Features & specifications
Built to the standard, engineered for production
TSA Server implements the timestamping protocol exactly as signing tools and validators expect it, and adds the operational features an internal authority needs: HSM-protected keys, your own policy identifiers and sustained throughput.
Compliance
RFC 3161 / 5816 compliant
Implements IETF RFC 3161 with the RFC 5816 update, producing tokens with ESSCertID and ESSCertIDv2 signing-certificate attributes — accepted by Adobe, Microsoft, Java and standard validation libraries.
Key protection
HSM-ready by design
Keep the TSA signing key in a hardware security module through PKCS#11, or use Windows key stores via MS-CAPI and CNG. Both RSA (up to 4096-bit) and elliptic-curve TSA certificates are supported, including ECC keys held on HSMs.
Performance
Up to 100 timestamps / second
Sustained token issuance at rates suited to bulk invoice and document signing, batch archiving jobs and organization-wide log sealing — on ordinary Windows server hardware, with IIS handling transport and TLS.
Technical specifications
| Protocol | IETF RFC 3161, RFC 5816 (ESSCertID, ESSCertIDv2) over HTTP / HTTPS |
|---|---|
| Hash algorithms | SHA-256 · SHA-384 · SHA-512 |
| TSA certificate keys | RSA up to 4096-bit · Elliptic-curve certificates (incl. on HSM) |
| Key storage | PKCS#11 (HSM) · CNG · MS-CAPI |
| Throughput | Up to 100 timestamps per second |
| Client compatibility | Adobe Acrobat (PAdES LTV / LTA), Microsoft Authenticode / signtool, Java JarSigner, OpenSSL ts, and any RFC 3161-compliant client or library |
| Certificate source | TSA certificate issued by your own CA or any commercial CA — you control the chain and the policy OID |
| Deployment | IIS application on Windows Server; runs in standard, DMZ, or fully offline / air-gapped networks |
| Requirements | Windows with IIS · Microsoft .NET Framework 4.8 |
| Current version | 7.0 |
Deployment & integration
Installs in minutes
Deployment is a standard IIS application: create the site, bind the certificate, select the signing key, and the endpoint is live. The installation manual walks through every step.
Fits your PKI, not the other way around
The server does not impose its own certificate hierarchy. Issue the TSA certificate from your existing enterprise CA and publish the endpoint under your own hostname and TLS certificate.
Transparent to existing tooling
Because the interface is plain RFC 3161 over HTTP(S), switching from a public TSA is a one-line configuration change in Adobe Acrobat, your document management system or your signing library — no client software to deploy.
Evaluate before you buy
The downloadable package is fully functional for testing, so you can validate throughput, HSM integration and client compatibility in your own environment before purchasing a license.
Questions about a specific setup?
Whether it's a particular HSM model, an ECC chain, or an unusual network topology — ask before you commit. Technical pre-sales answers typically arrive within one business day.