How to Request and Verify Timestamps Using OpenSSL

Qualified Timestamping with OpenSSL and cURL

Learn how to quickly request and verify a qualified timestamp response (TSR) for any file using standard command-line tools.

Prerequisites:

  • openssl utility installed (Linux, macOS, or Windows CLI).
  • curl utility to issue HTTP POST requests.
  • TSA Root & Intermediate Certificate Chain: Download TSAChain.zip.

Step 1: Generate the Timestamp Request (.tsq)

Use OpenSSL to compute the cryptographic hash of your file (e.g., document.pdf) and build an RFC 3161 compliant timestamp request. The -cert option instructs the TSA server to include its signer certificate in the response for offline verification.

openssl ts -query -data document.pdf -sha256 -cert -out request.tsq

Step 2: Submit the Request to the TSA Server

Send the binary request request.tsq to the TSA server HTTP endpoint using curl with the application/timestamp-query content type header. The server response will be saved to response.tsr.

curl -H "Content-Type: application/timestamp-query" \
     --data-binary "@request.tsq" \
     https://tsaexample.com/myserver.aspx \
     -o response.tsr

Step 3: Verify the Timestamp Token (.tsr)

Extract the certificate chain (TSAChain.pem) from the downloaded archive and validate the received timestamp token against the original file and the trusted certificate chain.

openssl ts -verify -data document.pdf \
     -in response.tsr \
     -CAfile TSAChain.pem
Expected Output: If the timestamp is valid and intact for the target file, OpenSSL will output: Verification: OK.

Optional: Inspect Timestamp Details

To inspect the inner details of the timestamp token (such as the exact UTC timestamp, hash algorithm, serial number, and TSA identity), decode the .tsr file using:

openssl ts -reply -in response.tsr -text