what about to start to working on a document that collects requirements for notary systems based also on TSAs?
In my opinion, the current TSP don't allows always the use of a time-stamp token as a proof-of-authorship, because the security analysis of the protocol don't address the possibility of a deliberate replay attack by a middleman replaying legitimate TS _requests_;...
document she wants to time-stamp; compute the hash over the signature of the signed data and set the messageImprint field of time-stamp request to the computed value (similarly to what is required in Appendix A, for the proof sign creation before corresponding certificate revocation).
Adrian Pickering/ Electronics and Computer Science University of Southampton, UK