ข้ามไปยังเนื้อหา

ลายเซ็นดิจิทัล

เซ็นด้วยใบรับรอง เพื่อให้ผู้อ่านพิสูจน์ได้ว่าไฟล์ไม่ถูกเปลี่ยนแปลง

ประมวลผลบนเครื่องของคุณ

เครื่องมือนี้ทำงานในเบราว์เซอร์ของคุณทั้งหมด ไฟล์ของคุณไม่ถูกอัปโหลดเลย และคุณตรวจสอบได้เองในแท็บเครือข่ายของเบราว์เซอร์ ตรวจสอบด้วยตัวเอง เปิดแท็บเครือข่ายของเบราว์เซอร์แล้วดู คุณจะเห็นคำขอเล็ก ๆ หนึ่งรายการที่ถามว่าคุณยังมีโควตางานเหลืออยู่หรือไม่ ซึ่งมีแค่ชื่อเครื่องมือกับค่าแฮช ไม่ใช่ตัวไฟล์

เครื่องมือนี้ทำอะไร

This applies a real cryptographic signature: a detached CMS SignedData structure computed over the document's bytes and embedded in the file, which Acrobat and other compliant readers check when the document is opened. Unlike a drawn signature it establishes two things - that the holder of a particular certificate signed, and that not one byte has changed since.

When the recipient will verify rather than merely look: a tender submission, an invoice under an e-invoicing rule, a document going into an archive that requires signed originals, or anything where a later argument about whether the file was altered is a real possibility.

วิธีทำงาน

  1. Drop two files onto this page: the PDF, and your certificate as a .p12 or .pfx file. The order does not matter - the PDF is recognised by its contents.
  2. Type the passphrase that protects the certificate. It is used in your browser to unwrap the private key and is never sent.
  3. Fill in the reason and the location if your recipient expects them. Both are recorded inside the signature and shown by readers that display signature details.
  4. Leave visible on to draw a signature block on the page you choose, or turn it off for a signature that exists only in the file's structure.
  5. Press Sign with certificate, then open the result in Acrobat to see what a recipient's reader will report.

Every online signing service asks you to upload the one file you should never upload. Here the .p12 is read in the page and parsed inside a worker that holds nothing else, and the worker is terminated when the job finishes - the thread is discarded rather than a variable cleared, so nothing of the key survives into a later job.

A PDF signature covers the byte ranges its /ByteRange array names, and that array has to be written into the file in place, after space for the signature has been reserved. Re-serialising the document afterwards moves every offset and invalidates what was just computed - the mistake naive implementations make, and the reason some signed PDFs report as broken the moment they are opened.

A self-signed certificate produces a valid signature that readers report as validity unknown, because they have no reason to believe the name on it. That is not a failure: it says the mathematics checks out and the identity does not. A certificate issued by an authority your recipient's reader already trusts is what turns that into a green tick.

There is no trusted timestamp and no revocation checking, because both need a network service that this tool never contacts. The signing time recorded is your own computer's clock, which a strict recipient should treat as a claim rather than proof. An encrypted PDF is refused for a related reason: a signature computed over ciphertext is not something a reader will validate.

สิ่งที่เครื่องมือนี้ทำไม่ได้

  • A self-signed certificate shows as validity unknown in the recipient's reader until they choose to trust it. Only a certificate from an authority their reader already trusts avoids that.
  • No trusted timestamp is applied and no revocation is checked, because both require contacting a server. The recorded signing time is your device's clock.
  • This produces a basic signature rather than a long-term-validation profile, so once the certificate expires nothing in the file confirms the signature was made while it was valid.
  • Encrypted documents are refused. Remove the password with Unlock PDF before signing.
  • The visible signature block has a fixed position and size on the page you choose; it cannot be dragged elsewhere.

คำถามที่คนมักถาม

ต่างจากเครื่องมือเซ็น PDF อย่างไร
เซ็น PDF วาดภาพลายเซ็นลงบนหน้าเอกสาร ส่วนเครื่องมือนี้คำนวณลายเซ็นทางวิทยาการรหัสลับจากไบต์ของไฟล์ด้วยกุญแจส่วนตัวของคุณแล้วฝังไว้ในไฟล์ ผู้อ่านจึงรายงานได้ว่าใครเป็นผู้เซ็นตามที่ใบรับรองระบุ และมีอะไรเปลี่ยนไปหลังจากนั้นหรือไม่ ส่วนแบบที่วาดขึ้นไม่ได้ให้ทั้งสองอย่างนั้น
จะได้ใบรับรองมาจากที่ใด
จากผู้ออกใบรับรอง มีทั้งโครงการระดับประเทศหลายแห่ง ผู้ออกใบรับรองเชิงพาณิชย์จำนวนหนึ่ง และนายจ้างบางรายที่ออกให้ สิ่งที่คุณต้องมีคือชุด PKCS#12 หรือไฟล์ .p12 หรือ .pfx ที่บรรจุใบรับรองของคุณพร้อมกุญแจส่วนตัว ใบรับรองที่เซ็นเองด้วย OpenSSL ก็ใช้เซ็นได้ดี แต่โปรแกรมอ่านจะไม่เชื่อถือให้โดยอัตโนมัติ
ทำไม Acrobat จึงบอกว่าไม่ทราบความถูกต้องของลายเซ็น
เพราะมันตรวจสอบทางคณิตศาสตร์แล้วแต่ยืนยันตัวตนไม่ได้ ข้อความนั้นหมายความว่าลายเซ็นยังสมบูรณ์และเอกสารไม่ถูกเปลี่ยนแปลง แต่ใบรับรองไม่ได้เชื่อมโยงไปถึงผู้ออกใบรับรองที่โปรแกรมอ่านเชื่อถือ ซึ่งเป็นสิ่งที่เกิดขึ้นกับใบรับรองที่เซ็นเองทุกใบ
กุญแจส่วนตัวของฉันถูกอัปโหลดหรือไม่
ไม่ และนี่คือเครื่องมือที่เรื่องนี้สำคัญที่สุด ไฟล์ .p12 ถูกอ่านในหน้าเว็บและแยกวิเคราะห์ภายใน Web Worker ที่ถูกปิดทันทีเมื่องานจบ กุญแจจึงไม่ถูกเก็บไว้และไม่มีอะไรถูกส่งออกไป เปิดแท็บเครือข่ายก่อนเซ็นแล้วเฝ้าดูว่ามันว่างเปล่าอยู่อย่างนั้น
มีการประทับเวลาที่เชื่อถือได้หรือไม่
ไม่มี การประทับเวลาต้องมาจากผู้ให้บริการประทับเวลาผ่านเครือข่าย และเครื่องมือนี้ไม่ส่งคำขอผ่านเครือข่ายเลย เวลาที่บันทึกไว้จึงเป็นเวลาจากนาฬิกาของเครื่องคุณเอง มันเป็นเพียงคำกล่าวอ้างไม่ใช่หลักฐาน และควรบอกผู้รับที่มีนโยบายเข้มงวดให้ทราบตั้งแต่ต้น
เอกสารของฉันถูกอัปโหลดหรือไม่
ไม่ ทั้งเอกสารและใบรับรองอยู่บนอุปกรณ์ของคุณ ลายเซ็นถูกคำนวณและเขียนลงในไฟล์ในเครื่อง เมื่อโหลดหน้าเว็บครั้งแรกแล้ว การเซ็นทำงานได้แม้ปิดการเชื่อมต่อ ซึ่งเป็นวิธีจัดการสิ่งที่เป็นความลับได้อย่างสมเหตุสมผล

เครื่องมือที่เกี่ยวข้อง