Okay, if you trust the root certificate of signing authority of timestamp server then things should work fine.If you are doing it for government organization or a large enterprise then it is not feasible to tell all recipients to trust the root explicitly, so for those use cases it is best to go for...