Signature Validation
Proof That Survives Time
Creating a legally strong signature is only the first step.
Signature validation confirms that the signature is authentic, the document is intact,
and the evidence remains usable — today and decades from now.
Integrity check
Certificate path
Revocation (OCSP/CRL)
Long-term levels
What is signature validation?
Signature validation is the process of verifying that an electronic signature is cryptographically correct,
that the certificate was valid at the time of signing, that it has not been revoked, and that the signed
data has not been altered. For long-term use, additional evidence must be preserved so the same checks
can still succeed years later.
Cryptographic integrity
The signature value matches the signed data. Any change to the document after signing is detected.
Certificate path validation
The certificate chain leads to a trusted root (typically a QTSP listed on the EU Trusted List).
Revocation status
At the claimed signing time the certificate was not revoked (checked via OCSP or CRL).
Time & policy
A qualified timestamp proves when the signature was created. Signature policy constraints are respected.
Why validation is critical for banks
Loan, mortgage and guarantee documents routinely need to remain enforceable for 10–30 years or longer.
Certificates expire
End-entity certificates (especially short-lived one-time certificates) expire quickly. Intermediate and root certificates also have finite lifetimes.
Revocation services disappear
OCSP responders and CRL distribution points may become unavailable years after the signature was created.
Algorithms age
Cryptographic algorithms considered secure today may be weakened in the future. Evidence must be protected against this risk.
Audit & dispute
Regulators, auditors and courts require reliable proof that a signature was valid at the time it was applied and that the document has remained intact.
PAdES / AdES long-term validation levels
ETSI standards define progressive levels that embed more validation material into the signed document.
Higher levels allow verification without relying on external services that may no longer exist.
B-B
Baseline signature + signer’s certificate.
- Valid only while the certificate is still valid
- Requires external status checks
- Not suitable for long retention
B-T
Adds a qualified timestamp proving the time of signing.
- Establishes reliable signing time
- Still depends on external revocation data
- Better, but still short- to mid-term
B-LT
Embeds the full certificate chain and revocation data (OCSP/CRL) inside the document.
- Verifiable from the file alone
- No need for external services at validation time
- Recommended for multi-year retention
B-LTA
Adds an archive timestamp that seals all previous validation material. Renewable over time.
- Protects against algorithm obsolescence
- Supports decades-long retention
- Best practice for mortgages & guarantees
How rSign prepares signatures for validation
Every rSign module is designed to produce signatures that are ready for verification and long-term archiving.
Qualified timestamp
Signatures are sealed with a qualified timestamp (or timestamp from a trusted TSA). This provides reliable proof of the time of signing — a foundation for any later validation.
PDF/A & PAdES
Signed documents are delivered in formats suitable for long-term preservation (PDF/A family) and can carry PAdES signature structures that support LT / LTA levels.
Full evidence package
Certificate information, identification records (where applicable) and process metadata form a complete audit trail that supports both technical and legal validation.
One-time certificates & short validity
For OQES and IQES the short-lived nature of the certificate is compensated by immediate timestamping and the ability to embed validation data for future verification.
What a complete validation examines
1. Signature integrity
Cryptographic verification that the signed data has not been altered after the signature was applied.
2. Certificate validity at signing time
Confirmation that the signing certificate was within its validity period at the claimed time of signing.
3. Trust path to a QTSP
The certificate chain must terminate at a trust anchor belonging to a QTSP listed on the EU Trusted List (for QES).
4. Revocation status
Evidence (OCSP response or CRL) that the certificate had not been revoked at the time of signing.
5. Timestamp validation
Verification of the qualified timestamp that anchors the signature in time.
6. Long-term material (if present)
For LT / LTA signatures: presence and integrity of embedded certificates, revocation data and archive timestamps.
Benefits of validation-ready signatures
Dispute resistance
Strong cryptographic and legal evidence significantly reduces the chance that a signature can be successfully challenged years later.
Regulatory confidence
Clear, standard-based evidence packages simplify responses to supervisors, auditors and internal risk functions.
Operational continuity
Documents remain verifiable even after original certificate authorities or revocation services are no longer reachable.
Future-proofing
Proper LTV practices (especially LTA with periodic renewal) protect against cryptographic algorithm obsolescence over multi-decade horizons.
Signatures that remain valid for decades
rSign produces Qualified Electronic Signatures and Advanced Electronic Signatures
with qualified timestamps and evidence structures designed for long-term validation and archiving.