Validating signatures

Check a document's digital signatures — whether it changed, whether each signature is genuine, whether you trust the signer — and adding to it.

Nixt PDF checks every digital signature in a document on your computer, and answers three separate questions about each one:

  1. Has the document changed since it was signed?
  2. Is the signature genuine — was it made with the key in the signer’s certificate?
  3. Do you trust the signer — is the certificate, or one that issued it, one you have chosen to trust?

A green tick in other software often stands for all three at once. Nixt PDF shows each answer on its own, because a document can be unchanged and genuinely signed by someone you have no reason to trust.

At a glance: the signature badge

A signed document shows a badge on the window’s bar, next to its name:

  • Signed — every signature checks, and nothing has been added since.
  • Otherwise, the most serious result among the signatures, such as Changed after signing, Does not match or Not genuine.

Rest the pointer on the badge for what it means. A document with only empty signature fields shows no badge.

The Signatures dialog

  1. On the Fill & Sign tab, click Check signatures… — or Protect › Signatures…, or More › Signatures….
  2. The Signatures dialog lists every signature field in the document, signed or not.

A document with none says This document is not signed and has no signature field in it.

What each signature shows

  • The result of checking it — see Results.
  • Who signed, as you judge it — see Trust. Rest the pointer on it for an explanation.
  • The field’s name. A timestamp applied to the whole document is marked (a timestamp on the document).
  • A sentence explaining the result. When a signature can’t be checked, it says Nixt PDF cannot check this signature because and the reason.
  • Done after it was signed — what has been added to the document since, when anything has. See What was done after signing.

Then the details the signature carries, when it has them:

DetailWhat it tells you
Typed by the signerThe name the signer’s software wrote into the signature. It isn’t checked.
The certificate saysThe name, organisation and country in the signer’s certificate.
Issued byWho issued the certificate.
Made with its keyYes — the signature checks against the certificate, or No.
Signed atWhen it was signed.
The document saysA different signing time recorded in the document, when there is one.
TimestampedThe time and the authority that timestamped it, with — which does not check added if the timestamp’s own signature fails.
Reason, Place, ContactWhat the signer entered.
Certifies itFor a certifying signature: Allowing and what it allows.
Hashed withThe hash algorithm, such as SHA-256.
Signs revisionWhich revision of the file it signs.
Added sinceHow much of the file was added after it was signed, such as 12% of the file.

And these buttons, for a signed field:

ButtonWhat it does
Go to itCloses the dialog and goes to the signature’s page.
Certificate…Opens the signer’s certificate. See The Certificate dialog.
Trust this signer… or Trust and a name …Opens the certificate to trust — the signer’s own, or the authority at the top of its chain. Shown when the signer isn’t already trusted.
Save the version that was signed…Saves the document exactly as it was when this signature was made. Shown when something was added afterwards.

Results

ResultWhat it means
Unchanged since it was signedEvery byte the signature covers is the byte that was signed, the signature was made with the key in its certificate, and it covers the whole file.
Changed after signingThe signed part is intact, and something has been added to the file since. What was added is listed. Filling in a form or signing again is expected; changing what the pages say is not.
Does not matchThe document doesn’t match what the signature says it should. It has been altered since it was signed.
Not genuineThe signature was not made by the key in the certificate it carries. Either the signature or the document has been tampered with, and nothing it claims can be relied on.
Cannot be checkedThe signature uses something Nixt PDF doesn’t check. The reason is given.
BrokenThe signature doesn’t say which part of the file it covers, or says something the file can’t satisfy.
Not signedAn empty signature field. Common and not a problem: a form sent out to be signed has one on every copy.

Changed after signing is normal for a document that was signed and then filled in, commented on or signed again — every later signature leaves earlier ones in this state. Read Done after it was signed to decide whether what was added matters.

Trust

LabelWhat it means
Trusted by youThe certificate, or the authority that issued it, is one you have chosen to trust.
Self-signedThe certificate vouches for itself. Only trust it if you know it is theirs — compare its fingerprint with one they give you some other way.
Issuer not trustedThe certificate was issued by an authority you haven’t chosen to trust.
Certificate out of dateA certificate involved wasn’t valid at the time the document says it was signed.
Signer not knownThe signature carries no certificate Nixt PDF could read.

Trust is judged only against certificates you added yourself. Nixt PDF comes with none, so a signature from an authority you haven’t added shows Issuer not trusted until you trust it.

Trusting a signer

  1. In the Signatures dialog, click Trust this signer… (or Trust followed by the authority’s name).
  2. In the Certificate dialog, check the SHA-256 fingerprint with the signer or the authority some other way.
  3. Click Trust it.

The dialog updates to show the new result. To manage everything you trust, use Trusted certificates…; see Digital IDs.

What was done after signing

When a signature doesn’t cover the end of the file, Nixt PDF compares the document as it was signed with the document as it is, and lists what changed:

  • What is drawn on page 2 was changed (or on several pages) — shown in red.
  • 1 page was added or pages were removed — added pages are shown in red.
  • form fields were added, removed, or filled in or changed.
  • Signed again, 1 time.
  • comments were added, changed or removed.
  • Its bookmarks, attachments or opening behaviour were changed.

Changes to what the pages draw are the ones that alter what was signed. Stamps fixed to the page, redaction and edited text all count.

Certified documents

A certifying signature says what may change afterwards. When what was done goes beyond that, the dialog says in red What was done after it breaks its certification: it allowed only and what it allowed, and the badge on the window’s bar shows Does not match.

Seeing what was signed

Click Save the version that was signed… to save the document exactly as the signer saw it. The name starts as the document’s name followed by -as-signed.pdf. The message says Saved the document as it was when it was signed.

Adding to a signed document

Nixt PDF adds your changes after the signed part of the file, so the signatures stay intact and anyone checking them is told what was added. The first time you choose a tool that changes a signed document, a dialog explains what that means for this document:

Dialog titleWhat it says
This document is signedWhat you add is kept apart from what was signed, so the signatures stay intact, and anyone checking them is told exactly what was added.
This document is certified for filling in, signing and commentsComments, stamps and signatures keep the certification. Changing what is drawn on the pages breaks it.
This document is certified for filling in and signingFilling in the form and signing keep the certification. Comments, stamps and anything drawn on the page break it.
This document is certified against any changeAnything you add breaks the certification, and every reader will say so.

Click Change it anyway to go on, or Leave it as it is to keep the document as it is.

Signatures Nixt PDF checks

  • Signatures in the PAdES and PKCS#7 formats, including older SHA-1 and X.509 kinds, and document timestamps.
  • RSA signatures and elliptic-curve signatures on the P-256, P-384 and P-521 curves.
  • Signatures in password-protected documents.
  • Timestamps on signatures, which are checked too. A timestamp that checks is the time a signature is judged at.

When a signature uses something else, it shows Cannot be checked and the reason, such as it uses a digest Nixt PDF does not implement.

What checking doesn’t tell you

The Signatures dialog ends with What this does not tell you:

  • Whether a certificate has been revoked since it was used. Finding out means asking the certificate’s issuer, over the network, about the document you’re reading, and Nixt PDF doesn’t send anything about your documents anywhere.

What the checks do establish is whether the document has changed, whether the signature was made with the key in its certificate, and whether that certificate is one you have chosen to trust.

Something unclear or out of date on this page? Tell us.