Skip to main content

Basic Properties

The following properties are common for all AdES Signers. Each AdES Signer may have additional specific set of properties that are described in the subsequent sections.

PropertyDescriptionDefault ValueMandatoryMetadata Support
SIGNATURE_LEVELThe signature level property specified the desired baseline level of the signature.NONEYESNO
Time Stamping AuthorityTime stamping authority to include timestamp.NONENO
EMBED_CRLEmbed CRL revocation information from the CRL location defined in the certificate CRL distribution point.falseMandatory for the following profiles:
  • BASELINE-LT
  • BASELINE-LTA
NO
CRL_DATA_LOADER_TIMEOUT_CONNECTIONTimeout in milliseconds for connection to the CRL data loader. This is the timeout for establishing a connection to the CRL distribution point.60000NOYES
CRL_DATA_LOADER_TIMEOUT_SOCKETTimeout in milliseconds for socket of the CRL data loader. This is the timeout for waiting for data after a connection to the CRL distribution point has been established.60000NOYES
CRL_CACHE_ENABLEDEnables in-memory caching of downloaded CRLs. A cached CRL is reused until its nextUpdate instead of being downloaded for every signing request. Review the CRL caching notes before enabling it.falseNOYES
CRL_CACHE_NEXT_UPDATE_OFFSETNumber of seconds before its nextUpdate at which a cached CRL is refreshed, so that the successor CRL is used as soon as it is expected to be published. Set it to the CA's CRL overlap period, and keep it below the validity period of the shortest-lived CRL in the chain, otherwise that CRL is never reused. Applies only when CRL_CACHE_ENABLED is true.NONENOYES
CRL_CACHE_MAX_NEXT_UPDATE_DELAYMaximum number of seconds after its thisUpdate for which a cached CRL is reused, for CAs that publish a distant nextUpdate. Because the limit counts from thisUpdate, a CRL issued longer ago than this value, such as a rarely issued root CA CRL, is downloaded for every signing request as if caching were disabled. Applies only when CRL_CACHE_ENABLED is true.NONENOYES
EMBED_OCSP_RESPONSEEmbed OCSP response status information from the OCSP URI located in the certificate AIA extension.falseMandatory for the following profiles:
  • BASELINE-LT
  • BASELINE-LTA
NO
OCSP_DATA_LOADER_TIMEOUT_CONNECTIONTimeout in milliseconds for connection to the OCSP data loader. This is the timeout for establishing a connection to the OCSP URI located in the certificate AIA extension.60000NOYES
OCSP_DATA_LOADER_TIMEOUT_SOCKETTimeout in milliseconds for socket of the OCSP data loader. This is the timeout for waiting for data after a connection to the OCSP URI located in the certificate AIA extension has been established.60000NOYES
ENCRYPTIONALGORITHMEncryption algorithm to use with the signature algorithm, for example RSASSA-PSS.Taken from the Subject Public Key Info of the signing certificate.NOYES
DIGESTALGORITHMDigest algorithm to use with the signature algorithm.SHA256NOYES
TRUSTED_CERTIFICATESContains list of PEM certificates to use as a trusted sources, additionally to the LOTL and TLs. This is the place where you need to provide your trusted certificates that are not part of the public trust list.LOTL and TLsNONO
Signed AttributesB-level parameters for a signature creation.NONENO
METADATA_PROPERTY_OVERRIDE_ALLOWEDContains list of comma-separated properties that are allowed to be overridden using metadata. The name of the property should match the name of the property in the configuration. For the properties that can be overridden, see the specific AdES Signer documentation.NONENONO
Alerts PropertiesAlerts configuration for signing process. You can configure alerts behavior for different types of issues and events occurring during the signing process, and how they should be handled.NONENO
EXCLUDE_SKIP_REVOCATION_EXTENSIONSComma-separated list of certificate extension OIDs for revocation data check skip that should be excluded. The following extensions are included by default:
  • 0.4.0.194121.2.1 - id_etsi_ext_valassured_ST_certs
  • 1.3.6.1.5.5.7.48.1.5 - id_pkix_ocsp_nocheck
  • 2.5.29.56 - noRevAvail
This property allows you to exclude specific extensions from the default list of extensions that are used to skip revocation data check. This is useful when you want to enforce revocation data check for certificates that contain these extensions.
NONENOYES

CRL caching​

Before enabling CRL_CACHE_ENABLED, keep in mind that:

  • The cache is shared by all workers in the same instance that enable it. Each worker applies its own limits, and a CRL that one of them refreshes is refreshed for all.
  • A CRL republished before its nextUpdate, for example after an emergency revocation, is not used until the cached copy expires, and only a restart clears the cache. Limit this with CRL_CACHE_NEXT_UPDATE_OFFSET, or with CRL_CACHE_MAX_NEXT_UPDATE_DELAY if every CRL in the chain is reissued within that delay.
  • Cached CRLs are held in memory, so allow enough heap for large CRLs.
  • For augmentors, keep caching disabled unless its effect on the ALERTS_NOREVOCATIONAFTERBESTSIGNATURETIME alert has been verified.