LTV enabled signatures not longer LTV enabled after update to Adobe DC 2018
Hello,
we are having a strange situation with different Adobe versions and what each version considers a LTV Enabled signature.
In 2017 we were signing PDF documents with a timestamp from a TA and the data from CRL and OCSP check embedded in the digital signatures. This resulted in a signed PDF document that Adobe displayed as : LTV Enabled . (unfortunately I cannot give you the version number of the Adobe DC instance used at that time)
We are having some problems with the OCSP service of the CA of our document signing certificate, so we have been signing with timestamp and CRL embedded only.
When viewed with Adobe 2017 (2017.12.20098 and 2017.12.20044) we have the following results for some test PDF's:
- No CLR/ No OCSP (only timestamp) -> Signature Valid / Not LTV Enabled
- CLR / NO OCSP -> Signature Valid / LTV Enabled
- No CLR / OCSP -> Signature Valid / Not LTV Enabled
- CRL / OCSP -> Signature Valid / LTV Enabled
So the presence of embedded CRL data is enough to get a LTV enabled signature. Notice how when only the OCSP is embedded we do not get an LTV Enabled signature.
When checking the *same* test PDF with Adobe DC 18 (2018.009.20044) : *none of the digital signatures are marked as LTV enabled* . An interesting note: when checking the "Revocation tab" only information about OCSP check is shown (embedded or fetched real time or present in local cache) : no more mention of the CRL data.
The following questions arise:
* how is this possible? First both OCSP and CRL data needed to be embedded, then only the CRL data and in the end no signature is considered LTV enabled.
* what has changed ? why has this changed? Is what is considered an LTV Enabled signature by Adobe subject to so many changes?
* how can a LTV enabled signature be placed?
If Adobe support staff wants more info: please contact me : I can send you screenshots and test PDF files.
best regards,
Loïc

