Skip to main content
Known Participant
September 7, 2026
Question

does adobe reader/acrobat support self host sign CA with freetsa on LTV

  • September 7, 2026
  • 8 replies
  • 56 views

we use self host nextcloud with libresign on openssl. the certificate include crl path pass on curl and also use freetsa. all openssl and freetsa pem/crt import to reader trust store and also no error find on certificate detail. whatever we test only LTV is show not enable and all other status work fine. 

I have question does reader/freetsa support self host openssl or is that force to use DSS? 

 

    8 replies

    kajiroujiAuthor
    Known Participant
    September 9, 2026

    thank’s davidwarner11t and Anand Sri Bhattacharya reply. I check again my setting, find other error I overlook , now try to re-produce the issue. will post update

     

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    September 9, 2026

    ​@kajirouji Sure, we will wait for your response. 

    Thanks for your time and cooperation.

     

    Regards,

    Anand Sri.

    davidwarner11t
    Participating Frequently
    September 8, 2026

    Self-hosted OpenSSL is supported; you don’t have to use DSS. If LTV is the only part failing, check that the PDF actually embeds the full certificate chain and CRL/OCSP data in its DSS/revocation section. The Reader trust store alone usually isn’t enough for LTV validation.

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    September 7, 2026

    Hello @kajirouji


    I hope you are doing well, and thanks for reaching out. Sorry for the trouble you had.


    Could you please share more details?

    1. Which OS/platform are you using: A) Windows, B) macOS

    2. What exact Acrobat/Reader version and build is installed (from Menu Help > About Adobe Acrobat/Reader)?

    3. Is the PDF signature created by LibreSign/OpenSSL and then timestamped by your self-hosted FreeTSA-compatible RFC 3161 TSA, or is the signing workflow different?

    4. When you say “LTV shows not enabled,” what exact message/status does Acrobat display under Signature Properties > Show Signer’s Certificate/validation details?


    Please note that Acrobat supports certificates from trusted third-party providers, RFC 3161 timestamping, and PAdES long-term validation. Also, a timestamp can come from a third-party timestamp authority or the CA that issued the digital ID.

    Please check these articles for more information:

    https://adobe.ly/46a4cVu

    https://adobe.ly/4qXj4QH

    https://adobe.ly/4ynerlc


    If by DSS you mean the PDF Document Security Store, this is not an Adobe online service. It is a PAdES mechanism inside the PDF for storing certificates, CRLs, OCSP responses, and signature-specific VRI references. Adobe documents that LTV information can be stored there after signing without changing the existing signature. Check this article for more details: https://adobe.ly/4r0V0MI


    I hope this helps, and please reach out if you need any assistance.


    Regards,

    Anand Sri.

    kajiroujiAuthor
    Known Participant
    September 19, 2026
    1. use Windows OS 10

    2. Reader Ver: 2026.002.21931

    3. Yes, status granted on RFC 3161 compatible

    4. Only LTV not enable , Singer Identity is valid . CRL point to Self Host CRL URL, 
      Crul return 200

      Revocation Detail
      The selected certificate is considered valid because it does not appear in the Certificate Revocation List (CRL) that is contained in the local cache.

      The CRL was signed by "foo.com" on 2026/09/18 16:18:24 +08'00' and is valid until 2026/09/25 16:18:24 +08'00'.

      Self Host openssl CA , Freetsa CA, Freetsa Crt ,all import on trust certificate on Abobe reader 

    5. I exam the signed PDF is no DSS , Signed with SHA256

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    September 21, 2026

    ​@kajirouji Thanks for sharing the details.

     

    Suggestions: 

    Embed it at signing (the proper fix). Configure your signing pipeline (LibreSign/OpenSSL) to produce a PAdES-LT (or LTA) level signature, i.e. build the DSS containing: the full signer certificate chain, revocation data (your CRL, or OCSP) for every cert in the signer chain, and, just as important, the timestamp token's own full chain plus its revocation data. If LibreSign is currently producing only PAdES-B-T (signed + timestamped, no LTV data), that is exactly why there is no DSS, it needs to add the long-term-validation material.

     

    Embed it after signing in Acrobat/Reader. Open the signed PDF, open the Signature panel, right-click the signature, and choose "Add Verification Information." Acrobat then fetches and writes the chains, CRL/OCSP, and timestamp data into the DSS. Since your CRL already returns 200 and your certs are trusted, this should succeed, provided every endpoint is reachable at that moment: not just the signer's CRL, but the FreeTSA timestamp chain's revocation too (the TSA side is the most commonly missed piece). Also make sure "include signature's revocation status" is enabled (Preferences > Signatures > Verification). After it embeds, re-validate and LTV should flip to enabled.

     

    For more details, please check these articles: 

    https://helpx.adobe.com/acrobat/desktop/e-sign-documents/manage-digital-signatures/certify-pdfs.html

    https://helpx.adobe.com/acrobat/desktop/e-sign-documents/manage-digital-signatures/validate-digital-sign.html

     

    Regards,

    Anand Sri.