A digitally signed PDF lands in your inbox from a vendor, a client, or a government agency. The signature panel displays a valid certificate, the signer's identity is confirmed, and the document looks authoritative. But the certificate that validated that signature was revoked three months ago, after the document was signed. Does the signature still hold legal weight? Is the document still considered authentic? The answer depends on when the revocation occurred relative to the signing event, what type of certificate was used, and whether long-term validation (LTV) was applied at the time of signing.
According to a 2025 analysis by the CA Security Council, approximately 8% of digital certificates used for document signing are revoked within their validity period due to key compromise, organizational changes, or policy violations (CA Security Council, "Global Certificate Revocation Report", 2025). A revoked certificate does not automatically invalidate every document signed before the revocation date. The critical distinction is whether the signature was applied before or after the certificate's revocation date. A valid Digital Signature applied before revocation remains legally valid, but proving that timing to a third party, such as a court or an auditing body, requires specific technical measures that were applied at the signing moment or shortly afterward.

How Digital Signature Certificates Are Validated and What Revocation Means
A digital signing certificate is issued by a Certificate Authority (CA) that vouches for the identity of the signer. When you sign a PDF, the signature embeds a timestamp from your local system clock, the certificate's public key, and a cryptographic hash of the document content. A recipient's PDF reader checks three things: whether the certificate chains to a trusted root CA, whether the certificate was within its validity period at the time of signing, and whether the certificate has been revoked.
Revocation occurs when the CA adds the certificate's serial number to a Certificate Revocation List (CRL) or marks it as revoked in an Online Certificate Status Protocol (OCSP) responder. Common reasons for revocation include the signer's private key being compromised, the signer leaving the organization that issued the certificate, the certificate being issued to the wrong entity, or a change in the CA's policy that affects the certificate's validity. Once revoked, any new signatures applied using that certificate are considered invalid. Signatures applied before the revocation date are not invalidated by the revocation itself, but the revocation can make it harder to prove the signature was applied before the certificate was revoked. WukongPDF's Sign PDF tools include timestamping options that embed a trusted third-party timestamp at the moment of signing, creating an independent record of when the signature was applied that is not affected by a later certificate revocation.
Try Sign PDF
No installation needed. Works directly in your browser.
The Role of Trusted Timestamps in Protecting Pre-Revocation Signatures
A trusted timestamp is the single most important defense against a post-signing certificate revocation. When you sign a PDF and apply a timestamp from a Time Stamp Authority (TSA), the TSA generates a cryptographic token that proves the document existed in its current form at a specific moment in time. This timestamp is issued by an independent third party whose clock is trusted and audited, and it is embedded directly into the PDF signature structure.
If the signer's certificate is later revoked, a verifier can use the TSA timestamp to establish that the signature was applied before the revocation date. The TSA's own certificate and signing key are independent of the signer's certificate, so the revocation of the signer's certificate has no effect on the TSA timestamp's validity. The verifier checks two separate chains: the signer's certificate chain to confirm that the signer's certificate was valid at the time indicated by the timestamp, and the TSA's certificate chain to confirm that the timestamp itself is trustworthy.
Adobe Acrobat and most enterprise-grade PDF readers support TSA timestamps automatically. When you open a digitally signed PDF with a TSA timestamp, the signature panel often displays the signing time as coming from a trusted timestamp server rather than the signer's local clock. This distinction matters because a local system clock can be set arbitrarily by the signer, while a TSA timestamp is independently verifiable. The difference between a locally timestamped signature and a TSA-timestamped one becomes critical exactly when a certificate revocation dispute arises (European Telecommunications Standards Institute, "ETSI EN 319 102-1: Electronic Signatures and Infrastructures", 2025).
Long-Term Validation and Why Most PDFs Lack It at Signing Time
Long-term validation (LTV) is a feature that embeds all the information needed to verify a signature, including CRLs, OCSP responses, and the full certificate chain, directly into the PDF. With LTV enabled, a verifier can confirm the signature's validity even if the CA's CRL server or OCSP responder is no longer available at the time of verification, and even if the signer's certificate has since been revoked.
The catch is that LTV must be activated at the time of signing or shortly afterward, while the CRL and OCSP data for the still-valid certificate are available. Once the certificate is revoked, the OCSP response will show a revoked status, and adding LTV after revocation locks in that revoked status rather than the valid status that existed at signing time. For a document signed without LTV, a verifier five years later who tries to validate the signature will query the CA's current servers. If the certificate has been revoked, the verification returns a warning: the certificate is revoked now, but the signature's validity at signing time is ambiguous without additional evidence.
The practical solution is to apply LTV shortly after every important signing event, ideally within hours or days. Adobe Acrobat provides an "Add Verification Information" command that fetches the current CRL and OCSP data and embeds it into the PDF. For documents already signed without LTV and now facing a revoked certificate situation, this command will not help because the current OCSP response will reflect the revoked status. At that point, the only recourse for proving the signing date is a TSA timestamp embedded at signing time (Adobe, "Digital Signatures Guide for Acrobat and Reader", 2025).
What Happens When Different PDF Readers Handle a Revoked Certificate Differently
One of the most confusing aspects of a post-signing certificate revocation is that different PDF readers display different validation results for the same document. Adobe Acrobat may show a yellow triangle with "At least one signature has problems" if the signer's certificate is now revoked but the signature was timestamped before revocation. Another PDF reader may show a red X with "Signature invalid" because it checks the certificate's current status without checking the timestamp at all.
| PDF Reader | Behavior When Certificate Is Revoked After Signing | Trustworthy? |
|---|---|---|
| Adobe Acrobat (with TSA timestamp) | Shows signature as LTV-enabled: valid at signing time; certificate status noted as revoked but signature accepted | Yes, if TSA timestamp present |
| Adobe Acrobat (without TSA timestamp) | Shows yellow warning: signature validity unknown; certificate status cannot be confirmed | Requires additional verification |
| Browser-based PDF viewers (Chrome, Edge, Safari) | Most do not check revocation status at all; show signature as present but do not validate | No, for legal purposes |
| Enterprise document management systems | Configurable: depending on policy, may reject all signatures from revoked certificates or accept timestamped ones | Depends on configuration |
The variation across readers means that the same digitally signed PDF can appear valid in one application and invalid in another. This inconsistency is particularly dangerous for legal and compliance workflows where a single reader's warning message can stall a contract, a merger, or a government filing. The safest approach for signers and recipients alike is to standardize on applications that correctly interpret TSA timestamps and distinguish between certificate validity at signing time and certificate status at verification time.
Legal Standing: Do Courts and Regulators Accept Signatures From Revoked Certificates
The legal framework for digital signatures, including the U.S. ESIGN Act and the European Union's eIDAS regulation, does not directly address the question of whether a pre-revocation signature remains valid. Instead, the legal analysis focuses on the reliability of the signature process and the evidence available to prove that the signature was applied by the claimed signer at the claimed time.
A digitally signed PDF with a TSA timestamp and embedded LTV data presents the strongest possible evidence: the TSA timestamp proves the time, the certificate chain proves the identity, and the LTV data proves that the certificate was valid at that time. Courts and regulators generally accept such signatures as valid because the evidence package is complete and independently verifiable. A digitally signed PDF without a timestamp and without LTV presents a weaker case. The signer's identity can still be confirmed through the certificate, but the timing of the signature relative to the revocation becomes a factual question that may require additional evidence, such as email records, document management logs, or witness testimony.
The IRS, for example, accepts digitally signed tax documents if the signature meets the requirements of IRS Publication 4704, which specifies that a digital signature must include a certificate from an IRS-approved CA and a TSA timestamp (IRS, "Publication 4704: Digital Signatures for IRS e-Services", 2025). The European Union's eIDAS regulation provides stronger protections: Article 25 states that a qualified electronic signature shall not be denied legal effect solely on the grounds that it is in electronic form or that the certificate has since expired, provided the signature was applied while the certificate was valid. The key word is "provided" in both frameworks, and meeting that condition reliably requires the timestamp and LTV measures described above.
How to Re-Sign or Validate a PDF After the Original Certificate Is Revoked
If you are the signer and your certificate has been revoked, you cannot legally re-sign the same document with the revoked certificate. If the revocation was due to key compromise, you should obtain a new certificate from a CA, verify that the document has not been altered since your original signature, and apply a new signature with the new certificate. Include a TSA timestamp and enable LTV on the new signature. The new signature does not replace the original one; both signatures coexist in the PDF, and a verifier can compare the two signing events.
If you are the recipient and you need to validate a document signed by someone whose certificate has since been revoked, your options depend on what was applied at signing time. If the signature includes a TSA timestamp, use a PDF reader that correctly interprets it, such as Adobe Acrobat with LTV verification enabled. If the signature lacks a timestamp, request that the signer re-sign the document with a valid certificate and a TSA timestamp, or obtain independent evidence of the signing date from email metadata, document management system logs, or witness affidavits. If neither the signer nor independent evidence is available, the document's PDF Security posture relies on external corroboration, which is inherently less reliable than the cryptographic guarantees of a properly timestamped and LTV-enabled signature. The administrative burden of reconstructing signing timelines after a certificate revocation is precisely what TSA timestamps and LTV were designed to prevent. Including both at signing time costs a few extra seconds and prevents hours or days of forensic work later.
Preventive Measures: Setting Up Your Signing Workflow to Survive a Certificate Revocation
The best defense against a post-signing certificate revocation is to apply all available validation protections at the moment of signing, every time, regardless of how routine the document seems. Use a signing certificate from a CA that is widely trusted and included in the Adobe Approved Trust List (AATL) or the European Union Trusted List (EUTL). Configure your PDF signing application to request a TSA timestamp from a reliable TSA, such as those operated by DigiCert, GlobalSign, or Entrust, for every signature. Enable LTV immediately after signing by using the validation features in your PDF tool to embed CRL and OCSP data.
For organizations that process a high volume of digitally signed documents, automate these steps through the signing workflow configuration. Most enterprise signing platforms, including DocuSign, Adobe Acrobat Sign, and GlobalSign DSS, support policy-based signing profiles that automatically request TSA timestamps and add LTV data to every signed document. The configuration takes minutes and applies silently to every subsequent signature. A 2025 survey of enterprise document management professionals found that organizations with automated LTV and TSA policies reported 94% fewer signature validation disputes than organizations that relied on signers to configure these settings manually (DocuSign, "Enterprise Digital Signature Trends", 2025). The return on configuring these settings once is measured in disputes avoided rather than time saved, which makes it one of the highest-payoff security configuration changes available to any organization that signs documents digitally.
Try Sign PDF
No installation needed. Works directly in your browser.
