TSA Servers for LibreOffice Digital Signatures

LibreOffice enables users to digitally sign documents and embed verifiable timestamps using RFC 3161-compliant Time Stamp Authority (TSA) servers. Adding a timestamp ensures non-repudiation by mathematically proving that a document was signed at a specific time and that the certificate was valid at that moment. Below is a guide to compatible TSA servers, their URLs, and how to configure them in LibreOffice.

Compatible RFC 3161 TSA Servers

LibreOffice requires an RFC 3161-compliant HTTP/HTTPS endpoint to request a trusted timestamp. The following public and commercial TSA servers are compatible with LibreOffice:

How to Configure a TSA in LibreOffice

To attach timestamps automatically when signing documents, add your preferred TSA URL directly into LibreOffice settings:

  1. Open LibreOffice.
  2. Navigate to Tools > Options (on macOS: LibreOffice > Preferences).
  3. In the left panel, expand LibreOffice and select Security.
  4. Click the TSAs button (or look for the Timestamping Authorities section under Digital Signatures).
  5. Click Add, enter the URL of the chosen TSA server (e.g., https://freetsa.org/tsr), and confirm.

Validating Timestamps in LibreOffice

When opening a signed OpenDocument format (ODF) or PDF file, LibreOffice verifies both the cryptographic signature and the embedded timestamp.

  1. Click the Digital Signature banner or go to File > Digital Signatures > Digital Signatures.
  2. Select the signature from the list.
  3. The dialog displays whether the signature is valid, along with the date and time certified by the TSA. If the timestamp was successfully applied, the exact server-verified time is shown rather than the local system clock.