly, such as EDIFACT formats (GS1AT, IDEAL, AECOC). Evidence can also be extracted from a PDF when a CAdES-A can't be constructed due to insufficient space in the PDF allocated at signature time.

The Details parameter

The Details output parameter contains information about the signature and the corresponding validation process, returned when a long-term verifiable signature is created. This parameter is also known as a validation report.

The Details element is included in the response when the job type is CADESA, XADESA, PADESLTV, or EVIDENCE. When two signatures are applied, the details element contains two signature elements.

To request audit details when using the Corroborate operation, set the CreateAuditDetails element to true. This element must be set to false when signing only and using an audit category that includes no audit data.

Ingoing namespaces

Namespace Prefix Description
http://www.trustweaver.com/ts/validationReportTypes Default TrustWeaver namespace
http://www.w3.org/2000/09/xmldsig# ds XMLDSIG namespace
http://www.w3.org/2001/XMLSchema xs XMLSchema namespace

ArchiveDetails

The outer element of type ArchiveDetails has the name details.

Node name Type Description
validationTime dateTime The time the validation was performed. Included only when no archive time-stamp is available.
signature SignatureInfo One element for each signature in the long-term verifiable signature (one or two).
otherTimestamps TimestampInfo The collection of document timestamps (PDF PAdES-LTV) covering the signed document. Included only when there is more than one document timestamp. The collection is ordered by the time the timestamps were applied.
signature (ds) ds:signature XMLDSIG signature element. Required if the signing certificate is qualified with respect to eIDAS regulations.

SignatureInfo

Node name Type Description
time dateTime The time the signature was created.
signingPolicyOid xs:string The OID of the policy under which the signature was created.
signingPolicyUrl xs:string The URL of the policy definition under which the signature was created.
validationPolicyOid xs:string The OID of the policy under which the signature was validated.
validationPolicyUrl xs:string The URL of the policy definition under which the signature was validated.
algorithmInfo AlgorithmInfo Information on the algorithms used for creating the signature.
signingCertificateInfo CertificateInfo Information on the certificate used for creating the signature.
signatureTimestamp TimestampInfo Information on the timestamp made at the time of signing. This timestamp covers only the signature itself.
archiveTimestamp TimestampInfo Information on the timestamp made when creating the long-term verifiable signature. This timestamp covers both the signature and the validation data.
validationReport ValidationReport The eIDAS-regulated validation report.
id xs:ID Element unique identifier.
isQualified xs:boolean True if the signature is qualified according to eIDAS regulations.
validationStatus xs:string The result of validating the signature. Possible values: SignerInvalid or SignatureInvalid.
hashAlgorithm xs:string The hash algorithm used for the signature, for example SHA1. This attribute duplicates the same-named attribute in algorithmInfo and exists for legacy reasons.
signatureAlgorithm xs:string The signature algorithm used when creating the signature. This attribute duplicates the same-named attribute in algorithmInfo and exists for legacy reasons.
validationModel xs:string The validation model used. Possible values: Shell validation model or Chain validation model.
keyLength xs:int The length in bits of the key used to create the signature. This attribute duplicates the same-named attribute in algorithmInfo and exists for legacy reasons.

CertificateInfo

Node name Type Description
qcStatements QcStatements The qualified statements of the certificate.
validity ValidityInfo The validity period of the certificate.
serialNumber xs:string The serial number of the certificate in hexadecimal digits.
issuerDn xs:string A human-readable string representation of the issuer distinguished name.
subjectDn xs:string A human-readable string representation of the subject distinguished name.
policyOid xs:string The OID of the policy under which the certificate was issued.
policyUrl xs:string The URL of the policy definition under which the certificate was issued.
rawCertificate xs:string The entire Base64-encoded certificate.
algorithmInfo AlgorithmInfo Information on the algorithms used for signing the certificate.
caChain CaChain The entire Certificate Authority (CA) chain for the certificate. Not used for certificates that are already inside a CA chain.
ocspResponse OcspResponseInfo Information on the Online Certificate Status Protocol (OCSP) response used when validating the certificate. Not present when a Certificate Revocation List (CRL) was used.
crl CrlInfo Information on the CRL used when validating the certificate. Not present when an OCSP response was used.
id xs:ID Element unique identifier.
revocationCheck xs:bool Indicates whether a revocation check was performed for this certificate. Default is true. If the attribute is absent, a revocation check was successfully performed.

QCStatements

The qcStatements extension, as defined in ETSI EN 319 412-5. This extension contains qcStatement1 through qcStatement6 elements identified by their respective Object Identifiers (OIDs):

Node name Type Description
id xs:ID Element unique identifier.
qcStatement1 QCStatement Identified by oid 0.4.0.1862.1.1.
qcStatement2 QCStatement Identified by oid 0.4.0.1862.1.2.
qcStatement3 QCStatement Identified by oid 0.4.0.1862.1.3.
qcStatement4 QCStatement Identified by oid 0.4.0.1862.1.4.
qcStatement5 QCStatement Identified by oid 0.4.0.1862.1.5.
qcStatement6 QCStatement Identified by oid 0.4.0.1862.1.6.

QCStatement

Node nome Type Description
oid xs:string The OID identifying a particular QCStatement.

TimestampInfo

Node name Type Description
time xs:dateTime When the timestamp was created.
serialNumber xs:string The timestamp serial number.
imprint xs:string The hex-encoded timestamp imprint.
policyOid xs:string The OID of the policy under which the timestamp token was issued.
signingCertificateInfo CertificateInfo Information on the certificate used to sign the timestamp. Present when the certificate is not already referenced elsewhere in the details structure.
signingCertificateRef CertificateRefType Reference to a signingCertificateInfo element with a matching id. Used when the certificate is already represented elsewhere in the details structure.
id xs:ID Unique element identifier.
type TimestampType The type of timestamp. Possible values: SignatureTimestamp, ArchiveTimestamp, or DocumentTimestamp.
Note:

The signing certificate is represented by either signingCertificateInfo or signingCertificateRef, not both.

AlgorithmInfo

Node name Type Description
isAlgorithmCombinationExpired (SigG only) xs:boolean It is true if the expiry time of at least one algorithm has passed during validation.
signatureAlgorithm xs:string The signature algorithm used when creating the signature.
keyLength xs:int The length in bits of the key used to create the signature.
signatureAlgorithmExpiryTime (SigG only) xs:dateTime The date and time when the signature algorithm expires. The value 0001-01-01T00:00:00Z indicates the algorithm is unknown to SigGLib. The value 9999-12-31T23:59:59.9999999Z indicates no expiration.
hashAlgorithm xs:string The hash algorithm used for the signature, for example SHA1.
hashAlgorithmExpiryTime (SigG only) xs:dateTime The date and time when the hash algorithm expires. Same value conventions as signatureAlgorithmExpiryTime.
Note: Attributes marked as "SigG only" are included only when the signer certificate is issued under a German SigG-compliant policy.

Validation report types

The validationReport element in SignatureInfo contains an eIDAS-regulated validation report structured as a hierarchy of typed blocks. Each block conveys the validation status of a target element identified by an xs:IDREF reference to that element's id attribute.

The inheritance relationships are as follows:

  • ValidationReportInfo extends ValidationStatusBlock

  • SignatureReport extends ValidationStatusBlock

  • CertificateReport extends ValidationStatusBlock

  • TimestampReport extends SignatureReport

ValidationReport

A wrapper element that contains the validation report for a single signature. It references elements elsewhere in the details structure using xs:ID and xs:IDREF attributes.

Node name Type Description
validationReport ValidationReportInfo The validation report for the signature referenced by the corresponding validation block.
ValidationReportInfo (of type ValidationStatusBlock)

Extends ValidationStatusBlock and contains the full validation report for a single signature, including its timestamps.

Node name Type Description
signature SignatureReport The signature validation report.
timestamps TimestampReport A sequence of timestamp signature validation reports contained within this signature.
SignatureReport (of type ValidationStatusBlock)

Extends ValidationStatusBlock and conveys the validation status of a signature and its certificate chain.

Node name Type Description
qcStatus QcStatusConstraint The eIDAS qualification status of the signature. Refer to the default TrustWeaver schema for the enumeration values.
format N/A The base signature format. Refer to the default TrustWeaver schema for details.
signingCertificate ValidationStatusBlock The validation status of the signing certificate.
cryptographicVerification ValidationStatusBlock The cryptographic verification status of the signature.
validationTime ValidationStatusBlock The validation status when the signature is validated.
certificates CertificateReport A sequence of certificate validation reports constituting the certificate chain, including the signing certificate.
CertificateReport (of type ValidationStatusBlock)

Extends ValidationStatusBlock and conveys the validation status of a single certificate in the chain.

Node name Type Description
revocationFreshness ValidationStatusBlock The validation status of the certificate with respect to the revocation resource used (OCSP or CRL).
TimestampReport (of type SignatureReport)

Extends SignatureReport and conveys the validation status of a timestamp signature.

Node name Type Description
timestampType TimestampType The timestamp type. Currently always RFC3161. Refer to the default TrustWeaver schema for the full enumeration.
ValidationStatusBlock

The base type shared by ValidationReportInfo, SignatureReport, CertificateReport, and TimestampReport. ValidationStatusBlock Conveys the validation status of a target element identified by an xs:IDREF reference.

Node name Type Description
target xs:IDREF Reference to the element in this document whose id attribute matches this value. Identifies the element whose validation status this block describes.
status xs:string The validation status code. Possible values: PASSED, FAILED, or INDETERMINATE.
subStatus xs:string A detailed status code. Always present when status is FAILED, it might be present when status is INDETERMINATE.

Supporting types

ValidityInfo

This type contains from (xs:dateTime) and to (xs:dateTime) elements specifying the start and end of a certificate's validity period.

CaChain

This type contains one certificateInfo element per Certificate Authority (CA) certificate, ordered from the issuing CA to the root CA (root CA is the last element).

OcspResponseInfo
This type contains:
  • signingCertificateInfo (CertificateInfo)

  • algorithmInfo (AlgorithmInfo)

  • id (xs:ID)

  • result (xs:string, either GOOD or REVOKED)

  • producedAt (xs:dateTime, production time of the OCSP response)

CrlInfo
This type contains:
  • issuerName (xs:string)

  • serialNumber (xs:string)

  • thisUpdate (xs:dateTime)

  • nextUpdate (xs:dateTime)

  • algorithmInfo (AlgorithmInfo)

  • id (xs:ID)