eIDAS Signatures for Long-Term Archival (LTA) in C#
Learn how to easily create eIDAS-compliant PAdES, CAdES, XAdES, and ASiC-E digital signatures with embedded Long-Term Validation (LTV) and Archival (LTA) using the eIDAS Signature Library .NET.
We are offering the fully-featured eIDAS Signature Library .NET (SignLib) absolutely FREE to all customers who purchase a Qualified Timestamp package. Seamlessly integrate digital signatures and timestamps into your C# / .NET applications with zero additional licensing costs.
eIDAS Compliance (EU Regulation 910/2014)
To ensure absolute legal certainty across the European Union, electronic documents must guarantee origin authenticity and content integrity over many years, even after the signer’s certificate expires or is revoked. The eIDAS Signature Library .NET supports:
- Qualified Digital Certificates & Seals: Direct hardware integration for Smart Cards, USB Tokens, eToken, and HSMs (Qualified Signature Creation Devices – QSCD).
- Qualified Electronic Timestamps: Automatic RFC 3161 TSA integration to establish the exact time of signing.
- Long-Term Archival (LTA): Automatically embedding Revocation Information (CRL / OCSP) and appending archive timestamps to create PAdES-LTA, CAdES-LTA, XAdES-LTA, and ASiC-E LTA signature profiles.
1. PDF Documents: PAdES-LTA (Long Term Archival)
PAdES-LTA is the highest level of PDF signature security, proving the document was signed while the certificate was valid and protecting it for long-term archiving.
using System;
using SignLib.Pdf;
using SignLib.Certificates;
public void SignPdfPadesLta(string inputFile, string outputFile)
{
PdfSignature pdf = new PdfSignature(inputFile, outputFile);
// 1. Load Qualified Certificate / Seal (from Windows Store, Smart Card, or HSM)
pdf.DigitalSignatureCertificate = DigitalCertificate.LoadFromCertificateStore();
// 2. Configure RFC 3161 Qualified Timestamping Server
pdf.TimeStamping.ServerUrl = new Uri("https://tsaexample.com/myserver.aspx");
// 3. Set Long-Term Archival (LTA) standard with embedded CRL/OCSP
pdf.SignatureStandard = PdfSignatureStandard.PadesLTA;
// 4. Apply eIDAS Compliant Signature
pdf.Sign();
}
2. Binary Data & Archives: CAdES-LTA (.p7m / .p7s)
For non-PDF files (Word documents, images, databases, ZIP archives), use CAdES (CMS Advanced Electronic Signatures). CAdES-LTA appends archive timestamps to protect the signature mathematically for decades.
using System;
using SignLib.CAdES;
using SignLib.Certificates;
public void SignCadesLta(string inputFile, string outputFile)
{
CadesSignature cades = new CadesSignature(inputFile, outputFile);
// 1. Load Qualified Certificate / Seal
cades.DigitalSignatureCertificate = DigitalCertificate.LoadFromCertificateStore();
// 2. Set TSA for Long Term Archival timestamping
cades.TimeStamping.ServerUrl = new Uri("https://tsaexample.com/myserver.aspx");
// 3. Set CAdES-LTA (Archive) standard
cades.SignatureStandard = CadesSignatureStandard.CadesLTA;
// 4. Sign file (outputs standard .p7m or detached .p7s)
cades.Sign();
}
3. XML Data (e-Invoicing): XAdES-LTA
XML Advanced Electronic Signatures are heavily used in B2B integrations, EU e-invoicing systems (e.g., UBL/CII), and government reporting. XAdES-LTA embeds the timestamp and revocation data directly into the XML DOM tree.
using System;
using SignLib.XAdES;
using SignLib.Certificates;
public void SignXadesLta(string inputXml, string outputXml)
{
XadesSignature xades = new XadesSignature(inputXml, outputXml);
// 1. Load eIDAS Certificate
xades.DigitalSignatureCertificate = DigitalCertificate.LoadFromCertificateStore();
// 2. Configure Qualified Timestamping Server
xades.TimeStamping.ServerUrl = new Uri("https://tsaexample.com/myserver.aspx");
// 3. Set XAdES-LTA (Archive) standard
xades.SignatureStandard = XadesSignatureStandard.XadesLTA;
// 4. Sign XML structure securely
xades.Sign();
}
4. Associated Signature Containers: ASiC-E LTA (.asice)
ASiC-E binds together one or multiple files (like documents, datasets, or images) and their associated digital signatures into a single ZIP-based container. Using the ASiC-E LTA profile ensures that the entire container is timestamped and protected with revocation data for long-term archival, meeting the highest eIDAS requirements.
using System;
using SignLib.ASiC;
using SignLib.Certificates;
public void SignAsicELta(string inputFile, string outputAsice)
{
AsicSignature asic = new AsicSignature(inputFile, outputAsice);
// 1. Load eIDAS Certificate
asic.DigitalSignatureCertificate = DigitalCertificate.LoadFromCertificateStore();
// 2. Configure Qualified Timestamping Server
asic.TimeStamping.ServerUrl = new Uri("https://tsaexample.com/myserver.aspx");
// 3. Set ASiC-E LTA (Archive) standard
asic.SignatureStandard = AsicSignatureStandard.AsicELTA;
// 4. Sign and generate ASiC-E container (.asice / .sce)
asic.Sign();
}
Ready to implement eIDAS compliant signatures?
Buy any Qualified Timestamp packagee today and receive the full eIDAS Signature Library .NET with a lifetime developer license included for free.