Features & specifications

Built to the standard, engineered for production

TSA Server implements the timestamping protocol exactly as signing tools and validators expect it, and adds the operational features an internal authority needs: HSM-protected keys, your own policy identifiers and sustained throughput.

Compliance

RFC 3161 / 5816 compliant

Implements IETF RFC 3161 with the RFC 5816 update, producing tokens with ESSCertID and ESSCertIDv2 signing-certificate attributes — accepted by Adobe, Microsoft, Java and standard validation libraries.

Key protection

HSM-ready by design

Keep the TSA signing key in a hardware security module through PKCS#11, or use Windows key stores via MS-CAPI and CNG. Both RSA (up to 4096-bit) and elliptic-curve TSA certificates are supported, including ECC keys held on HSMs.

Performance

100 timestamps / second

Sustained token issuance at rates suited to bulk invoice and document signing, batch archiving jobs and organization-wide log sealing — on ordinary Windows server hardware, with IIS handling transport and TLS.

Technical specifications

Protocol IETF RFC 3161, RFC 5816 (ESSCertID, ESSCertIDv2) over HTTP / HTTPS
Hash algorithms SHA-256 · SHA-384 · SHA-512
TSA certificate keys RSA up to 4096-bit · Elliptic-curve certificates (incl. on HSM)
Key storage PKCS#11 (HSM) · CNG · MS-CAPI
Throughput Up to 100 timestamps per second
Client compatibility Adobe Acrobat (PAdES LTV / LTA), Microsoft Authenticode / signtool, Java JarSigner, OpenSSL ts, and any RFC 3161-compliant client or library
Certificate source TSA certificate issued by your own CA (e.g. AD CS) or any commercial CA — you control the chain and the policy OID
Deployment IIS application on Windows Server; runs in standard, DMZ, or fully offline / air-gapped networks
Requirements Windows with IIS · Microsoft .NET Framework 4.8
Current version 7.0 (June 2026)

Operational characteristics

Installs in minutes

Deployment is a standard IIS application: create the site, bind the certificate, select the signing key, and the endpoint is live. The installation manual walks through every step, including HSM configuration.

Fits your PKI, not the other way around

The server does not impose its own certificate hierarchy. Issue the TSA certificate from your existing enterprise CA, reuse your NTP infrastructure as the time source, and publish the endpoint under your own hostname and TLS certificate.

Transparent to existing tooling

Because the interface is plain RFC 3161 over HTTP(S), switching from a public TSA is a one-line configuration change in Adobe Acrobat, your document management system or your signing library — no client software to deploy.

Evaluate before you buy

The downloadable package is fully functional for testing, so you can validate throughput, HSM integration and client compatibility in your own environment before purchasing a license.

Questions about a specific setup?

Whether it's a particular HSM model, an ECC chain, or an unusual network topology — ask before you commit. Technical pre-sales answers typically arrive within one business day.