Security

What is a trusted timestamp, and why does a signature need one?

A trusted timestamp is an independent record of when you signed, made by an outside service that nobody involved in the document controls. Without one, the only proof of the signing time is your own computer's clock, and a clock can be wrong, or changed on purpose.

4 min read

In the Digital Signature tool there is a tick box called "Add a trusted timestamp". It is on by default.

Why the time matters at all

Imagine you sign a rental contract on the 3rd of March. Later there is an argument, and the other side says you actually signed it in June, after the rent went up.

How would anyone settle that?

The date printed on the page proves nothing. Anyone can type a date. The date inside the file is just what your computer's clock said at that moment, and a clock can be set to any date in a few seconds. So on its own, the signing time is only as trustworthy as the person who made it.

A timestamp fixes this by bringing in somebody with no interest in your contract.

What actually happens

A timestamp authority is a service that does one job: it keeps very accurate time and it signs statements about it. Think of it like the post office date stamp on an envelope. You did not choose the date; the post office did, and everyone accepts it because the post office has no reason to lie about your letter.

When the option is on, this is the order of events:

  1. You sign the document with your certificate.
  2. A short fingerprint of that signature (not the document, not a single word of its contents) is sent to the timestamp authority.
  3. The authority signs it together with its own clock reading and sends the result back.
  4. That receipt is tucked inside the PDF, next to your signature.

Why you would want it on

Because certificates expire, and signatures should not.

Your certificate (the digital ID that makes the signature) has an expiry date, usually one to three years away. After that date, a checker looking at your signed contract has a problem: was this signed while the certificate was still valid, or after it ran out?

With a trusted timestamp, the answer is in the file: *signed on this date, and on that date the certificate was fine*. Without one, a checker has only your computer's word for it, and many readers will show a warning or refuse to say the signature was valid at signing time.

It also matters because a timestamp is the foundation for the other two long-term options. In the tool you will notice that long-term validation and the archive timestamp switch themselves off when you turn the timestamp off. That is not a quirk. They are built on top of it.

What happens if you leave it off

The signature still works. It still proves the document has not been changed and who signed it. The tool's own hint says it plainly: "The signing time comes from this server's clock only."

That is often perfectly fine:

  • an internal approval that everyone will act on this week,
  • a document you are signing as a test,
  • anything where the date is already recorded somewhere else that people trust.

It is a poor idea for:

  • contracts, tenders, invoices and anything that may still matter in five years,
  • documents you must file with an office that checks signatures properly,
  • anything where the exact date could be argued about.

The everyday version

Two ways to prove you posted a letter on time:

  • No timestamp: you write the date on the envelope yourself and swear it is right.
  • Timestamp: the post office stamps the envelope as it takes it.

Both are real. Only one of them settles an argument.

Does it slow things down?

Adding a timestamp means one quick call to an outside service while the document is being signed. If that service cannot be reached, the tool tells you rather than quietly pretending it worked. The result page always reports what actually happened, not what you asked for.

How to tell whether a PDF has one

Open it in Verify PDF Signature. In the list of status rows there is a line called Timestamp. It says Valid, Invalid, or None. "None" means the signing time in that file is only the signer's own clock.

Common questions

What is a trusted timestamp on a PDF signature?

It is a signed record from an independent time service saying when the signature was made. Because the service is outside the document and nobody involved controls it, the signing time no longer depends on the signer's own computer clock.

Does the timestamp service see my document?

No. Only a short mathematical fingerprint of the signature is sent. That fingerprint cannot be turned back into the document, so the service never learns what you signed.

Should I leave 'Add a trusted timestamp' switched on?

Yes, for anything that might matter later. It is on by default. Turn it off only when the date genuinely does not matter, because the two long-term options depend on it.

What happens to my signature when my certificate expires?

With a trusted timestamp, a checker can see the signature was made while the certificate was still valid, so it can still be judged correctly. Without one, there is no independent proof of when you signed, and readers may refuse to confirm the signature was valid at the time.

Is a timestamp the same as a digital signature?

No. A digital signature says who signed and that nothing has changed. A timestamp only says when something existed. They are usually used together, and one timestamp cannot replace a signature.

How do I check whether a signed PDF has a timestamp?

Open it in Verify PDF Signature. The status rows include a Timestamp line that reads Valid, Invalid or None.