GroupDocs.Signature can add a trusted time stamp to a PDF digital signature. The time stamp comes from a time-stamp authority (TSA) that implements RFC 3161. It proves when the document was signed, which matters once the signing certificate expires: a validator can then check that the certificate was valid at the signing time.
Here are the steps to sign a PDF document with a time stamp:
using(Signaturesignature=newSignature("sample.pdf")){PdfDigitalSignaturepdfDigitalSignature=newPdfDigitalSignature(){// The time-stamp authority to contact. The user name and password are optional:// set either, both or neither, depending on what the time-stamp authority requires.TimeStamp=newTimeStamp("https://freetsa.org/tsr","","")};DigitalSignOptionsoptions=newDigitalSignOptions("certificate.pfx"){Password="1234567890",Signature=pdfDigitalSignature};signature.Sign("signed.pdf",options);}
How the time stamp is requested
The time-stamp authority is contacted while the document is signed, so the signing machine must be able to reach it. The request contains a hash of the signature, not the document.
The time stamp uses the same digest as the signature: SHA-256 by default, or the value of HashAlgorithm.
The user name and password are sent with HTTP Basic authentication, so use an https:// address. Starting with GroupDocs.Signature for .NET 26.9, they are sent when either of them is set; earlier versions sent them only when both were set.
If the time-stamp authority cannot be reached or rejects the request, Sign throws GroupDocsSignatureException and the document is not signed.