RFC 3161 timestamp
macOS app for PDF signing
Sign and verify PDF documents locally on macOS using digital certificates available in Keychain. The app writes a standard PDF signature field and supports visible signatures, RFC 3161 timestamping, and PAdES-oriented validation data.
RFC 3161 timestamp
Built for real PDF digital signatures, not just a visible stamp.
PAdES Studio writes signatures as incremental PDF updates so the original document bytes are preserved and existing signatures can remain verifiable.
Keychain signing
Select a signing identity from macOS Keychain and sign with a private key that remains under system control.
Visible signature
Add an optional page area, signature image, signer name, and signing time without changing the cryptographic signature model.
Timestamping and LTV
Use RFC 3161 timestamps and embed certificates, OCSP responses, or CRLs in the PDF Document Security Store when available.
Signature inspection
Review signature status, certificate chains, timestamps, DSS/VRI material, and detected or validated PAdES profiles.
Multiple signatures
Add another signature as a new document revision. Existing signatures are not rewritten and remain independently verifiable.
Local documents
PDF files are not processed on the developer's server. Network access is used only for optional TSA, OCSP, or CRL requests.
From opening a PDF to a verifiable signature.
The app supports everyday signing as well as archival workflows where timestamps and validation data matter.
Open a PDF
Open a document from the File menu, Open Recent, or by dragging it into the app window.
Select an area
Mark a place on the page for a visible signature, or skip selection for an invisible digital signature.
Choose a profile
Select the identity, metadata, PAdES profile, timestamp server, and LTV options required by the document.
Sign and verify
Save the signed copy, then inspect the signature status, certificates, and validation notes.
Supported PAdES-oriented outputs.
Higher profiles need more external data. The app reports when timestamps or long-term validation material cannot be obtained.
Support
Reference notes from the user guide for supported standards, limitations, troubleshooting, safety, and common questions.
Supported formats and standards
- PAdES Studio creates PDF signature fields with detached CMS/CAdES signatures.
- Supported profiles are PAdES-B-B, PAdES-B-T, PAdES-B-LT, and PAdES-B-LTA.
- RFC 3161 timestamps and DSS/VRI validation material are embedded when available.
Limitations
- Signing requires a certificate and private key available through macOS Keychain.
- PKCS#11-only tokens, some complex PDF structures, and signature removal are not currently supported.
- The app does not decide whether a signature is legally qualified.
Troubleshooting
- If no identity appears, check that the certificate has a private key, is not expired, and allows digital signatures.
- If timestamping or LTV fails, verify the TSA URL, network access, certificate chain, OCSP endpoints, and CRL URLs.
- If a file verifies as modified, compare it with the original and inspect Validation notes.
Safety notes
- Keep the original unsigned PDF whenever possible.
- Verify signed output before distribution, ideally also with an independent validator for important documents.
- Choose a timestamp authority appropriate for your compliance requirements.
- Protect your signing certificate and private key carefully.
FAQ
- Is a signature produced by PAdES Studio legally binding?
- PAdES Studio produces technically standard PAdES signatures. Legal effect depends on the certificate, trust provider, signing environment, TSA, jurisdiction, and document context.
- Can I sign with a smart card or hardware token?
- Yes, when the token exposes the certificate and private key through macOS Keychain. PKCS#11-only tokens are not currently supported.
- Do I need an internet connection to sign?
- PAdES-B-B can be signed offline. Timestamped, LT, and LTA profiles need TSA, OCSP, or CRL network access.
- Which TSA should I use?
- Use any RFC 3161 compliant TSA you trust. Regulated workflows may require a specific accredited TSA.
- Can I remove a signature from a signed PDF?
- No. PAdES Studio does not remove signatures from signed PDFs.
- Can I add a visible signature when I re-sign a signed document?
- Yes, if the selected rectangle is large enough. Existing signatures are preserved.
- Why does the strict validator show a lower profile than the detected one?
- The strict validator requires DSS, VRI, and archive timestamp material to be complete and verifiable, not merely present.
- Can I use PAdES Studio to verify a signature made by another tool?
- Yes. The Verify button can inspect signatures created by other PDF signing tools.
- Where are my signing settings stored?
- They are stored locally in app preferences, including certificate fingerprint, timestamp URL, profile, metadata, and visible-signature settings.
- What happens when I open a document from Finder while another one is loaded?
- The new document replaces the active document in the window. Source files are not modified.
For other questions or feedback, contact us at: info@cloudmakers.eu
Documents stay local.
PAdES Studio does not use a developer-operated server to process PDFs. Timestamping and LTV may contact only endpoints you configure or endpoints published in certificates.
