Timestamping Authority is an on-premises timestamping solution based on RFC 3161 that guarantees that data, including documents or code, exists at a given time through the generation of digitally signed timestamps. Specifically:

  • Proof of the time when a digital signature was applied or validated.
  • Prevents code rejection, ensuring that the signature is valid when signing.
  • Enables digital signature verification after the certificate used for the signature is revoked or expired.

 When deployed on Cryptographic Security Platform, this Entrust solution adds the following to the Base installation integration report.

Hardware secure modules supported by Timestamping Authority

Timestamping Authority supports the following Hardware Secure Modules (HSM).

Hardware

Client driver

Firmware

Entrust nShield Connect XC

13.9.0  (FIPS 140-2 Level 3 mode supported)

12.60.15 & 12.60.2

Entrust nShield 5c

13.9.0

13.2.4

Thales Luna HSM 7

10.8.0

7.7.1-20

General considerations:

  • You do not need to install the client drivers because the solution already includes this software. However, these client drivers cannot be updated.
  • You can only use 1/N card sets. A card set of, for example, 2/5 cards is not supported.
  • On high-availability installations with a cluster of several HSMs:

    • You cannot use HSMs from different providers simultaneously, meaning that nShield and Thales HSMs cannot coexist within the same deployment.
    • Entrust Validation Authority may experience the Thales TCT limitations described in the Thales TCT Universal Client Plugin Additional Information technical note dated May 28, 2025.
    • Solutions using the HSMs must be redeployed after any loss of connection with the HSMs, such as after an HSM reboot.

Signature key generation algorithms supported by Timestamping Authority

Validation Authority supports the following algorithms for generating the timestamping response signing key.

<key_type>

Description

Post-quantum

RSA2048

RSA 2048 bits

(error) 

​RSA3072

RSA 3072 bits

(error) 

RSA4096

RSA 4096 bits

(error) 

ECDSAP256

ECDSA curve NIST P-256

(error) 

ECDSAP384

ECDSA curve NIST P-384

(error) 

ECDSAP521

ECDSA curve NIST P-521

(error) 

ML-DSA-44

Module-Lattice-Based Digital Signature Algorithm 44-bit

(tick) 

ML-DSA-65

Module-Lattice-Based Digital Signature Algorithm 65-bit

(tick) 

ML-DSA-87

Module-Lattice-Based Digital Signature Algorithm 87-bit

(tick)