Should I validate an embedded timestamp in a PAdES signature when doing signature verification?
问题 I'm trying to understand if and how I should validate a PAdES signature with an embedded timestamp. This embedded timestamp is obtained from a timestamp authority (TSA). If the signature includes crl file or ocsp response, we should generally first validate the chain of certificates from the signature is not expired nor revoked at the date corresponding to this timestamp. As the timestamp from a TSA is also signed, I'm trying to figure out if I should also validate the chain of certificates