Skip to main content

rfc3161-client

rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161.

It is composed of three subprojects:

  • 🦀 tsp-asn1: A Rust crate using rust-asn1 to create the types used by the Time-Stamp protocol. This crate depends on rust-asn1 and cryptography to minimize the amount of duplicated code. While it is usable as a standalone crate, this is not officially supported. Drop us a message if you are interested in using it.
  • 🦀 rfc3161-client: Another Rust crate that provides Python bindings to the tsp-asn1 crate using PyO3.
  • 🐍 rfc3161-client A Python library using the crate above to provide a usable API to create Timestamp Request and read Timestamp Response.

Goals and anti-goals

  • This library should be correct and provide an accurate implementation of protocol described in the RFC 3161.
  • This library does not perform any network activity, it simply provides primitive to build and verify objects. Network activity must be handled separately.

Usage

There are two parts to timestamping: retrieving + verifying the timestamp.

1. Retrieving a timestamp

The below code uses requests to get the timestamp from the Identrust TSA server:

# /// script
# dependencies = [
#   "requests",
#   "rfc3161-client",
# ]
# ///
import requests
from rfc3161_client import (
    decode_timestamp_response,
    TimestampRequestBuilder,
    VerifierBuilder,
    VerificationError,
)

# the data to sign. Could be a hash or any message. Should be bytes
message = b"Hello, World!"

# build the timestamp request
timestamp_request = (
    TimestampRequestBuilder().data(message).build()
    # Note: you could also add .hash_algorithm(XXX) to specify a specific hash algorithm
)

# TSA servers must be RFC 3161 compliant (see https://github.com/trailofbits/rfc3161-client/issues/46
# for a list of working servers)
tsa_server = "http://timestamp.identrust.com"

# make the request, remember to set content-type headers appropriately
response = requests.post(
    tsa_server,
    data=timestamp_request.as_bytes(),
    headers={"Content-Type": "application/timestamp-query"},
)
response.raise_for_status()

# if successful, should give a valid TimeStampResponse object
timestamp_response = decode_timestamp_response(response.content)

Verifying a timestamp

The second part is to verify the timestamp, this is done against a set of root certificates. In this example, we'll Mozilla's list of root certs provided in the certifi package:

import certifi
from cryptography import x509
import hashlib


# get trusted root certs from certifi
with open(certifi.where(), "rb") as f:
    cert_authorities = x509.load_pem_x509_certificates(f.read())

# for each of the root certs we have, try to verify the TSR with it
root_cert = None
for certificate in cert_authorities:
    verifier = VerifierBuilder().add_root_certificate(certificate).build()
    try:
        verifier.verify_message(timestamp_response, message)
        root_cert = certificate
        break
    except VerificationError:
        continue

# if successful, the TSR was verified and we should have the root cert that signed this TSR :)
print("Here's the root cert that signed your TSR:")
print(root_cert)

License

Copyright 2024 Trail of Bits

Licensed under the Apache License, Version 2.0 (the "License");
you may not use this file except in compliance with the License.
You may obtain a copy of the License at

    http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software
distributed under the License is distributed on an "AS IS" BASIS,
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
See the License for the specific language governing permissions and
limitations under the License.

Authors

Trail of Bits

Metadata

Release files for rfc3161-client 1.0.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for rfc3161-client 1.0.9
File Size Uploaded
rfc3161_client-1.0.9.tar.gz 112.8 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for rfc3161-client 1.0.9
File
rfc3161_client-1.0.9-cp39-abi3-win_amd64.whl CPython 3.9 abi3 Windows x86-64 Details
rfc3161_client-1.0.9-cp39-abi3-win32.whl CPython 3.9 abi3 Windows x86-32 Details
rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_x86_64.whl CPython 3.9 abi3 Linux musl 1.2+ x86-64 Details
rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_i686.whl CPython 3.9 abi3 Linux musl 1.2+ x86-32 Details
rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_armv7l.whl CPython 3.9 abi3 Linux musl 1.2+ ARMv7l Details
rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_aarch64.whl CPython 3.9 abi3 Linux musl 1.2+ ARM64 Details
rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl CPython 3.9 abi3 Linux glibc 2.17+ x86-64 Details
rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_i686.manylinux2014_i686.whl CPython 3.9 abi3 Linux glibc 2.17+ x86-32 Details
rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_armv7l.manylinux2014_armv7l.whl CPython 3.9 abi3 Linux glibc 2.17+ ARMv7l Details
rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl CPython 3.9 abi3 Linux glibc 2.17+ ARM64 Details
rfc3161_client-1.0.9-cp39-abi3-macosx_11_0_arm64.whl CPython 3.9 abi3 macOS 11.0+ ARM64 Details
rfc3161_client-1.0.9-cp39-abi3-macosx_10_12_x86_64.whl CPython 3.9 abi3 macOS 10.12+ x86-64 Details

Total release size: 29.2 MB

Release files / rfc3161_client-1.0.9.tar.gz

Download URL rfc3161_client-1.0.9.tar.gz
Size 112.8 kB
Tags Source
SHA-256 checksum
How to use checksums
66997415086d2c6e5d57a2d315157b32a9c3f4f1312877ca8eb55e2e0ddf8ce4
BLAKE2b-256 checksum
How to use checksums
5653e2f526fb6957023180c928448e2dd71b03b35038c315aed2d12d9a77c3af
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-win_amd64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-win_amd64.whl
Size 2.4 MB
Tags CPython 3.9 Windows x86-64 abi3
SHA-256 checksum
How to use checksums
908f6a775da4bdce1d39f825a4431f389542696078ef3e4ed911a068bcaf1792
BLAKE2b-256 checksum
How to use checksums
d2a1b71d9f2071660a914e039061d3cdcad77b1cbccf7276bff073f95e8b4d1a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-win32.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-win32.whl
Size 2.0 MB
Tags CPython 3.9 Windows x86-32 abi3
SHA-256 checksum
How to use checksums
4d33f5aaec2974239e1c62a79a6fcf32506b09095482377a8b5be3a00fa67dfb
BLAKE2b-256 checksum
How to use checksums
d218fcb2f311b0b1754b0476165a4eae2929606007fc0ff0a575a65dbff2c0f6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_x86_64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_x86_64.whl
Size 2.6 MB
Tags CPython 3.9 Linux musl 1.2+ x86-64 abi3
SHA-256 checksum
How to use checksums
d4cf92f0e784ff02ff5ea1c574f8521f30953dc178092424126dbd8348034f93
BLAKE2b-256 checksum
How to use checksums
15416c48b05fc41a424ab3b0cb0515e77046707b498837411633fe7ce77812ee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_i686.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_i686.whl
Size 2.6 MB
Tags CPython 3.9 Linux musl 1.2+ x86-32 abi3
SHA-256 checksum
How to use checksums
8208999e94e1252e3f5f748f5efe59d3b9c308d04c7626be1becfbf3236c9de4
BLAKE2b-256 checksum
How to use checksums
ff54f0193b27f1a635aa336d19b48c296f133719cafb87e950de6eae4638a046
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_armv7l.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_armv7l.whl
Size 2.4 MB
Tags CPython 3.9 Linux musl 1.2+ ARMv7l abi3
SHA-256 checksum
How to use checksums
03be7ac7919c7f4c566076b07773b81b1f1b28d447fa91c6960fb5f82fac5bc1
BLAKE2b-256 checksum
How to use checksums
2bb2938e4df767a2ea6fae2bc8e8e0df52e1d70a32a082a13bdfdd6fac59dc32
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_aarch64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-musllinux_1_2_aarch64.whl
Size 3.0 MB
Tags CPython 3.9 Linux musl 1.2+ ARM64 abi3
SHA-256 checksum
How to use checksums
0ac247d5aa22f3514d1e284bdc547d2ad5f101e1e5d7f6db25db2ab3a0c59f06
BLAKE2b-256 checksum
How to use checksums
6e5443f89c8e004baade51943261b29f9dd866df3383f4554d5797a2568c2855
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 2.4 MB
Tags CPython 3.9 Linux glibc 2.17+ x86-64 abi3
SHA-256 checksum
How to use checksums
fac3f440a507555e684dc5daba75e33dc08f0f45fdefa48448f19001233a6b21
BLAKE2b-256 checksum
How to use checksums
11ae19139fee184916065705d660bad203b676dc40b449afff36f79818c59c4f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_i686.manylinux2014_i686.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_i686.manylinux2014_i686.whl
Size 2.4 MB
Tags CPython 3.9 Linux glibc 2.17+ x86-32 abi3
SHA-256 checksum
How to use checksums
614da494c6f8850c5d6d98c23bc291a4e4dbf2c3c9082d9907fa156f9e4a75c6
BLAKE2b-256 checksum
How to use checksums
c85779bf6a67cd4ca729b0b74e6fa79ebef84e6bc8657b85772df01a7d3b7b89
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_armv7l.manylinux2014_armv7l.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_armv7l.manylinux2014_armv7l.whl
Size 2.1 MB
Tags CPython 3.9 Linux glibc 2.17+ ARMv7l abi3
SHA-256 checksum
How to use checksums
d3cbf1991b6f3457efcb25e1d31179cac556112e6d3e65ec9e0fd70c6e9af90d
BLAKE2b-256 checksum
How to use checksums
3349154c3e80ac94e51b9d1097dab15b95f44aa593c395bd41775e4486a7d0a0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
Size 2.7 MB
Tags CPython 3.9 Linux glibc 2.17+ ARM64 abi3
SHA-256 checksum
How to use checksums
7b703b233dbee7228d117d5f1c118363c61d523fa6f018c9217c79e3c6684f86
BLAKE2b-256 checksum
How to use checksums
8ef34b69d47fd7f79238bf8db20902a30d28c908efc0d906fb57abcc89ac75e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-macosx_11_0_arm64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-macosx_11_0_arm64.whl
Size 2.4 MB
Tags CPython 3.9 abi3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
a7004edfbf1bb7ec7801978a39fa7a7fe385ca59673df90d7578079b6eba3b24
BLAKE2b-256 checksum
How to use checksums
88cfbcfb66eaeccdc076457451a6213360c840bcacd0e938e8507951be29373f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release files / rfc3161_client-1.0.9-cp39-abi3-macosx_10_12_x86_64.whl

Download URL rfc3161_client-1.0.9-cp39-abi3-macosx_10_12_x86_64.whl
Size 2.1 MB
Tags CPython 3.9 abi3 macOS 10.12+ x86-64
SHA-256 checksum
How to use checksums
5e619d7e28ffa3a46685923e6d6ba4ce2e74cb09a41c77995a0702cc1a533bc4
BLAKE2b-256 checksum
How to use checksums
922cb81b822bc067647aa291dc4ea71f052f994344934fc84d499759aec64cf8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 14, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

1.0.9 This release

13 release files

1.0.8

13 release files

1.0.5

13 release files

1.0.4

13 release files

1.0.3

13 release files

1.0.2

13 release files

1.0.1

13 release files

1.0.0

13 release files

0.1.2

13 release files

0.1.1

13 release files

0.1.0

13 release files

0.0.4

13 release files

0.0.2

13 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page