[{"data":1,"prerenderedAt":125},["ShallowReactive",2],{"$kql3xGZSTAYZl":3},{"code":4,"status":5,"result":6},200,"OK",{"blocks":7,"title":114,"intro":115,"newsite":116,"introdisable":116,"related":117,"browser":118,"published":119,"updated":120,"tags":121,"author":122,"description":124},[8,14,20,24,29,33,38,42,46,50,54,58,62,66,70,74,78,82,86,90,94,98,102,106,110],{"content":9,"id":11,"isHidden":12,"type":13},{"text":10},"\u003Cp>Signing a document with a digital certificate means cryptographically binding the signer’s verified identity to the file at a particular point in time. This makes tampering with the document easily detectable after the fact, giving digitally signed documents legal standing under a variety of official government frameworks, like US Fed ESIGN and the European eIDAS.\u003C/p>\u003Cp>Up until now, it was possible to use email encryption S/MIME certificates to apply document signatures. This served as a convenient shortcut to requesting a dedicated document signing certificate, but it will no longer be possible, as the shortcut is now closed.\u003C/p>","1f946f57-aad0-4e3f-94bc-31d64570daa7",false,"text",{"content":15,"id":18,"isHidden":12,"type":19},{"level":16,"text":17},"h2","Why S/MIME No Longer Covers Document Signing","b85eda45-c13d-43cc-8570-0cf07bb40f3f","heading",{"content":21,"id":23,"isHidden":12,"type":13},{"text":22},"\u003Cp>S/MIME (Secure/Multipurpose Internet Mail Extension) certificates are email security SSL/TLS solutions whose primary purpose is to digitally sign outgoing mail. Doing so proves the sender’s identity and the fact that the message was not altered in transit, enabling end-to-end encryption.\u003C/p>\u003Cp>In September 2023, the CA/Browser Forum introduced the first version of the Baseline Requirements for S/MIME certification, formalising what they are permitted to do, which key usages they fit, and how they must be validated. Document signing was, predictably, not within the scope of these requirements.\u003C/p>\u003Cp>The consequence of this development is that Certificate Authorities (CAs) issuing S/MIME according to the new Baseline Requirements cannot include document signing functionality as part of the certificate. For anyone that might have relied on S/MIME for digital document signatures, it is now necessary to procure a purpose-built document signing certificate, instead.\u003C/p>","5d608c99-263f-44e9-b39f-f9d3e72dc169",{"content":25,"id":28,"isHidden":12,"type":19},{"level":26,"text":27},"h3","What Does a Document Signing Certificate Do?","52a44ad6-9737-4144-b6ee-4c411593ba57",{"content":30,"id":32,"isHidden":12,"type":13},{"text":31},"\u003Cp>A document signing certificate is an X.509 digital certificate issued exclusively for document-signing Extended Key Usage. Applying a signature to a document using one of these certificates does the following:\u003C/p>","57773b9a-a38c-48e6-a1c2-07501310f547",{"content":34,"id":36,"isHidden":12,"type":37},{"text":35},"\u003Cul>\u003Cli>\u003Cp>Generates a cryptographic hash of the document&rsquo;s content.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Encrypts the hash using your private key.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Creates a digital signature according to the encrypted hash.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Embeds the signature and the certificate into the document.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Applies a trusted timestamp from your CA&rsquo;s RFC 3161 timestamping server.\u003C/p>\u003C/li>\u003C/ul>","a9ef5f8b-df9b-46df-8c42-778c9fbf6bee","list",{"content":39,"id":41,"isHidden":12,"type":13},{"text":40},"\u003Cp>Upon opening the signed document in a compatible document viewer (i.e. Adobe Acrobat, Microsoft Word), the viewer’s application will:\u003C/p>","1053cf58-1e73-4675-9808-e958fce5998e",{"content":43,"id":45,"isHidden":12,"type":37},{"text":44},"\u003Cul>\u003Cli>\u003Cp>Recompute the applied hash.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Decrypt the embedded signature using your CA&rsquo;s public key.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Verify the CA&rsquo;s signature against its trusted root store.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Confirm that the timestamp had been applied during your certificate&rsquo;s active validity period.\u003C/p>\u003C/li>\u003C/ul>","762a1a2d-e1a5-4b87-9765-d2fc62cbcd3b",{"content":47,"id":49,"isHidden":12,"type":13},{"text":48},"\u003Cp>If everything goes well and the document hasn't been tampered with, there will be an indicator of a trusted signature visible in the user interface. If any part of the verification chain fails, however, a warning will be raised instead.\u003C/p>","30a88f2d-38ed-4c41-af97-4bfaebba47b5",{"content":51,"id":53,"isHidden":12,"type":19},{"level":26,"text":52},"Hardware Security Requirements","880e35c1-2c53-4d9d-9313-4ac899aac0eb",{"content":55,"id":57,"isHidden":12,"type":13},{"text":56},"\u003Cp>Document signing certificates issued by public Certificate Authorities now require the private signing key to be stored on a Hardware Security Module (HSM) or an equivalent tamper-resistant device. This follows the trend set by the CA/Browser Forum’s June 2023 decisions about code signing certificates, where HSMs are also required.\u003C/p>\u003Cp>Examples of how an HSM might be deployed are:\u003C/p>","94718981-e1ca-47c6-9393-c1bb3755a94b",{"content":59,"id":61,"isHidden":12,"type":37},{"text":60},"\u003Cul>\u003Cli>\u003Cp>Pre-configured, pre-encrypted eToken USBs shipped to a verified address.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Dedicated Hardware Security Modules for organisation-level deployments.\u003C/p>\u003C/li>\u003Cli>\u003Cp>Cloud-based HSMs for situations where remote or multi-user access is necessary.\u003C/p>\u003C/li>\u003C/ul>","ea225680-31a8-4f00-96d1-1c7a4885cb62",{"content":63,"id":65,"isHidden":12,"type":13},{"text":64},"\u003Cp>Hardware storage ensures that the private key cannot be exported or used without physical possession of the device and the correct password. This results in an automatic multi-level authentication built into the signing workflow, significantly increasing the level of security that document-signing certificates can guarantee.\u003C/p>","d67edd87-197e-4714-a162-52c8cc3bfc11",{"content":67,"id":69,"isHidden":12,"type":19},{"level":16,"text":68},"Different Types of Document Signing Certificates","160f783b-9ff3-4d0e-9382-9d747abc15ed",{"content":71,"id":73,"isHidden":12,"type":13},{"text":72},"\u003Cp>Document signing certificates are available across three different validation profiles:\u003C/p>","15e2ac77-07eb-4ec1-957d-9eebde35fc47",{"content":75,"id":77,"isHidden":12,"type":19},{"level":26,"text":76},"Document Signing for Individuals","c0aaabe2-e78a-4594-97ee-49fafbb86552",{"content":79,"id":81,"isHidden":12,"type":13},{"text":80},"\u003Cp>\u003Ca href=\"/digicert-ssl/individual-document-signing-certificate\">Individual Validation (IV) certificates\u003C/a> display a specific person’s verified identity. This level of validation is achieved through a notarised identity declaration or, in some cases, a video call. It’s suitable for independent professionals, sole traders, and anyone else who needs to sign documents in a personal capacity.\u003C/p>","d6b57346-792a-4a79-8157-8e906c4061fd",{"content":83,"id":85,"isHidden":12,"type":19},{"level":26,"text":84},"\u003Ca href=\"/digicert-ssl/employee-document-signing-certificate\">Document Signing for Employees\u003C/a>","3026375b-b767-4430-8ea2-3884f554d0fc",{"content":87,"id":89,"isHidden":12,"type":13},{"text":88},"\u003Cp>Organisation Validation (OV) is issued to corporate-affiliated individuals, verifying both their identity and their organisational connection. These document signing certificates are most appropriate for environments where individual accountability is important within the context of a specific organisation. Think legal teams, procurement operations, government offices, financial services, etc.\u003C/p>","f0c8bca0-baf7-4f95-b63a-188f02f61ba0",{"content":91,"id":93,"isHidden":12,"type":19},{"level":26,"text":92},"\u003Ca href=\"/digicert-ssl/organisation-document-signing-certificate\">Document Signing for Organisations\u003C/a>","e90097b9-9556-4ac3-9ea7-0687657d9943",{"content":95,"id":97,"isHidden":12,"type":13},{"text":96},"\u003Cp>Organisation Validation (OV) is issued company-wide, displaying the corporation name as the designated signer. Purpose-built for organisations that need to sign documents on behalf of the entire business entity. Examples include contracts, invoices, official correspondence, and such. Issuance can take up to three business days, though certain Certificate Authorities support instant provisioning with some caveats.\u003C/p>","365679d9-cf0b-47ed-a474-8895dd821fa7",{"content":99,"id":101,"isHidden":12,"type":19},{"level":16,"text":100},"Cross-Platform Coverage With SSLTrust","653fbcc6-c847-47bd-b6ff-25c666d56788",{"content":103,"id":105,"isHidden":12,"type":13},{"text":104},"\u003Cp>SSLTrust’s \u003Ca href=\"/document-signing-certificates\">document signing certificates are issued by DigiCert\u003C/a>, a Certificate Authority with memberships in both the Microsoft Trusted Root Program and the Adobe Approved Trust List (AATL). This means that all signatures applied using SSLTrust DigiCert certificates are automatically recognised as authentic and trusted without any manual intervention on the user’s part.\u003C/p>\u003Cp>\u003Cbr>As the RFC 3161 timestamp is signed by DigiCert’s timestamping server and embedded into documents at the time of their signature, the file will continue to validate even after the certificate itself has expired. These documents gain Long-Term Validation (LTV) status, which preserves their legal enforceability for years or decades to come.\u003C/p>","e8099c2e-dcc7-445d-bcc2-6e39c9603634",{"content":107,"id":109,"isHidden":12,"type":19},{"level":16,"text":108},"Growing Pains, Better Security","54fa814c-5631-4c33-8194-2ad9d74c5991",{"content":111,"id":113,"isHidden":12,"type":13},{"text":112},"\u003Cp>The new S/MIME Baseline Requirements from the CA/B Forum indicate broader trends toward tighter scoping and bespoke, purpose-built certification across the board. Document signing now has its own dedicated certificate type, with hardware requirements and a fresh trust chain. The end result is that signed documents will be more reliable and defensible across the board.\u003C/p>\u003Cp>Those who relied on S/MIME solutions for document signing up until now will have to make the transition to document signing certificates, but the trustworthiness reward for doing so is substantial.\u003C/p>","26c0b0f6-e6ee-4526-a63d-0d52bb950f5c","What is a Document Signing Certificate, and Why it Breaks an Age-Old Precedent","How strict industry standards now separate document and email signing, and what that means for your organisation.","false",[],"What is a Document Signing Certificate? We explain them and how they work","7 August 2026",null,"Articles",{"id":123},"rSGuMHwF","Signing a document with a digital certificate means cryptographically binding the signer’s verified identity to the file at a particular point in time.",1786077322635]