PDF Timestamps and Long-Term Validation with Dragdox
Premium adds a trusted timestamp and embeds certificate revocation data in the signature, so the signature can still be checked after the certificate expires. Both need a network connection while you sign.
Timestamp
With Timestamp selected, Dragdox asks a Time Stamping Authority (TSA) for an RFC 3161 timestamp and adds it to the signature. The default server is http://timestamp.comodoca.com; change it in Settings → Security → Timestamp Server. If the server cannot be reached, signing stops with a “Timestamping failed” message instead of creating a signature without the timestamp you asked for.
Long-term validation (LTV)
With LTV selected, Dragdox downloads the certificate revocation lists (CRLs) published in your certificate chain (each certificate’s CRL distribution points) and embeds them in the signature. This is best effort: if a list cannot be downloaded, signing continues with the lists that were available. Dragdox does not embed OCSP responses. Embedded lists make the signed file larger.
If you connect through a proxy, set it in Settings → Security → Proxy Settings.
Good to know
- Timestamp and LTV are Premium features; the free version signs without them.
- Whether a portal, organisation or court accepts a signature depends on its own rules. LTV data helps later verification but does not guarantee acceptance.
Verify the result with the verification guide.
