Littlepanda

Document signing fingerprints

How to check that a PDF really was signed by Littlepanda.

Documents signed by Littlepanda use a private certificate authority rooted at this domain. This page is served over the same publicly trusted TLS connection as the rest of littlepanda.uk: if you reached it securely, you can trust that the fingerprints below are the ones we actually control.

The signature itself is embedded in each PDF (PAdES/CMS), not supplied as a separate file.

Root CA

SubjectCN=littlepanda.uk Document Signing CA Root CA,O=littlepanda.uk Document Signing CA
SHA-256 fingerprint05:72:D6:77:E4:93:19:70:B9:13:78:17:DA:2F:B6:55:D8:71:80:B9:B6:4E:A3:10:13:90:4A:81:BB:04:08:3B
Valid untilSep 20 11:19:17 2036 GMT

Download root CA certificate

Import this into your PDF reader's trusted root store to get a fully trusted signature indicator. Never import anything claiming to be our root certificate from any other source or URL.

Intermediate CA

SubjectCN=littlepanda.uk Document Signing CA Intermediate
SHA-256 fingerprint2F:8C:10:A2:CE:0D:FE:73:6D:E8:F1:08:96:A9:3F:17:15:97:78:34:D5:54:0C:22:51:21:43:3E:6E:3B:71:02
Valid untilSep 20 13:26:27 2036 GMT

Current document-signing certificate

SubjectCN=littlepanda.uk Document Signer
SANemail:docsign@littlepanda.uk
SHA-256 fingerprintF7:4E:96:80:53:45:AA:83:D3:DB:F5:F9:6B:A9:FF:D1:17:8F:64:BF:BD:47:DC:D3:41:D9:32:BB:CF:21:89:E1
Valid untilSep 23 14:25:43 2027 GMT

This certificate is renewed automatically, so its fingerprint changes on renewal; the root CA fingerprint above does not. If this table's "valid until" date has passed, check the document's own embedded signing time: it may simply predate the current certificate.

How to verify a signed PDF

  1. Open the PDF in any reader that supports digital signatures (Adobe Acrobat/Reader, Preview and others). The signature panel appears automatically; no extra file is needed.
  2. The reader will report the signature as mathematically valid (the document is unchanged since signing) without any setup on your part.
  3. To see it as trusted rather than "unknown signer", import littlepanda-root-ca.crt (linked above) into your reader's trusted certificate store, once. After that, every PDF we sign validates automatically.
  4. To double-check by hand, the fingerprint your reader shows for the signing certificate embedded in the PDF should match the "Current document-signing certificate" fingerprint above, or a previous one if the document is older than the latest renewal.

Generated automatically at 2026-10-01 08:02 UTC from the certificates currently in production use. This page is not edited by hand.