PAdES: inside a signed PDF
From SHA-256 digest to PAdES profiles and RFC 3161 timestamps: what happens technically when a PDF is signed.
Published Sep 9, 2026 · Updated Oct 3, 2026 · 3 min read
What the demo PDF shows
Timestamp availability depends on the configuration and timestamp service. Do not infer qualification or a long-term validation level from the word “PAdES” alone: inspect the resulting file and project configuration.
PAdES (PDF Advanced Electronic Signatures) is the standard way to embed a cryptographic signature in a PDF. The file stays a readable PDF, and the signature travels with it: integrity, signer identity via an X.509 certificate, and a timestamp when a TSA is connected.
Why PAdES
A drawn signature image or a graphic stamp proves nothing technically. PAdES binds the PDF bytes to a private key: if a page changes later, the signature becomes invalid. That is what product and engineering teams should validate before discussing trust or legal recognition.
- The PDF still opens in Adobe, Preview and common viewers.
- Integrity can be verified outside your application.
- Legal strength depends on the certificate and framework, not on the format alone.
The technical chain
PDF document SHA-256 digest Signer certificate CMS / PKCS#7 container PAdES profile (B-B → B-LT) RFC 3161 timestamp (optional)
Order of operations for a PAdES signature. The timestamp appears only when an RFC 3161 TSA is configured.
- Compute a hash (often SHA-256) over the PDF byte range that will be signed.
- Sign that digest with the private key tied to the signer certificate.
- Wrap the result as CMS/PKCS#7 and write it into a PDF signature field.
- A PAdES profile defines what is embedded (signature only, + timestamp, + validation data).
- If a timestamp authority is configured, an RFC 3161 token anchors the signature in time.
What the PDF viewer shows
Adobe Acrobat and other viewers walk the certificate chain to a trust anchor they know. With a self-signed test certificate, integrity can still look fine while identity shows as unverified. That is not a workflow bug: it signals that public trust is not connected yet.
B-B, B-T and B-LT profiles
PAdES profiles describe how far the signature remains verifiable over time. Pick the profile from the business need, not from marketing labels.
| Profile | What it adds | When to consider it |
|---|---|---|
| B-B | Baseline signature: document integrity | Immediate technical proof, no long-term requirement |
| B-T | Timestamp on the signature | Prove the signature existed at a given time |
| B-LT | Embedded validation data (LTV) | Re-open and verify the PDF long after signing |
General information, not legal advice. Confirm the requirements for your transaction with the appropriate adviser or receiving authority.
Does PAdES mean a qualified signature?
No. PAdES is a technical format. Legal strength depends on the certificate, party identification and applicable framework, not on the PAdES profile alone.
Why does Adobe warn on the demo PDF?
Usually because the certificate chain does not reach a publicly recognized trust anchor. That is typical for a self-signed test certificate: integrity can still validate while identity is not publicly trusted.
Is a timestamp always required?
Not for plain B-B. As soon as you must prove a signature existed at a given time, or target B-T / B-LT, an RFC 3161 TSA becomes relevant.