ตรวจสอบลายเซ็น
ตรวจไฟล์ PDF ที่เซ็นแล้ว รวมถึงว่าลายเซ็นครอบคลุมทั้งไฟล์หรือไม่
เครื่องมือนี้ทำงานในเบราว์เซอร์ของคุณทั้งหมด ไฟล์ของคุณไม่ถูกอัปโหลดเลย และคุณตรวจสอบได้เองในแท็บเครือข่ายของเบราว์เซอร์ ตรวจสอบด้วยตัวเอง เปิดแท็บเครือข่ายของเบราว์เซอร์แล้วดู คุณจะเห็นคำขอเล็ก ๆ หนึ่งรายการที่ถามว่าคุณยังมีโควตางานเหลืออยู่หรือไม่ ซึ่งมีแค่ชื่อเครื่องมือกับค่าแฮช ไม่ใช่ตัวไฟล์
เครื่องมือนี้ทำอะไร
This checks the digital signatures inside a PDF and writes a report. It asks four separate questions and never collapses them into one tick: does the signature cover the whole file, does the digest still match, does the signature verify against the certificate embedded with it, and is that certificate one you should trust. The last is answered honestly - there is no trust store here, so the report says not checked.
Whenever a signed document matters and you did not produce it: an invoice that claims to be signed, a contract returned by a counterparty, a certificate sent as proof of something. It is also worth running on your own output, to see what the recipient's reader will report.
วิธีทำงาน
- Drop the signed PDF onto this page.
- Leave certificate details on to see the subject, the issuer, the validity dates and the serial number in the report.
- Press Verify signature. A document with no signature field says so plainly and points you at Digital signature, rather than reporting a failure.
- Read the report. Each signature gets its own section, and every line is marked ok, information, warning or danger.
- Keep the report as a web page, or switch the format to JSON under advanced options if something else is going to read it.
The check most verifiers skip is whether the signature covers the whole file. A PDF signature covers only the byte ranges named in its /ByteRange array, so a forged document can carry a perfectly valid signature over the first two pages and an appended third page that nobody signed. A verifier that asks only whether the CMS validates reports that as signed and intact, which is why it is the first line of this report.
Certificate trusted: not checked is the honest answer, and it is deliberate. Deciding whether a certificate belongs to whoever it names requires a trust store and, for revocation, a call to the issuer - and this tool ships no trust store and contacts no issuer. So the report shows the subject, the issuer and the validity window and asks you to compare them against what you expected.
Read the four lines together rather than looking for a verdict. Covers the whole document and document unchanged tell you the bytes are as they were signed; signature verifies tells you the private key matching the embedded certificate produced it. An expired certificate is a warning rather than a failure, because a signature made before expiry stays valid - though without a timestamp nothing proves when it was made.
A document signed with a picture of a signature has nothing here to check, and the report says no signature field rather than pretending otherwise. That is not evidence of anything wrong - most everyday signing is done that way - but the file carries no evidence of its own integrity, and no tool can supply that afterwards.
สิ่งที่เครื่องมือนี้ทำไม่ได้
- There is no trust store and no network access, so the report cannot say whether a certificate belongs to whoever it names.
- Revocation is not checked. A certificate revoked after it was issued verifies here exactly like one that was not.
- Timestamp tokens are not validated, so any signing time shown is the signer's claim rather than evidence.
- A drawn or scanned signature image carries nothing cryptographic to check; only certificate-based signatures produce a report.
คำถามที่คนมักถาม
- เครื่องมือนี้ตรวจอะไรบ้าง
- สี่อย่าง และรายงานแยกกัน ได้แก่ ช่วงไบต์ที่เซ็นครอบคลุมทั้งไฟล์หรือไม่ ค่าย่อยของเอกสารยังตรงกันอยู่หรือไม่ ลายเซ็น CMS ผ่านการตรวจสอบกับใบรับรองที่ฝังมาด้วยหรือไม่ และใบรับรองนั้นระบุอะไรไว้ แต่ละข้อมีบรรทัดและระดับความรุนแรงของตัวเอง เพราะการยุบทั้งหมดให้เหลือคำตัดสินเดียวคือสิ่งที่ทำให้ลายเซ็นที่ไม่ดีดูดีได้
- ทำไมจึงบอกว่าใบรับรองไม่น่าเชื่อถือ
- มันบอกว่ายังไม่ได้ตรวจ ซึ่งเป็นคนละคำกล่าว การตรวจความน่าเชื่อถือหมายถึงการเทียบใบรับรองกับคลังของผู้ออกใบรับรอง และถามผู้ออกว่าใบนั้นถูกเพิกถอนไปแล้วหรือยัง ทั้งสองอย่างต้องใช้เครือข่ายที่เครื่องมือนี้ไม่ใช้ ให้เทียบชื่อผู้ถือและผู้ออกกับสิ่งที่คุณคาดหวังไว้แทน
- การที่ลายเซ็นไม่ครอบคลุมทั้งเอกสารหมายความว่าอย่างไร
- หมายความว่าบางส่วนของไฟล์อยู่นอกช่วงไบต์ที่เซ็นไว้ มีการต่อเนื้อหาเพิ่มเข้ามาหลังจากลงลายเซ็นแล้ว ลายเซ็นที่ครอบคลุมส่วนแรกอาจผ่านการตรวจสอบอย่างสมบูรณ์ ในขณะที่ส่วนที่เพิ่มเข้ามาไม่ได้ถูกเซ็น ให้ถือว่าทุกอย่างนอกช่วงนั้นยังไม่ได้รับการตรวจสอบ ไม่ว่าลายเซ็นจะบอกอะไรเกี่ยวกับส่วนที่เหลือ
- ไฟล์ PDF มีลายเซ็นอยู่บนหน้า แต่รายงานบอกว่าไม่มีลายเซ็น เพราะอะไร
- เพราะมันเป็นภาพ ไม่ใช่ลายเซ็น ภาพลายเซ็นลายมือคือเนื้อหาของหน้าตามปกติ ไม่มีอะไรทางวิทยาการรหัสลับอยู่เบื้องหลัง จึงไม่มีอะไรให้ตรวจสอบ นั่นเพียงพอสำหรับงานเอกสารส่วนใหญ่ แต่ตัวไฟล์บอกคุณไม่ได้ว่ามันถูกแก้ไขหลังการเซ็นหรือไม่
- เอกสารถูกอัปโหลดเพื่อตรวจสอบหรือไม่
- ไม่ การตรวจสอบทำงานใน Web Worker ในเบราว์เซอร์ของคุณ และไม่มีการติดต่อผู้ออกใบรับรองรายใด ซึ่งก็เป็นเหตุผลที่เรื่องความน่าเชื่อถือถูกปล่อยไว้โดยไม่ตอบ แทนที่จะยืนยันลอยๆ รายงานที่คุณดาวน์โหลดถูกสร้างขึ้นบนเครื่องของคุณเอง