CSC Remote Signature Provider

THPDFCSCSignatureProvider implements CSC API v2 credentials/info, credentials/authorize, credentials/authorizeCheck, signatures/signHash, signatures/signPolling, and signatures/timestamp on the existing THPDFSignatureProvider contract

Transport and authorization

The provider never selects an HTTP stack or stores a refresh token, client secret, PIN, or OTP

THPDFCSCTransport receives the exact method, URL, bearer authorization, JSON body, stable idempotency key, attempt number, operation identifier, and response budget, while THPDFCSCAccessTokenCallback supplies and refreshes short-lived OAuth access tokens

When SAD is required, the provider retrieves credential metadata and the complete bounded certificate chain, asks THPDFCSCAuthenticationCallback for reviewed authentication values, obtains a SAD, and polls an asynchronous authorization handle when necessary

Signing and replay safety

Sign accepts digest input from the CMS pipeline, carries the digest and signature OIDs into signatures/signHash, and emits DER-encoded RSA-PSS parameters when required

SignHashBatch sends an ordered same-algorithm digest batch under one authorization, pins the resulting SAD to the exact count, algorithms, parameters, and digest bytes, and preserves request order in synchronous and asynchronous results

A multi-digest call is accepted only when its count fits both MaxBatchSignatures and the credential multisign value, and the response must contain exactly one signature for every requested digest

Transient requests reuse a fixed-length SHA-256 content-addressed Idempotency-Key, while the bounded operation cache returns defensive copies of an already completed batch when the same operation, credential, parameters, and ordered digests are submitted again

A failed transport attempt retains an automatically authorized SAD for an exact retry, but a different batch cannot consume that SAD and must obtain a new authorization

Budgets and cancellation

THPDFCSCOptions.Default bounds batch signatures, response bytes, individual signatures, timestamps, certificate chain count and bytes, retry attempts, Retry-After delays, poll attempts, and cached operations

Cancel is observed before transport calls, between retries, and during short-sliced poll waits, and the operation identifier is also passed to the transport so an application can cancel its own in-flight HTTP request

Certificate chains and timestamps

RefreshCredentialInfo validates and caches key, algorithm, authorization, SCAL, multisignature, and certificate-chain metadata without signing

GetCertificateChain returns defensive byte copies suitable for the CMS certificate input, while TimestampDigest requests and decodes one RFC 3161 token with an optional nonce

Modern Signature Providers