Basic Properties
The following properties are common for all AdES Signers. Each AdES Signer may have additional specific set of properties that are described in the subsequent sections.
| Property | Description | Default Value | Mandatory | Metadata Support |
|---|---|---|---|---|
| SIGNATURE_LEVEL | The signature level property specified the desired baseline level of the signature. | NONE | YES | NO |
| Time Stamping Authority | Time stamping authority to include timestamp. | NONE | NO | |
| EMBED_CRL | Embed CRL revocation information from the CRL location defined in the certificate CRL distribution point. | false | Mandatory for the following profiles:
| NO |
| CRL_DATA_LOADER_TIMEOUT_CONNECTION | Timeout in milliseconds for connection to the CRL data loader. This is the timeout for establishing a connection to the CRL distribution point. | 60000 | NO | YES |
| CRL_DATA_LOADER_TIMEOUT_SOCKET | Timeout in milliseconds for socket of the CRL data loader. This is the timeout for waiting for data after a connection to the CRL distribution point has been established. | 60000 | NO | YES |
| CRL_CACHE_ENABLED | Enables in-memory caching of downloaded CRLs. A cached CRL is reused until its nextUpdate instead of being downloaded for every signing request. Review the CRL caching notes before enabling it. | false | NO | YES |
| CRL_CACHE_NEXT_UPDATE_OFFSET | Number of seconds before its nextUpdate at which a cached CRL is refreshed, so that the successor CRL is used as soon as it is expected to be published. Set it to the CA's CRL overlap period, and keep it below the validity period of the shortest-lived CRL in the chain, otherwise that CRL is never reused. Applies only when CRL_CACHE_ENABLED is true. | NONE | NO | YES |
| CRL_CACHE_MAX_NEXT_UPDATE_DELAY | Maximum number of seconds after its thisUpdate for which a cached CRL is reused, for CAs that publish a distant nextUpdate. Because the limit counts from thisUpdate, a CRL issued longer ago than this value, such as a rarely issued root CA CRL, is downloaded for every signing request as if caching were disabled. Applies only when CRL_CACHE_ENABLED is true. | NONE | NO | YES |
| EMBED_OCSP_RESPONSE | Embed OCSP response status information from the OCSP URI located in the certificate AIA extension. | false | Mandatory for the following profiles:
| NO |
| OCSP_DATA_LOADER_TIMEOUT_CONNECTION | Timeout in milliseconds for connection to the OCSP data loader. This is the timeout for establishing a connection to the OCSP URI located in the certificate AIA extension. | 60000 | NO | YES |
| OCSP_DATA_LOADER_TIMEOUT_SOCKET | Timeout in milliseconds for socket of the OCSP data loader. This is the timeout for waiting for data after a connection to the OCSP URI located in the certificate AIA extension has been established. | 60000 | NO | YES |
| ENCRYPTIONALGORITHM | Encryption algorithm to use with the signature algorithm, for example RSASSA-PSS. | Taken from the Subject Public Key Info of the signing certificate. | NO | YES |
| DIGESTALGORITHM | Digest algorithm to use with the signature algorithm. | SHA256 | NO | YES |
| TRUSTED_CERTIFICATES | Contains list of PEM certificates to use as a trusted sources, additionally to the LOTL and TLs. This is the place where you need to provide your trusted certificates that are not part of the public trust list. | LOTL and TLs | NO | NO |
| Signed Attributes | B-level parameters for a signature creation. | NONE | NO | |
| METADATA_PROPERTY_OVERRIDE_ALLOWED | Contains list of comma-separated properties that are allowed to be overridden using metadata. The name of the property should match the name of the property in the configuration. For the properties that can be overridden, see the specific AdES Signer documentation. | NONE | NO | NO |
| Alerts Properties | Alerts configuration for signing process. You can configure alerts behavior for different types of issues and events occurring during the signing process, and how they should be handled. | NONE | NO | |
| EXCLUDE_SKIP_REVOCATION_EXTENSIONS | Comma-separated list of certificate extension OIDs for revocation data check skip that should be excluded. The following extensions are included by default:
| NONE | NO | YES |
CRL caching
Before enabling CRL_CACHE_ENABLED, keep in mind that:
- The cache is shared by all workers in the same instance that enable it. Each worker applies its own limits, and a CRL that one of them refreshes is refreshed for all.
- A CRL republished before its
nextUpdate, for example after an emergency revocation, is not used until the cached copy expires, and only a restart clears the cache. Limit this withCRL_CACHE_NEXT_UPDATE_OFFSET, or withCRL_CACHE_MAX_NEXT_UPDATE_DELAYif every CRL in the chain is reissued within that delay. - Cached CRLs are held in memory, so allow enough heap for large CRLs.
- For augmentors, keep caching disabled unless its effect on the
ALERTS_NOREVOCATIONAFTERBESTSIGNATURETIMEalert has been verified.