PDF: Support not contacting OCSP servers when validating signatures
This is sub-optimal since will not check if the certificate has been revoked but is more privacy friendly since doesn't leak to the certificate authority server that you're trying to validate a given certificate