OK, that makes sense (sort of :)).
I'm not sure why you would send the .cer along with every email, as
that seems to defeat the purpose of signing the PDF (assuming he's
taking the .cer at face value).
It would make sense if you sent the .cer to them once and then they
used it for checking any subsequent invoices from you. That would
allow them to to make sure that the invoices did, in fact, come from
you and have not been altered. That's essentially the same as
certifying a PDF.
Do you know if they will be verifying the signatures on the server or
using Adobe Reader? If they are using Adobe Reader, then you can send
the .cer as a .fdf exported identity. That would be easier to import
into Reader than the .cer.
Just a thought.
Regards,
Rob