Why doesn't the signature validator honour the id-etsi-extension-validityAssured-ST-1 extension in signing certificates
If a signing certificate has the extension `id-etsi-extension-validityAssured-ST-1` (defined in this etsi standard), adobe doesn’t honour the extension, but instead looks for LTV data for the signing certificate. Since none is present in the /DSS, Adobe states that the signers identity isn’t valid (because of expiration or not yet valid).
The proper behaviour should be that if the certificate has that extension, and its validity is within the signing time of the signature and covered by a time stamp, Adobe should validate the identity as trusted.
I’m aware that I can change the preferences for Signature validation to ignore document validation information, but this is a very blunt way to solve this. IMHO the validation should be able to make this distinction automatically.
Is there any plans to make changes to the signature validation process?
