Document signing fingerprints
How to check that a PDF really was signed by Littlepanda.
Documents signed by Littlepanda use a private certificate authority
rooted at this domain. This page is served over the same publicly
trusted TLS connection as the rest of littlepanda.uk: if
you reached it securely, you can trust that the fingerprints below are
the ones we actually control.
The signature itself is embedded in each PDF (PAdES/CMS), not supplied as a separate file.
Root CA
| Subject | CN=littlepanda.uk Document Signing CA Root CA,O=littlepanda.uk Document Signing CA |
|---|---|
| SHA-256 fingerprint | 05:72:D6:77:E4:93:19:70:B9:13:78:17:DA:2F:B6:55:D8:71:80:B9:B6:4E:A3:10:13:90:4A:81:BB:04:08:3B |
| Valid until | Sep 20 11:19:17 2036 GMT |
Import this into your PDF reader's trusted root store to get a fully trusted signature indicator. Never import anything claiming to be our root certificate from any other source or URL.
Intermediate CA
| Subject | CN=littlepanda.uk Document Signing CA Intermediate |
|---|---|
| SHA-256 fingerprint | 2F:8C:10:A2:CE:0D:FE:73:6D:E8:F1:08:96:A9:3F:17:15:97:78:34:D5:54:0C:22:51:21:43:3E:6E:3B:71:02 |
| Valid until | Sep 20 13:26:27 2036 GMT |
Current document-signing certificate
| Subject | CN=littlepanda.uk Document Signer |
|---|---|
| SAN | email:docsign@littlepanda.uk |
| SHA-256 fingerprint | F7:4E:96:80:53:45:AA:83:D3:DB:F5:F9:6B:A9:FF:D1:17:8F:64:BF:BD:47:DC:D3:41:D9:32:BB:CF:21:89:E1 |
| Valid until | Sep 23 14:25:43 2027 GMT |
This certificate is renewed automatically, so its fingerprint changes on renewal; the root CA fingerprint above does not. If this table's "valid until" date has passed, check the document's own embedded signing time: it may simply predate the current certificate.
How to verify a signed PDF
- Open the PDF in any reader that supports digital signatures (Adobe Acrobat/Reader, Preview and others). The signature panel appears automatically; no extra file is needed.
- The reader will report the signature as mathematically valid (the document is unchanged since signing) without any setup on your part.
- To see it as trusted rather than "unknown signer", import
littlepanda-root-ca.crt(linked above) into your reader's trusted certificate store, once. After that, every PDF we sign validates automatically. - To double-check by hand, the fingerprint your reader shows for the signing certificate embedded in the PDF should match the "Current document-signing certificate" fingerprint above, or a previous one if the document is older than the latest renewal.
Generated automatically at 2026-10-01 08:02 UTC from the certificates currently in production use. This page is not edited by hand.