Supported facts from the available documentation are:
-
signtool timestampandsigntool signboth support RFC 3161 timestamping through the/troption. -
/trtakes aURLfor the RFC 3161 time stamp server. -
/tdmust be used with/trto request the digest algorithm, and SHA256 is recommended. -
/trcannot be used together with/t. - If
/tror/tis not present, the file is not time stamped. - If time stamping fails, SignTool generates a warning.
- For SDK, WDK, HLK, and ADK builds 20236 and later, SignTool requires specifying
/fdfor signing and/tdfor time stamping.
For an app package, time stamping must be done during the sign operation, not with the separate timestamp operation.
The available documentation does not provide:
- a statement that HTTPS is or is not supported for
/tr - any version-specific known issue for SDK
10.0.26100.0 - the internal validation rules that lead to
Invalid Timestamp URL - whether that error occurs before any network access
- any official issue identifier or corrected build for this behavior
- diagnostics that distinguish URL parsing failure from TLS or transport failure
- any documented effect of
/tp 0, trailing slash, proxy handling, architecture, or OS Authenticode components on this specific error
Based on the documented behavior alone, the only confirmed requirement for RFC 3161 is to use /tr <URL> together with /td <alg>, and not combine /tr with /t.
References: