Security

What is LTV, and why does my signed PDF say the certificate expired?

Signing certificates last a year or a few, but signed documents are kept for decades. If a signature carries a trusted timestamp, checkers can confirm it was made while the certificate was still valid; if it also embeds the revocation information from that time (long-term validation, LTV), it can be checked even after the issuer's services are gone. Without them, a perfectly good old signature can show as expired or unknown.

5 min read

A contract signed four years ago opens today with a warning: the signer's certificate has expired, or validity is unknown, or Adobe says the signature is not LTV enabled. Nothing about the document has changed. So what did?

The calendar did.

The short answer

  • A certificate has an expiry date, usually one to three years after issue.
  • A signature made while the certificate was valid remains a valid signature after it expires. if a checker can tell when it was made.
  • A trusted timestamp is an independent authority's signed statement that the signature existed at a particular moment. With one, a checker can validate "as of the time of signing".
  • Long-term validation (LTV) goes further: it stores inside the PDF everything needed to check the signature later. The certificate chain and the revocation answers (OCSP responses or CRLs) as they were at signing time.
  • Without a timestamp, a checker has only the signer's own claim about the time, and many checkers will validate against today's date instead.

Why the signer's clock is not enough

Every signature can carry a signing time. But that time comes from the signer's own computer. It is a claim, not evidence. Someone with an expired or revoked certificate could simply set their clock back.

A trusted timestamp fixes that. At signing, the software sends a fingerprint of the signature to a timestamp authority, which returns a signed token saying "this existed at 10:42:17 UTC on this date". The token is embedded in the signature. Nobody can backdate it without breaking it.

That is why Verify PDF Signature shows the Signed time and the Timestamp row separately: the first is what the signature says; the second tells you whether an independent authority confirmed it (Valid, Invalid or None).

What revocation has to do with it

A certificate can be revoked before it expires, because its key was lost or stolen, or it was issued in error. Checkers ask the issuer's revocation service, either by OCSP (a live yes/no question) or a CRL (a published list of revoked certificates).

Two problems appear over time:

  1. The services disappear. Years later, the issuer may have stopped answering for expired certificates, or may no longer exist.
  2. "Revoked now" is not the question. What matters is whether the certificate was revoked when the document was signed. A certificate revoked in 2025 does not invalidate a signature timestamped in 2022.

LTV solves both by capturing the revocation answers at the time and storing them in the PDF.

What the different messages mean

"Certificate expired" or "Not valid yet"

In Certificate details, the validity dates are shown with Expired or Not valid yet when relevant. Expired on its own is not a problem for an old signature with a valid timestamp inside the certificate's validity period. Without a timestamp, a checker cannot prove the signature predates the expiry.

"Not valid yet" is more suspicious: it means the signing time is before the certificate's start date, which usually indicates a wrong clock or a manipulated time.

Adobe: "Signature is not LTV enabled and will expire after [date]"

Adobe is saying the signature does not contain everything needed to validate it after the certificate expires. It is a forecast, not a failure. Adobe's result also depends on its verification-time setting: validating at the secure time (timestamp) embedded in the signature, at the time the signature was created, or at the current time can produce different answers for the same file.

"Long-term validation: Present (not checked)" in our report

Verify PDF Signature reports whether LTV data is present in the file. Present (not checked) or Not included. It does not currently validate the stored revocation data itself, and says so rather than implying more. Where long-term validity matters formally, use the validator your jurisdiction or counterparty specifies as well.

"Revocation: Not checked"

The certificate names no revocation service, or the service could not be reached. That is not a failure. Common for self-signed and some company certificates, and for old certificates whose issuer no longer answers.

What you can do with an older signed PDF

If you received it

  1. Check it in Verify PDF Signature and look at Signature, Timestamp and the certificate dates together.
  2. Signature: Valid means the content has not changed. That is true forever, whatever the dates say.
  3. A valid timestamp inside the certificate's validity period means the signature was made while the certificate was good.
  4. If there is no timestamp and the certificate has expired, the integrity result still stands, but proving when it was signed needs other evidence. Emails, the date the file was received, an audit trail.

If you own it and need it to stay checkable

In Adobe Acrobat, you can often add the missing validation data to an existing signature: right-click the signature and choose Add Verification Information. That works only while the revocation services still respond, so do it early. Some archives go further and add a document timestamp periodically so the whole file stays provable even as older algorithms weaken.

If you are about to sign

Use a signature with a trusted timestamp (KovaPDF's Digital Signature adds one by default) and, where the counterparty requires long-term validity, a signing setup that embeds revocation data (often described as PAdES B-LT or B-LTA).

The PAdES levels in one table

LevelAddsWhy it matters
PAdES B-B (basic)The signature and signer's certificateIntegrity and signer, while the certificate is valid
PAdES B-TA trusted timestampProves when it was signed
PAdES B-LTRevocation data and chain stored in the fileCheckable after the issuer's services are gone
PAdES B-LTAA document timestamp over everythingKeeps it provable as algorithms age

When a signature's level can be read, our report shows it next to the hash algorithm (for example "PAdES B-T").

Common questions

My signed PDF says the certificate expired. Is the signature invalid?

Not necessarily. If the signature carries a valid trusted timestamp from while the certificate was still valid, it was made in time. Integrity (whether the content changed) is unaffected by expiry either way.

What does “not LTV enabled” mean in Adobe?

That the signature does not contain all the information needed to validate it after the certificate expires, such as a timestamp and stored revocation data. It is a warning about the future, not a sign that the document changed.

What is the difference between signing time and a timestamp?

The signing time comes from the signer's own computer clock and is only a claim. A trusted timestamp is issued by an independent authority and cannot be backdated without breaking it.

Can I make an old signature LTV enabled?

Often, while the certificate's revocation services still respond. In Adobe Acrobat, right-click the signature and choose Add Verification Information. Once those services are gone, the missing data can no longer be collected.

Does KovaPDF check LTV?

It reports whether long-term validation data is present in the signature. It does not currently validate the stored revocation data itself, and says so in the result.

The certificate was revoked after I signed. Is my signature still good?

If a trusted timestamp proves the signature was made before the revocation, it is generally treated as made with a valid certificate. Without a timestamp, that is much harder to prove.