Security
What is revocation checking (OCSP and CRL), and why does it matter?
Certificates can be cancelled early, like a stolen bank card. Revocation checking is the step where a verifier asks the issuer whether this particular certificate was cancelled, by a quick single question (OCSP) or by downloading the issuer's cancellation list (CRL).
Every signature in Verify PDF Signature has a Revocation row, reading *Not revoked*, *Revoked* or *Not checked*. This page is about what that question is and why it is asked.
Why certificates get cancelled
A certificate has an expiry date, usually one to three years out. But things go wrong before then:
- Someone steals the private key, or a laptop holding it is lost.
- An employee leaves the company, and the ID issued to them in the company's name must stop working.
- The certificate was issued by mistake, to the wrong person or with the wrong details.
- The holder's details change: a company is renamed, a role ends.
In every case the issuer can revoke it: mark it cancelled before its expiry date.
The everyday version
Your bank card has an expiry date printed on it. If you lose it, you do not wait until that date. You ring the bank and have it cancelled today.
Now think of a shop. The date on the card looks fine. The only way to know the card was cancelled is to ask the bank, right there at the till.
That is revocation checking. The date is not enough; someone has to ask.
The two ways to ask
OCSP is the quick question. The checker finds a web address inside the certificate itself and asks about that one certificate: *is this still good?* The issuer replies with a small, signed answer. Fast, current, tiny.
CRL is the list. The issuer publishes a file of everything it has cancelled, and the checker downloads it and looks. Bigger and less immediate, but for a growing number of certificates it is the only method available. Some large issuers withdrew their OCSP services in 2025.
Our verifier tries OCSP first, then falls back to a CRL when there is no responder or the answer is not usable. Only a signed, verified answer counts; a reply whose signature does not check out is discarded rather than believed.
What each result means
Not revoked. The issuer was asked and said the certificate was fine. The strongest answer available.
Revoked. The certificate was cancelled. Take this seriously. It does not mean the document was altered (the signature may still be mathematically intact) but the identity behind it has been withdrawn. The headline sentence on the result will say so directly.
Not checked. We could not find out. Either the certificate names no cancellation service at all (common with self-signed IDs and small in-house authorities) or the service could not be reached. This is reported as not checked and never quietly turned into "good".
Why revoked does not always mean invalid
Here is a subtlety worth understanding.
Suppose a contract was signed in March, and the signer's certificate was stolen and cancelled in September. Was the March signature bad?
Probably not. It was made months before anything went wrong. This is exactly why a trusted timestamp matters: with one, the signing date is independently proved, and the March signature can be judged against what was true in March.
Without a timestamp, nobody can show the signature came first, and the cancellation casts doubt over the whole thing.
Revocation and long-term validation
Long-term validation is largely about this question. It collects the revocation answers at signing time and stores them in the file, so that in ten years nobody has to find a service that may no longer exist. When a certificate publishes no revocation information at all, LTV cannot be completed, and the tool says so, giving the reason.
What to do with a 'revoked' result
- Do not act on the document until you have asked the sender.
- Check the signing date and whether there is a valid timestamp.
- If it matters, ask the issuer when and why the certificate was revoked.
A revoked certificate on a document you were not expecting is one of the clearest warning signs there is.
Common questions
What does revocation mean for a certificate?
It means the issuer cancelled the certificate before its expiry date, usually because the key was compromised, the holder left, or it was issued in error.
What is the difference between OCSP and CRL?
OCSP asks the issuer about one certificate and gets a small signed answer back. A CRL is a published list of everything the issuer has cancelled, which the checker downloads and searches.
What does 'Revocation: not checked' mean?
The certificate names no cancellation service, or it could not be reached, so the question has no answer. It is reported honestly rather than assumed to be fine.
My document says the certificate is revoked. Is the signature worthless?
Not automatically. If the signature carries a trusted timestamp proving it was made before the cancellation, it can still be judged on what was true at that time. Without a timestamp, there is no way to show it came first.
Why can't a revoked certificate simply be detected from the file?
Because revocation happens after the certificate is issued and is recorded by the issuer, not in the certificate. Someone has to ask the issuer, or the answer has to have been stored in the file in advance.
How do I stop this being a problem for my own signatures?
Sign with a trusted timestamp and include long-term validation. That fixes the signing date and stores the revocation answers inside the file.