3 ms·
From looking at the table at the end of the article, it would seem it is difficult to get PDF signature verification completely correct, but it is possible. Th
by wbond 8y ago
From looking at the table at the end of the article, it would seem it is difficult to get PDF signature verification completely correct, but it is possible.
That said, having worked on PDF signature generation in the past, the spec is very complicated, partially due to the structure of PDF documents and how they can be appended, including signed additions.
- blattimwind 8y agoPDF Signatures violate the The Cryptographic Signature Doom Principle, which is that your signing scheme will lead to doom unless the signature wraps the entirety of your document's binary representation. Same for XML signatures. Violating the TCSDP doesn't mean that your scheme is technically wrong, but it does mean that implementations will often be wrong in funny ways.
- jessaustin 8y ago"the The" It's so important it requires two articles.
- dunham 8y agoEspecially complicated if you want the "LTV" thing to show up in Acrobat. As far as I could determine (I've done it and acrobat is happy), it requires fetching and embedding the necessary CRLs for the TSA (timestamp authority) cert chain before getting the signature, but you don't have the certs with the CRL urls until after you get the signature. And the URLs can change over time (our TSA just switched its cert chain, but they did notify us ahead of time).