I am trying to sign a pdf with timestamp and LTV enabled so that it is shown like this in Adobe Reader:
In english it means that "the signature includes an embedded timestamp" and "the signature is LTV enabled". Here is the code I'm using:
PrivateKey pk = // get pk from an encrypting certificate created using encrypting file system
Certificate[] chain = ks.getCertificateChain(alias);
PdfReader reader = new PdfReader(src);
FileOutputStream fout = new FileOutputStream(dest);
PdfStamper stp = PdfStamper.createSignature(reader, fout, '\0');
PdfSignatureAppearance sap = stp.getSignatureAppearance();
ExternalSignature signature = new PrivateKeySignature(pk, "SHA-512", "SunMSCAPI");
TSAClient tsc = null;
String url = // TSA URL
tsc = new TSAClientBouncyCastle(url, null, null, 4096, "SHA-512");
List<CrlClient> crlList = new ArrayList<>();
crlList.add(new CrlClientOnline(chain));
ExternalDigest digest = new BouncyCastleDigest();
MakeSignature.signDetached(sap, digest, signature, chain, crlList, null, tsc, 0, CryptoStandard.CMS);
Based on this answer, I need a way to get CRL for the TSA Certificate to the CrlList, but.. how can I get the TSA Certificate? Do I need to make a timestamp-query request to the TSA and read response and then add it to CrlList? Note that this is already done inside MakeSignature.signDetached when it calls sgn.getEncodedPKCS7. Note that I am using a free TSA server.
This is what is shown in Adobe Reader with the code above.
Signature details:

UPDATE
Since it was a free TSA server, I just had to add the TSA server certificate in Adobe Trusted Certificates and now it works. But, I have made another test using a Smart Card to sign a document and here is what I got (I've added the root cert to the Trusted Certificates in Adobe):
Signature details:
Signing certificate details:
Based on this link, LTV enabled means that all information necessary to validate the file (minus root certs) is contained within the PDF. So, the PDF is LTV enabled if it is signed correctly and contains all necessary certificates and a valid CRL or OSCP response for every certificate, and also, if it includes signatures over CRLs and OCSPs, not just the signature certificate. It looks like I got all of those requirements or am I missing something? If so, how can I know what is missing to get a LTV enabled pdf?




