Certificates

Digital certificates in C2PA

C2PA signing uses certificates and private keys to bind a manifest to media. ProvSeal supports test certificates for demos and may use imported signing material for controlled workflows.

What certificates prove and what they do not

Certificates support provenance review — they do not certify visual truth.

Signature binding

A certificate helps verify that the manifest signature matches the public key associated with the signing material.

Chain context

The certificate path helps determine whether a signature can be linked to a recognized public trust source.

Not a truth verdict

A valid certificate does not prove that visual content is true. It supports provenance and integrity review.

Test certificates and imported certificates

Choose signing material based on demo, development or controlled production needs.

TypeUse caseTrust implication
Test certificate Demos, development, internal validation and learning workflows. Not public production trust. It should usually appear as Signed but untrusted.
Imported .p12 / .pfx Controlled signing workflows with existing signing material. Trust depends on certificate properties and whether the chain is recognized.
Hardware-backed material Soon Planned support for security token, smart card or managed key workflows. Will improve key handling when available, but public trust will still depend on the certificate chain.
Private key handling

Private keys should be handled carefully. Do not import production signing credentials into environments you do not control. Test certificates are for demos and development only.

What to inspect in certificate details

Key fields to review when opening certificate information in a report.

01 Subject and issuer

Who the certificate identifies and which authority issued it.

02 Validity period

Whether the certificate is valid for the time being evaluated.

03 Key usage and extensions

Whether certificate properties are compatible with the signing workflow.

Related guides

Continue with trust chains and recognized authorities to interpret Trusted vs Signed but untrusted.