Qualified Timestamping with OpenSSL and cURL
Learn how to quickly request and verify a qualified timestamp response (TSR) for any file using standard command-line tools.
opensslutility installed (Linux, macOS, or Windows CLI).curlutility to issue HTTP POST requests.- TSA Root & Intermediate Certificate Chain: Download TSAChain.zip.
Step 1: Generate the Timestamp Request (.tsq)
Use OpenSSL to compute the cryptographic hash of your file (e.g., document.pdf) and build an RFC 3161 compliant timestamp request. The -cert option instructs the TSA server to include its signer certificate in the response for offline verification.
openssl ts -query -data document.pdf -sha256 -cert -out request.tsq
Step 2: Submit the Request to the TSA Server
Send the binary request request.tsq to the TSA server HTTP endpoint using curl with the application/timestamp-query content type header. The server response will be saved to response.tsr.
curl -H "Content-Type: application/timestamp-query" \
--data-binary "@request.tsq" \
https://tsaexample.com/myserver.aspx \
-o response.tsr
Step 3: Verify the Timestamp Token (.tsr)
Extract the certificate chain (TSAChain.pem) from the downloaded archive and validate the received timestamp token against the original file and the trusted certificate chain.
openssl ts -verify -data document.pdf \
-in response.tsr \
-CAfile TSAChain.pem
Verification: OK.Optional: Inspect Timestamp Details
To inspect the inner details of the timestamp token (such as the exact UTC timestamp, hash algorithm, serial number, and TSA identity), decode the .tsr file using:
openssl ts -reply -in response.tsr -text