Article

P26-electronic-evidence-certificate.html" style="color:#3D61D2; text-decoration:underline;">Bharatiya Sakshya Adhiniyam 2023, Section 63 (and the corresponding Section 65B of the Indian Evidence Act 1872).

A Note on Admissibility

Signing and timestamping produce a certificate in a court-ready format — they make the record tamper-evident, attributable and independently dated. They do not, and cannot, guarantee a particular outcome: admissibility remains the decision of the court. The value of strong signing and timestamping is that it lets you stand behind the technical claims with confidence; how that evidence is received is for the court to determine. e-Dex's certificate wording is counsel-reviewed, but this article is an explainer, not legal advice.

Conclusion

Signing and timestamping are two proofs, not one: the signature binds identity and integrity, the timestamp binds time. Apply both — ideally with a real DSC and a trusted TSA — and your forensic certificate becomes a self-contained, tamper-evident record that can prove its own origin and age years later. e-Dex — the Digital Evidence Integrity Suite applies a SHA-256 seal, an optional PAdES signature and an optional RFC-3161 timestamp at the moment of generation, so your evidence is defensible from the start. Download it free and try it on your next case file.

Streamline Your Business with Planex365 ERP

Consolidate your sales pipeline, CRM contacts, inventory, accounts receivable, and billing in a single, secure database designed for Indian SMEs.

Frequently Asked Questions

What is the difference between signing and timestamping a document?

Signing and timestamping answer two different questions. A digital signature proves who produced the document and that it has not been changed since it was signed. A trusted timestamp proves the document provably existed at a specific point in time. Neither implies the other, so a strong forensic certificate uses both.

What is a PAdES signature?

PAdES stands for PDF Advanced Electronic Signatures, a family of standards for embedding a cryptographic signature directly inside a PDF rather than alongside it. A PAdES signature proves signer identity through the certificate and integrity, because altering even one byte after signing makes the signature fail validation.

What does an RFC-3161 trusted timestamp add?

An RFC-3161 timestamp asks an independent Time-Stamping Authority to sign a hash of your document, returning a token that proves it existed at that moment. This gives independent proof of existence-at-a-time, a defence against back-dating, and longevity, since the timestamp anchors validity even after the signer's certificate expires.

Is a self-signed certificate good enough, or do I need a DSC?

A self-signed signature is cryptographically just as strong at proving a document is unmodified, but no recognised authority vouches for the identity behind it. In India, a Digital Signature Certificate from a licensed Certifying Authority ties the signature to an accountable person. The rule of thumb: self-signed for testing, your DSC for anything that may be produced.

Can a signed and timestamped certificate be verified offline?

Yes. e-Dex's Evidence Viewer re-verifies a certificate entirely offline, confirming the signature is valid, the document is unmodified, and the timestamp token is valid, with no internet and no Adobe. That self-contained verifiability lets the certificate prove itself on an air-gapped forensic workstation or in court.

Try ERP Demo