Timestamping Authority is an on-premises timestamping solution based on RFC 3161 that guarantees that data, including documents or code, exists at a given time through the generation of digitally signed timestamps. Specifically:

  • Proof of the time when a digital signature was applied or validated.
  • Prevents code rejection by ensuring the signature is valid at the time of signing.
  • Enables digital signature verification after the certificate used for the signature is revoked or expired.

 When deployed on PKI Hub, this Entrust solution adds the following to the PKI Hub integration report.

Hardware security modules supported by Timestamping Authority

 See the following table for versions supported by Timestamping Authority and other solutions.

Hardware

Client driver

Firmware

Certificate Authority

Timestamping Authority

Validation Authority

Entrust nShield Connect XC

13.9.0 (FIPS 140-2 Level 3 mode supported)

12.60.15 & 12.60.2

(tick) 

(tick) 

(tick) 

Entrust nShield 5c

13.9.0

13.2.4

(tick) 

(tick) 

(tick) 

Entrust nShield 5c 10G 

Not supported

Not supported

(error) 

(error) 

(error) 

Epicom

 EP990 v1.08-1

—

(error) 

(tick) 

(tick) 

Thales Luna HSM 7

10.8.0

7.7.1-20

(tick) 

(tick) 

(tick) 

Thales TCT

10.8.0

7.7.1-20

(error)  

(tick) 

(tick) 

Signature key generation algorithms supported by Timestamping Authority

Validation Authority supports different key types and algorithms for generating the timestamping response signing key.

See the table below for the supported RSA key types.

Key type identifier

Key algorithm

Modulus size

RSA2048

RSA

2048 bits

RSA3072

RSA

3072 bits

RSA4096

RSA

4096 bits

See the table below for the supported ECDSA key types.

Key type identifier

Key algorithm

Curve

ECDSAP256

ECDSA

NIST P-256

ECDSAP384

ECDSA

NIST P-384

ECDSAP521

ECDSA

NIST P-521

See table below for the supported ML-DSA key types.

Key type identifier

ML-DSA key

ML-DSA-44

ML-DSA-44 key pair

ML-DSA-65

ML-DSA-65 key pair

ML-DSA-87

ML-DSA-87 key pair

See table below for the supported composite key types.

Key type identifier

ML-DSA key

Classical algorithm

Classical parameter

Signature scheme

Hash

MLDSA44-RSA2048-PSS-SHA256

ML-DSA-44 key pair

RSA

2048 bits

RSA-PSS

SHA-256

MLDSA44-RSA2048-PKCS15-SHA256

ML-DSA-44 key pair

RSA

2048 bits

RSA PKCS#1 v1.5

SHA-256

MLDSA44-ECDSA-P256-SHA256

ML-DSA-44 key pair

ECDSA

NIST P-256

ECDSA

SHA-256

MLDSA65-RSA3072-PSS-SHA512

ML-DSA-65 key pair

RSA

3072 bits

RSA-PSS

SHA-512

MLDSA65-RSA3072-PKCS15-SHA512

ML-DSA-65 key pair

RSA

3072 bits

RSA PKCS#1 v1.5

SHA-512

MLDSA65-RSA4096-PSS-SHA512

ML-DSA-65 key pair

RSA

4096 bits

RSA-PSS

SHA-512

MLDSA65-RSA4096-PKCS15-SHA512

ML-DSA-65 key pair

RSA

4096 bits

RSA PKCS#1 v1.5

SHA-512

MLDSA65-ECDSA-P256-SHA512

ML-DSA-65 key pair

ECDSA

NIST P-256

ECDSA

SHA-512

MLDSA65-ECDSA-P384-SHA512

ML-DSA-65 key pair

ECDSA

NIST P-384

ECDSA

SHA-512

MLDSA87-RSA3072-PSS-SHA512

ML-DSA-87 key pair

RSA

3072 bits

RSA-PSS

SHA-512

MLDSA87-RSA4096-PSS-SHA512

ML-DSA-87 key pair

RSA

4096 bits

RSA-PSS

SHA-512

MLDSA87-ECDSA-P384-SHA512

ML-DSA-87 key pair

ECDSA

NIST P-384

ECDSA

SHA-512

MLDSA87-ECDSA-P521-SHA512

ML-DSA-87 key pair

ECDSA

NIST P-521

ECDSA

SHA-512