ลายเซ็นดิจิทัล
เซ็นด้วยใบรับรอง เพื่อให้ผู้อ่านพิสูจน์ได้ว่าไฟล์ไม่ถูกเปลี่ยนแปลง
เครื่องมือนี้ทำงานในเบราว์เซอร์ของคุณทั้งหมด ไฟล์ของคุณไม่ถูกอัปโหลดเลย และคุณตรวจสอบได้เองในแท็บเครือข่ายของเบราว์เซอร์ ตรวจสอบด้วยตัวเอง เปิดแท็บเครือข่ายของเบราว์เซอร์แล้วดู คุณจะเห็นคำขอเล็ก ๆ หนึ่งรายการที่ถามว่าคุณยังมีโควตางานเหลืออยู่หรือไม่ ซึ่งมีแค่ชื่อเครื่องมือกับค่าแฮช ไม่ใช่ตัวไฟล์
เครื่องมือนี้ทำอะไร
This applies a real cryptographic signature: a detached CMS SignedData structure computed over the document's bytes and embedded in the file, which Acrobat and other compliant readers check when the document is opened. Unlike a drawn signature it establishes two things - that the holder of a particular certificate signed, and that not one byte has changed since.
When the recipient will verify rather than merely look: a tender submission, an invoice under an e-invoicing rule, a document going into an archive that requires signed originals, or anything where a later argument about whether the file was altered is a real possibility.
วิธีทำงาน
- Drop two files onto this page: the PDF, and your certificate as a .p12 or .pfx file. The order does not matter - the PDF is recognised by its contents.
- Type the passphrase that protects the certificate. It is used in your browser to unwrap the private key and is never sent.
- Fill in the reason and the location if your recipient expects them. Both are recorded inside the signature and shown by readers that display signature details.
- Leave visible on to draw a signature block on the page you choose, or turn it off for a signature that exists only in the file's structure.
- Press Sign with certificate, then open the result in Acrobat to see what a recipient's reader will report.
Every online signing service asks you to upload the one file you should never upload. Here the .p12 is read in the page and parsed inside a worker that holds nothing else, and the worker is terminated when the job finishes - the thread is discarded rather than a variable cleared, so nothing of the key survives into a later job.
A PDF signature covers the byte ranges its /ByteRange array names, and that array has to be written into the file in place, after space for the signature has been reserved. Re-serialising the document afterwards moves every offset and invalidates what was just computed - the mistake naive implementations make, and the reason some signed PDFs report as broken the moment they are opened.
A self-signed certificate produces a valid signature that readers report as validity unknown, because they have no reason to believe the name on it. That is not a failure: it says the mathematics checks out and the identity does not. A certificate issued by an authority your recipient's reader already trusts is what turns that into a green tick.
There is no trusted timestamp and no revocation checking, because both need a network service that this tool never contacts. The signing time recorded is your own computer's clock, which a strict recipient should treat as a claim rather than proof. An encrypted PDF is refused for a related reason: a signature computed over ciphertext is not something a reader will validate.
สิ่งที่เครื่องมือนี้ทำไม่ได้
- A self-signed certificate shows as validity unknown in the recipient's reader until they choose to trust it. Only a certificate from an authority their reader already trusts avoids that.
- No trusted timestamp is applied and no revocation is checked, because both require contacting a server. The recorded signing time is your device's clock.
- This produces a basic signature rather than a long-term-validation profile, so once the certificate expires nothing in the file confirms the signature was made while it was valid.
- Encrypted documents are refused. Remove the password with Unlock PDF before signing.
- The visible signature block has a fixed position and size on the page you choose; it cannot be dragged elsewhere.
คำถามที่คนมักถาม
- ต่างจากเครื่องมือเซ็น PDF อย่างไร
- เซ็น PDF วาดภาพลายเซ็นลงบนหน้าเอกสาร ส่วนเครื่องมือนี้คำนวณลายเซ็นทางวิทยาการรหัสลับจากไบต์ของไฟล์ด้วยกุญแจส่วนตัวของคุณแล้วฝังไว้ในไฟล์ ผู้อ่านจึงรายงานได้ว่าใครเป็นผู้เซ็นตามที่ใบรับรองระบุ และมีอะไรเปลี่ยนไปหลังจากนั้นหรือไม่ ส่วนแบบที่วาดขึ้นไม่ได้ให้ทั้งสองอย่างนั้น
- จะได้ใบรับรองมาจากที่ใด
- จากผู้ออกใบรับรอง มีทั้งโครงการระดับประเทศหลายแห่ง ผู้ออกใบรับรองเชิงพาณิชย์จำนวนหนึ่ง และนายจ้างบางรายที่ออกให้ สิ่งที่คุณต้องมีคือชุด PKCS#12 หรือไฟล์ .p12 หรือ .pfx ที่บรรจุใบรับรองของคุณพร้อมกุญแจส่วนตัว ใบรับรองที่เซ็นเองด้วย OpenSSL ก็ใช้เซ็นได้ดี แต่โปรแกรมอ่านจะไม่เชื่อถือให้โดยอัตโนมัติ
- ทำไม Acrobat จึงบอกว่าไม่ทราบความถูกต้องของลายเซ็น
- เพราะมันตรวจสอบทางคณิตศาสตร์แล้วแต่ยืนยันตัวตนไม่ได้ ข้อความนั้นหมายความว่าลายเซ็นยังสมบูรณ์และเอกสารไม่ถูกเปลี่ยนแปลง แต่ใบรับรองไม่ได้เชื่อมโยงไปถึงผู้ออกใบรับรองที่โปรแกรมอ่านเชื่อถือ ซึ่งเป็นสิ่งที่เกิดขึ้นกับใบรับรองที่เซ็นเองทุกใบ
- กุญแจส่วนตัวของฉันถูกอัปโหลดหรือไม่
- ไม่ และนี่คือเครื่องมือที่เรื่องนี้สำคัญที่สุด ไฟล์ .p12 ถูกอ่านในหน้าเว็บและแยกวิเคราะห์ภายใน Web Worker ที่ถูกปิดทันทีเมื่องานจบ กุญแจจึงไม่ถูกเก็บไว้และไม่มีอะไรถูกส่งออกไป เปิดแท็บเครือข่ายก่อนเซ็นแล้วเฝ้าดูว่ามันว่างเปล่าอยู่อย่างนั้น
- มีการประทับเวลาที่เชื่อถือได้หรือไม่
- ไม่มี การประทับเวลาต้องมาจากผู้ให้บริการประทับเวลาผ่านเครือข่าย และเครื่องมือนี้ไม่ส่งคำขอผ่านเครือข่ายเลย เวลาที่บันทึกไว้จึงเป็นเวลาจากนาฬิกาของเครื่องคุณเอง มันเป็นเพียงคำกล่าวอ้างไม่ใช่หลักฐาน และควรบอกผู้รับที่มีนโยบายเข้มงวดให้ทราบตั้งแต่ต้น
- เอกสารของฉันถูกอัปโหลดหรือไม่
- ไม่ ทั้งเอกสารและใบรับรองอยู่บนอุปกรณ์ของคุณ ลายเซ็นถูกคำนวณและเขียนลงในไฟล์ในเครื่อง เมื่อโหลดหน้าเว็บครั้งแรกแล้ว การเซ็นทำงานได้แม้ปิดการเชื่อมต่อ ซึ่งเป็นวิธีจัดการสิ่งที่เป็นความลับได้อย่างสมเหตุสมผล