Xác minh chữ ký
Kiểm tra một PDF đã ký, gồm cả việc chữ ký có bao trùm toàn bộ tệp không.
Công cụ này chạy hoàn toàn trong trình duyệt của bạn. Tệp của bạn không bao giờ được tải lên, và bạn có thể tự kiểm chứng điều đó trong tab mạng của trình duyệt. Tự kiểm chứng: mở tab mạng của trình duyệt và theo dõi. Bạn sẽ thấy một yêu cầu nhỏ hỏi xem bạn còn tác vụ nào không - một tên công cụ và một mã băm, không bao giờ là tệp.
Công cụ này làm gì
This checks the digital signatures inside a PDF and writes a report. It asks four separate questions and never collapses them into one tick: does the signature cover the whole file, does the digest still match, does the signature verify against the certificate embedded with it, and is that certificate one you should trust. The last is answered honestly - there is no trust store here, so the report says not checked.
Whenever a signed document matters and you did not produce it: an invoice that claims to be signed, a contract returned by a counterparty, a certificate sent as proof of something. It is also worth running on your own output, to see what the recipient's reader will report.
Cách hoạt động
- Drop the signed PDF onto this page.
- Leave certificate details on to see the subject, the issuer, the validity dates and the serial number in the report.
- Press Verify signature. A document with no signature field says so plainly and points you at Digital signature, rather than reporting a failure.
- Read the report. Each signature gets its own section, and every line is marked ok, information, warning or danger.
- Keep the report as a web page, or switch the format to JSON under advanced options if something else is going to read it.
The check most verifiers skip is whether the signature covers the whole file. A PDF signature covers only the byte ranges named in its /ByteRange array, so a forged document can carry a perfectly valid signature over the first two pages and an appended third page that nobody signed. A verifier that asks only whether the CMS validates reports that as signed and intact, which is why it is the first line of this report.
Certificate trusted: not checked is the honest answer, and it is deliberate. Deciding whether a certificate belongs to whoever it names requires a trust store and, for revocation, a call to the issuer - and this tool ships no trust store and contacts no issuer. So the report shows the subject, the issuer and the validity window and asks you to compare them against what you expected.
Read the four lines together rather than looking for a verdict. Covers the whole document and document unchanged tell you the bytes are as they were signed; signature verifies tells you the private key matching the embedded certificate produced it. An expired certificate is a warning rather than a failure, because a signature made before expiry stays valid - though without a timestamp nothing proves when it was made.
A document signed with a picture of a signature has nothing here to check, and the report says no signature field rather than pretending otherwise. That is not evidence of anything wrong - most everyday signing is done that way - but the file carries no evidence of its own integrity, and no tool can supply that afterwards.
Công cụ này không làm được gì
- There is no trust store and no network access, so the report cannot say whether a certificate belongs to whoever it names.
- Revocation is not checked. A certificate revoked after it was issued verifies here exactly like one that was not.
- Timestamp tokens are not validated, so any signing time shown is the signer's claim rather than evidence.
- A drawn or scanned signature image carries nothing cryptographic to check; only certificate-based signatures produce a report.
Câu hỏi thường gặp
- Cái này thực sự kiểm tra những gì?
- Bốn điều, được báo cáo riêng biệt: dải byte đã ký có bao trùm toàn bộ tệp không, bản tóm tắt của tài liệu còn khớp không, chữ ký CMS có xác minh được với chứng thư nhúng kèm nó không, và chứng thư đó nói gì. Mỗi điều có dòng và mức độ nghiêm trọng riêng, vì gộp chúng vào một phán quyết duy nhất chính là thứ khiến một chữ ký xấu trông có vẻ tốt.
- Vì sao nó nói chứng thư không được tin cậy?
- Nó nói chưa kiểm tra, đó là một phát biểu khác. Kiểm tra độ tin cậy nghĩa là đối chiếu chứng thư với một kho các tổ chức và hỏi bên cấp xem nó có bị thu hồi chưa, và cả hai đều cần một mạng mà công cụ này không dùng. Hãy so sánh chủ thể và bên cấp với những gì bạn đang mong đợi.
- Khi một chữ ký không bao trùm toàn bộ tài liệu thì điều đó nghĩa là gì?
- Rằng một phần của tệp nằm ngoài dải byte đã ký - nội dung đã được thêm vào sau khi chữ ký được áp. Chữ ký trên phần trước đó có thể xác minh hoàn hảo trong khi phần được thêm vào lại chưa được ký. Hãy coi mọi thứ nằm ngoài dải đó là chưa được xác minh, bất kể chữ ký nói gì về phần còn lại.
- PDF có một chữ ký trên trang nhưng báo cáo nói không có chữ ký nào. Vì sao?
- Vì đó là một hình ảnh, không phải một chữ ký. Một ảnh của chữ ký viết tay là nội dung trang thông thường không có gì mã hóa phía sau, nên chẳng có gì để xác minh. Điều đó ổn với hầu hết giấy tờ, nhưng tệp không thể cho bạn biết nó có bị thay đổi sau khi ký hay không.
- Tài liệu có được tải lên để xác minh không?
- Không. Việc xác minh chạy trong một Web Worker trong trình duyệt của bạn, và không có tổ chức chứng thực nào được liên hệ - đó cũng là lý do độ tin cậy bị bỏ ngỏ chứ không được khẳng định. Báo cáo bạn tải xuống được tạo ra trên chính máy của bạn.