Timestamping is used to specify time when the digital signature is made. This is needed to properly validate the signature.

If signature timestamp is present, the application which validates (verifies) the signature, will check whether the certificates involved into signature validation were valid at the moment of signing. If there's no timestamp for the signature, certificate validity is checked for the moment of signature validation, which is not always acceptable.

Timestamping of digital signatures made over data is performed according to RFC 3161. Timestamps for PE file signatures (Authenticode) are made using proprietary PKCS#7-based format.

SecureBlackbox supports both types of timestamps. For more information about timestamping please read the knowledgebase article.

