Sign and Timestamp Files for Long-Term Archival (LTA)

eIDAS Signatures for Long-Term Archival (LTA) in PowerShell

Learn how to automate digital signatures and eIDAS qualified timestamps (PAdES-LTA, CAdES-A, and XAdES-LTA) directly from Windows PowerShell using the SignLib .NET library and the timestamp server.

🎁 Special Offer for our Customers

We offer the fully-featured eIDAS Signature Library .NET (SignLib) completely free to all customers who purchase a Qualified Timestamping package, ensuring secure workflow automation in PowerShell.

PowerShell Automation for eIDAS Compliance

Using Windows PowerShell and SignLib modules, you can run signing scripts capable of handling qualified certificates, hardware tokens (USB / Smart Card), PFX files, and Qualified TSA Server.

1. PDF Signing in PowerShell (PAdES-LTA)

The script below loads a PDF document, applies a qualified certificate, and embeds a long-term archival timestamp[cite: 1]:

# PowerShell example for PAdES-LTA
$sign = New-Object SignLib.Pdf.PdfSignature
$sign.LoadPdfDocument([System.IO.File]::ReadAllBytes("document.pdf"))

# Set certificate from Windows store or Smart Card
$sign.DigitalSignatureCertificate = Get-SigningCertificate -Thumbprint "FAC4D3EF766A59BB068DD90877267EBC56B4232A"

# Configure RFC 3161 TSA Server
$sign.TimeStamping.ServerUrl = [Uri]"https://tsaexample.com/myserver.aspx"

# Apply PAdES-LTA standard
$sign.SignatureStandard = [SignLib.Pdf.PdfSignatureStandard]::PadesLTA
$sign.PadesLtvLevel = [SignLib.Pdf.PadesLtvLevel]::IncludeOcspOnly

# Save signed file
[System.IO.File]::WriteAllBytes("document_signed.pdf", $sign.ApplyDigitalSignature())

2. Generic File Signing (CAdES-A / CAdES-LTA)

For binary files, archives, or co-signatures (.p7m or .p7s), use the CadesSignature class with the appropriate archive level:

# PowerShell example for CAdES-A / CAdES-LTA
$sign = New-Object SignLib.Cades.CadesSignature
$sign.DigitalSignatureCertificate = Get-SigningCertificate -PfxFile "certificate.pfx" -PfxPassword "123456"

# Configure CAdES level (e.g., CadesA for archiving)
$sign.SignatureStandard = [SignLib.Cades.CadesSignatureStandard]::CadesA
$sign.TimeStamping.ServerUrl = [Uri]"https://tsaexample.com/myserver.aspx"

# Apply signature to file
[System.IO.File]::WriteAllBytes("document.p7m", $sign.ApplyDigitalSignature((Get-FullPath "document.pdf")))

3. XML Document Signing (XAdES-LTA)

For electronic invoicing and XML documents, the library allows applying the XadesLTA level with embedded timestamps[cite: 3]:

# PowerShell example for XAdES-LTA
$sign = New-Object SignLib.Xml.XadesSignature
$sign.DigitalSignatureCertificate = Get-SigningCertificate -Thumbprint "FAC4D3EF766A59BB068DD90877267EBC56B4232A"

# Set XAdES-LTA standard and TSA server
$sign.SignatureStandard = [SignLib.Xml.XadesSignatureStandard]::XadesLTA
$sign.TimeStamping.ServerUrl = [Uri]"https://tsaexample.com/myserver.aspx"

# Apply XML signature
$sign.ApplyDigitalSignature((Get-FullPath "invoice.xml"), (Get-FullPath "invoice_signed.xml"))

Ready to automate eIDAS compliant signatures?

Buy any Qualified Timestamp package and receive the developer license for the eIDAS Signature Library .NET for free.

View Timestamp Packages