X-Git-Url: http://pere.pagekite.me/gitweb/homepage.git/blobdiff_plain/25e0cd197e5457c1b4546c1f750be8a61b638606..2303a53e3000b721cc73c3bfe81b6d2911b51a35:/blog/data/2014-03-25-trusted-timestamping.txt diff --git a/blog/data/2014-03-25-trusted-timestamping.txt b/blog/data/2014-03-25-trusted-timestamping.txt index 344846d579..c9ad9d3fe3 100644 --- a/blog/data/2014-03-25-trusted-timestamping.txt +++ b/blog/data/2014-03-25-trusted-timestamping.txt @@ -25,11 +25,13 @@ few years ago as RFC 3161. The mechanism is simple. Create a hash of the file in question, send it to a trusted third party which add a time stamp to the hash and sign the result with its private key, and send back the -signed hash + timestamp. Anyone with the document and the signature -can then verify that the document matches the signature by creating -their own hash and checking the signature using the trusted third -party public key. There are several commercial services around -providing such timestamping. A quick search for +signed hash + timestamp. Both email, FTP and HTTP can be used to +request such signature, depending on what is provided by the service +used. Anyone with the document and the signature can then verify that +the document matches the signature by creating their own hash and +checking the signature using the trusted third party public key. +There are several commercial services around providing such +timestamping. A quick search for "rfc 3161 service" pointed me to at least DigiStamp, @@ -44,16 +46,18 @@ trusted third party is not compromised.
timestamp services available for everyone. I've been looking for one for a while now. But yesterday I found one over at Deutches -Forschungsnetzmentioned in +Forschungsnetz mentioned in a -blog by David Müller. I then found a good recipe on how to use -over at the -University -of Greifswald. The OpenSSL library contain both server and tools -to use and set up your own signing service. See the ts(1SSL), -tsget(1SSL) manual pages for more details. The following shell script -demonstrate how to extract a signed timestamp for any file on the disk -in a Debian environment: +blog by David Müller. I then found +a +good recipe on how to use the service over at the University of +Greifswald. + +The OpenSSL library contain +both server and tools to use and set up your own signing service. See +the ts(1SSL), tsget(1SSL) manual pages for more details. The +following shell script demonstrate how to extract a signed timestamp +for any file on the disk in a Debian environment:
#!/bin/sh