All Classes and Interfaces

Class
Description
5.2.8 Signature acceptance validation (SAV) This building block covers any additional verification to be performed on the signature itself or on the attributes of the signature ETSI EN 319 132-1
The abstract class implementing the "5.3 Validation process for Basic Signatures" process
The abstract cryptographic check
Abstract class to perform cryptographic validation
Performs cryptographic validation
Abstract code for DetailedReport builder
This class contains a common code to be processed as a part of a "5.2.2 Format Checking" building block for validation of signatures and timestamps.
Abstract class to check if the given value is one of the allowed values by ValidationPolicy
Abstract class containing the main logic for PastSignatureValidation result check
An abstract class for PDF lock dictionary validation
Abstract validation process executor
This class is a container for all reports generated by the validation process: diagnostic data, detailed report and simple report.
Abstract revocation check class
Abstract class verifying the validity of the Trusted List
Abstract filter defining the main logic of filters
Checks if the value is allowed
Checks if the signature's basic validation result is acceptable
Checks if a result of a Basic Signature Validation process for a timestamp token is acceptable
Verifies whether the BasicBuildingBlock's validation succeeded
Verifies whether the validation of a List of Trusted Lists is conclusive
Checks if the mimetype file is acceptable
Checks if an acceptable revocation data is found
Verifies whether the validation of aTrusted Lists is conclusive
Verifies whether acceptable Trusted Lists have been found
Checks if the zip comment is acceptable
Checks whether AdES signature validation as per EN 319 102-1 succeeded
Checks if all certificates in the path have the corresponding signing certificate references
Checks if all files are signed inside an ASiC container
Checks if the authority information access urls are present
Definition of signature Basic Building Blocks as per EN 319 102-1
5.2 Basic building blocks
This check verifies if the certificate contains BasicConstraint.cA attribute and its value is set to true
This check verifies whether the certificate path depth of the current certificate is conformant with BasicConstraints.pathLenConstraint value defined within intermediate CA certificates precessing in the chain
Signature validation process at validation time as per EN 319 102-1 ch.
Checks whether the validation result of EN 319 102-1 ch.
Verifies if the Basic Signature Validation Process succeeds
Checks if the best-signature-time is in the certificate's validity range
Checks if the best-signature-time is before certificate's expiration
Checks if best-signature-time is before the suspension date (onHold)
If best-signature-time is before the issuance date of the signing certificate, the process shall return the indication FAILED with the sub-indication NOT_YET_VALID.
This class verifies if all signatures and document timestamps present in a PDF are valid
This class verifies the applicability of the /ByteRange field extracted from a corresponding PDF revision
Checks if the current signature /ByteRange does not collide with other signature byte ranges
Checks whether there are CA/QC TrustedServices
Filters TrustedServices by CA/QC type
5.2.8 Signature acceptance validation (SAV) This building block covers any additional verification to be performed on the signature itself or on the attributes of the signature ETSI EN 319 132-1
This class verifies if the certificate does not contain forbidden certificate extensions
Checks if there are consistent by QC TrustedServices issues the certificate in question at control time
Checks if there are consistent by QSCD TrustedServices issues the certificate in question at control time
Checks if the certificate has been issued to a legal person
Checks if the certificate has been issued to a natural person
Checks if the QCEuRetentionPeriod constraint
Checks the minimal allowed QC transaction limit for the certificate
This check verifies the validity of the certificate in regard to "Name constraint" certificate extension's value in its certificate chain.
Checks if the certificate is not on hold
Checks if the certificate is not revokek
Checks if the certificate is not self-signed
Contain util methods for certificate policy identifiers checks
Checks if the certificate policy ids are acceptable
Checks if the certificate policies contain a Qualified identifier(s)
Checks if the certificate has a is a supported by QSCD policy identifier
This check verifies if the certificate has a valid policy tree according to its certification path in regard to RFC 5280
Processes a certificate validation
Checks the certificate's QcPS2D Id
Checks the certificate's QcPS2D Name
Checks the certificate's QcPS2D Role
Checks if the country code or set of country codes defined in QcCCLegislation is supported by the policy
Checks if the certificate is QC Compliant (has the id-etsi-qcs-QcCompliance statement)
Checks the minimal allowed QCLimitValue statement is defined with an acceptable currency
Checks the defined PDS locations for the certificate
Checks if the certificate is supported by QCSD (has the id-etsi-qcs-QcSSCD statement)
Checks the certificate's QcType(s)
This class verifies the final qualification of a certificate, processing its validation at issuance and validation time
This class is used to determine certificate's qualification based on its content and the given TrustedServiceWrapper
This class is a container for all reports generated by the certificate validation process: diagnostic data, detailed report and simple report.
This class validates revocation data for a given certificate and returns the latest valid entry
This class verifies the result of a CertificateRevocationSelector
Checks if the certificate is self-signed
Checks the QCStatement SemanticsIdentifier value
Checks if the certificate's signature is valid
Verifies if the certificate does not contain any of the certificate extensions listed within a list of unsupported certificate extensions
Checks if the certificate type has been successfully identified at best signing time
Checks if the certificate type has been identified at the given time
Verifies if a TrustedService(s) issuing the certificate have been found
Checks if the certificate is not expired
Checks if the certified roles are acceptable
Verifies certificate's qualification at the given time
This class is used to determine the certificate qualification based on the given qualification parameters
This class is part of the design pattern "Chain of responsibility".
This class is an item of the Chain class.
Checks if the SubXCV validation result is valid
Checks if the claimed roles are acceptable
Checks if the commitment type indications are acceptable
Checks if the certificate's common name is acceptable
Filters TrustedServices by qualifier and additional service information consistency
Filters TrustedServices by QC consistency
Filters TrustedServices by QSCD consistency
Filters TrustedServices by status consistency
Checks if the container type is acceptable
Checks if the content hints are acceptable
Checks if the content identifier is acceptable
Checks if a content timestamp is present
Checks if a collection of content timestamps is not empty
Checks if the content type is acceptable
Checks if a counter signature is present for the signature
Checks if the country's name is acceptable
The cryptographic check
Runs the cryptographic validation
Validates the result of a cryptographic checker
The wrapper for cryptographic information retrieved from a validation policy
5.2.7 Cryptographic verification This building block checks the integrity of the signed data by performing the cryptographic verifications.
Verifies if the format Cryptographic Verification process as per clause 5.2.7 succeeded
Checks if the current state is PASSED
Executes a certificate validation
This class executes a signature validation process and produces SimpleReport, DetailedReport and ETSI Validation report
Builds a DetailedReport for a signature validation
Builds a DetailedReport for a certificate validation
Check DigestAlgorithm at validation time
Check if DigestAlgorithm is acceptable
Checks the digest algorithm
Validates Digest cryptographic constraint
Verifies the DigestAlgorithm
Class used to verify a DigestMatcher
Checks if the digest value matches for a signing certificate reference
Checks if the digest value is present for a signing certificate reference
Verifies a signature according to given permissions for the document in /DocMDP
Processes a document validation
Exception to be thrown in case of JAXB Report marshaling or unmarshaling error
Contains EIDAS Utils
This class verifies whether the elliptic curve key size used to create the signature corresponds to the defined within 'alg' header of the JWA signature as per RFC 7518.
Check EncryptionAlgorithm at validation time
Check if EncryptionAlgorithm is acceptable
Builds the ETSI Validation report
Checks if the extended key usage is acceptable
Verifies a signature according to given permissions for the document in /FieldMDP
Determines the final qualification of a certificate giver two qualifications at issuance and best-signature-time
Checks if the signature format is acceptable
Verifies if the format checking process as per clause 5.2.2 succeeded
Checks if the signature covers FULL scope documents
Checks if the certificate's given name are acceptable
Filters TrustedServices by 'granted' status (before and after eIDAS)
Verifies of the certificate has related TrustedServices which have been 'granted' at the timestamp's production time
Verifies if the certificate has TrustedServices with a 'granted' status
Verifies if the identification of the signing certificate (as per clause 5.2.3) succeeded
5.2.3 Identification of the signing certificate This building block is responsible for identifying the signing certificate that will be used to validate the signature.
Checks if the certificate has ocsp-no-check extension and not expired in validation time
Checks whether the validator was able to select one TrustedService (in condition that there is no conflict with other TrustedServices)
Verifies if there is no conflict in certificate qualification determination result based on a use of different TrustedServices
Checks if the issuer serial matches for a signing certificate reference
Represents a merged strategy to extract pseudo information, accepting the certificate's pseudo attribute and custom German pseudo processing algorithm
Verifies whether a value of the signed attribute 'kid' (key identifier), when present, matches the signing-certificate sued to create the signature
This class verifies whether a 'kid' (key identifier) header parameter is present within the protected header of a signature
Checks if the certificate's key usage are acceptable
Verifies and returns the latest acceptable revocation data for a long-term validation process
Checks if the long-term validation check is acceptable
Checks if a manifest entry is present
Checks if the manifest file is present inside an ASiC container
Checks if message-digest (CAdES/PAdES) or SignedProperties (XAdES) is present
Verifies the message-imprint cryptographic constraints
Verifies cryptographical validity of a DigestAlgorithm used for message-imprint creation
Verifies whether the result of MessageImprintDigestAlgorithmValidation is valid
Checks if a mimetype file is present
This class verifies whether the certificate content equivalence information has been applied for the certificate
Checks if the nextUpdate is present
Checks if the certificate's organization name is acceptable
Checks if the certificate's organization unit is acceptable
Validates certificate in a past
Checks if the Past Certificate Validation result is acceptable
Checks if an acceptable revocation data is found
Performs the "5.6.2.4 Past signature validation building block"
Filters revocation data on a "Past Signature Validation" process
Verifies the validation result of a PastSignatureValidationCertificateRevocationSelector
Checks if the past signature validation result is acceptable
Checks if timestamp's past validation is acceptable
Checks if an acceptable revocation data is present for a Past Signature Validation process
This class checks whether the input document is a compliant according to the determined PDF/A format
Verifies if a PDF contains annotations overlapping
This class is used to check whether a determined PDF/A profile of the input document is acceptable.
Verifies if a PDF contains difference between page amount in different revisions
This class verifies whether the corresponding signature dictionary is consistent across PDF revisions.
Verifies if a PDF has visual difference between revisions
Contains Proof Of Existence for validation objects
The class compares two POE instances, by its production time, origin and covered context The class returns the following values: -1 if the poe1 is preferred over poe2 0 of the POEs are equal 1 if the poe2 is preferred over poe1
Checks if a POE exists before the control time
Checks if the POE exists
This check verifies if the set of POEs contains a POE for the certificate after the issuance date and before the expiration date of that certificate.
5.6.2.3 POE extraction 5.6.2.3.1 Description This building block derives POEs from a given time-stamp.
This class verifies if there is a POE for the revocation information of the signer certificate at (or before) the revocation time of the CA certificate
Represents a valid_policy_tree node (leaf) as per RFC 5280
This interface allows to define how the validation process should be carried out.
Checks if the certificate chain is trusted
Checks if the certificate's chain is trusted
Extracts pseudo String defined in X500 Attributes for the certificate
Extract pseudo information for German certificates
Checks if the certificate's pseudonym is acceptable
A strategy to extract a pseudo String from a given certificate
Checks if the certificate's pseudo usage is acceptable
Check if public key size is acceptable
Check if EncryptionAlgorithm is public key size is known
This class is used to check whether the given certificate contains qualification identifiers
Checks whether the certificate has been for QSCD at signing time
Checks whether the certificate was for QSCD at validation time
Used to extract QSCD status
Used to obtain a QSCDStrategy for the given certificate and a TrustedService
Checks of the certificate used to issue a timestamp is QTST
Filters TrustedServices by TSA/QTST type
Extract the qualification status for a certificate
Gets a QualificationStrategy to detect qualification strategy for a certificate
Checks whether the certificate is qualified at certificate issuance time
Checks whether the certificate is qualified at signing time
Checks whether the certificate is qualified at validation time
Checks if the referenced data is found
Checks if the referenced data is intact
Checks if the references are not ambiguous (only one document is retrieved)
This class verifies whether MRA enacted trusted services are present
This class is a container for all reports generated by the signature validation process: diagnostic data, detailed report and simple report.
Checks if the revocation is acceptable and can be used
Verifies if the RAC result is valid
5.2.8 Signature acceptance validation (SAV) This building block covers any additional verification to be performed on the signature itself or on the attributes of the signature ETSI EN 319 132-1
Performs basic validation of a revocation data
Checks if the revocation's certHash matches
Checks if the revocation's certHash is present
Checks if the revocation is consistent and can be used for the given certificate
Verifies the result of a basic revocation validation process
Checks if a revocation data is available for the certificate
Checks if the revocation data is fresh
Checks if the revocation data is fresh against its ThisUpdate and NextUpdate time interval
Checks if the revocation status is known
Checks if the revocation date is after best-signature-time
5.2.5 Revocation freshness checker This building block checks that a given revocation status information is "fresh" at a given validation time.
Checks if the revocation freshness checker's result is valid
Checks if the revocation access points are present in the certificate
This class verifies if the issuance date of the revocation status information is before control time
Checks if the revocation data is available for the revocation issuer's certificate
This class checks if the provided certificate token is trusted
This class verifies if a validation time is in the validity range of the certificate of the issuer of the revocation information
This method verifies whether the ResponderId property of an OCSP response matches the found certificate used to sign the OCSP response.
Checks if an acceptable revocation data exists
Checks if the certificate in question is not present in the OCSP's certificate chain
Checks if the certificate's serial number is present
Allowed services are : cert type T1 = ASi T1 cert type T1 = ASi T2 + QCForXXX T2 (overrule)
This class is used to filter trusted services by country code(s).
This filter is used to filter TrustedServices that have been valid at the given time
This class filters Trusted Services with MRA enacted value
This class fitlers Trusted Services by the related MRA equivalence starting date
This class is used to filter trusted services by the TL Url.
Checks if the Trusted Service is consistent
Service type identifier (ETSI TS 119 612 V2.1.1) It specifies the identifier of the service type.
Verifies a signature according to given permissions for the signature field in /SigFieldLock
5.2.8 Signature acceptance validation (SAV) This building block covers any additional verification to be performed on the signature itself or on the attributes of the signature ETSI EN 319 132-1
Checks if the signature validation result is acceptable
Verifies if the format Signature Acceptance Validation process as per clause 5.2.8 succeeded
5.2.2 Format Checking This building block shall check that the signature to validate is conformant to the applicable base format (e.g.
Checks if the signature value is intact
Checks if the signature is intact for the given token, with a difference that provides the token's Id to the additional information
Checks if the signature can be identifier
Checks if signature policy identifier is present and the hash matched
Checks if signature policy identifier is present and the policy is identified
Checks if the signature policy identifier is acceptable
Checks if a SignaturePolicyStore is present
Checks if the signature policy identifier is a zero-hash
Performs the qualification verification for a signature
Checks if signed file are present in an ASiC container
Checks if only one SignatureInformationStore is present for a PAdES signature
Checks if the signer's location attribute is present
Checks if the signing certificate reference is present
Verifies a DigestAlgorithm used for a signing-certificate-reference
Verifies if the X.509 Certificate Validation as per clause 5.2.6 did not return INDETERMINATE/REVOKED_NO_POE indication
Checks if a signing certificate is identified
This class verifies whether a used eu.europa.esig.dss.enumerations.DigestAlgorithm for a signing-certificate-reference signing-attribute is reliable and acceptable at validation time
Checks if a signing certificate reference is present and valid (all signingCertificate references refer the signature certificate chain)
Checks if the claimed signing time is present
Checks if a claimed signing time is present
Builds a signature qualification result based on the given parameters
This class builds a SimpleReport XmlDom from the diagnostic data and detailed validation report.
Builds a SimpleReport for a certificate validation
Checks if the structural validation of the signature succeeds
The sub X509 certificate validation
Checks if the certificate's surname is acceptable
5.2.8 Signature acceptance validation (SAV) This building block covers any additional verification to be performed on the signature itself or on the attributes of the signature ETSI EN 319 132-1
Performs Time-stamp validation building block as per clause 5.4
Checks if the timestamp's order is coherent
Checks if the claimed signing time + timestamp's delay is after the best-signature-time
This class performs "5.2.2 Format Checking" building block execution for a document or container timestamp
This class verifies if the generation time of a content timestamp is not after the certificate's expiration time
Checks if the generation time of a content timestamp is not after the expiration time of cryptographic constraints concerned by the failure
This class checks if the generation time of a content timestamp is not after the revocation time of a signature's signing certificate
Checks message-imprint validity for a timestamp token
The class performs a qualification verification for a timestamp
Verifies whether the Trusted List is fresh
Checks if the Trusted List is defined with MRA
Verifies whether the Trusted List is not expired
This class is used to perform validation of a Trusted List
Checks whether the version of the Trusted List is acceptable
Checks whether signature of Trusted List is valid
Checks if the ServiceDigitalIdentifier of the TrustedService matches the TrustedService name
Checks whether a Trusted List has been reached for the given certificate chain
Contain util method to check validity of the TrustedServiceWrapper
Checks whether the TrustedService is valid
Used to filter acceptable Trusted Services to be used during qualification determination process
Verifies whether type qualifiers and additional service information are consistent for pre-eIDAS trusted service
Creates a TrustedServiceFilter
ETSI TS 119 612 V2.2.1
Checks if the certificate's usage time in the validity range of a TrustedService with the accepted status
Verifies status of a trusted service created before eIDAS
Checks if the certificate's usage time in the validity range of a TrustedService with the accepted type
Checks if a corresponding Trust Service found valid at control time
Checks if a trust service corresponding to the certificate type has been found
Checks if the TSTInfo.tsa field is present
Checks if the TSTInfo.tsa field value matches the timestamp's issuer distinguishing name
Checks if the TSTInfo.tsa field value matches the timestamp's issuer distinguishing name
Strategy to extract certificate usage type for a certificate
Creates a TypeStrategy
This class checks whether a document contains undefined object modifications
Checks if the only one reference to the signing certificate reference is present
This class is used to select a TrustedService that is unambiguous and does not have conflicts with other TrustedServices.
5.2.4 Validation context initialization This building block initializes the validation constraints (chain constraints, cryptographic constraints, signature elements constraints) and parameters (X.509 validation parameters including trust anchors, certificate validation data) that will be used to validate the signature.
Verifies if the Validation Context Initialization as per clause 5.2.4 succeeded
The target validation level as per EN 319 102-1 NOTE: the validation process "stops" processing on the chosen level
5.6 Validation process for Signatures with Archival Data
5.5 Validation process for Signatures with Time and Signatures with Long-Term Validation Data
Contains utils for a validation process
Verifies if the result of X509CertificateValidation is not indication INDETERMINATE with the sub-indication OUT_OF_BOUNDS_NO_POE or OUT_OF_BOUNDS_NOT_REVOKED
Performs Validation Time Sliding process
Filters revocation data on a "Validation Time Sliding" process
Checks if the Validation Time Sliding result is valid
Checks if an acceptable Trust Service for a qualified certificate issuance found
5.2.6 X.509 certificate validation This building block validates the signing certificate at current time.
Verifies if the X.509 Certificate Validation as per clause 5.2.6 succeeded
Checks if the zip comment is present