You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Adobe Acrobat与Foxit Reader显示PDF签名有效,iText7验证第二个签名失败

问题分析与解决方法

你遇到的第二个签名验证失败问题,主要可能来自以下几个原因:

1. 证书信任链未正确加载

Adobe和Foxit默认会使用系统内置的信任根证书来验证签名的证书链,但iText7不会自动加载系统信任存储。即使签名的哈希值完全匹配,只要证书链验证不通过,VerifySignatureIntegrityAndAuthenticity()就会返回false。

解决代码调整:

// 加载当前用户的系统根证书存储
using var trustStore = new System.Security.Cryptography.X509Certificates.X509Store(
    System.Security.Cryptography.X509Certificates.StoreName.Root,
    System.Security.Cryptography.X509Certificates.StoreLocation.CurrentUser);
trustStore.Open(System.Security.Cryptography.X509Certificates.OpenFlags.ReadOnly);
var trustedCerts = trustStore.Certificates;
trustStore.Close();

// 创建验证选项并传入信任证书集合
var verificationOptions = new iText.Signatures.VerificationOptions(trustedCerts);
// 传入验证选项执行签名验证
var verify = pkcs7.VerifySignatureIntegrityAndAuthenticity(verificationOptions);

2. 未处理LTV(长期验证)数据

如果第二个签名包含LTV扩展数据(用于证书过期后仍能验证签名有效性),Adobe会自动解析这些数据,但iText7默认不处理LTV,这会导致验证失败。

解决代码调整:

在初始化SignatureUtil后添加LTV验证逻辑:

// 初始化LTV验证器
var ltvVerifier = new iText.Signatures.LtvVerification(pdfDocument);
ltvVerifier.SetCertificateOption(iText.Signatures.LtvVerification.CertificateOption.WHOLE_CHAIN);

// 对每个签名执行LTV验证
var ltvResult = ltvVerifier.Verify(name, verificationOptions);
// ltvResult返回0表示验证通过

3. 额外细节检查

  • 确保PdfReader以只读模式打开,避免意外修改文档状态:
var readerProps = new iText.Kernel.Pdf.ReaderProperties().SetReadOnly();
using var pdfReader = new iText.Kernel.Pdf.PdfReader(mStream, readerProps);
  • 确认签名遍历顺序正确:打印签名的创建时间,确保按签名生成顺序验证:
foreach (var name in signatureUtil.GetSignatureNames())
{
    var sig = signatureUtil.GetSignature(name);
    Console.WriteLine($"签名:{name},创建时间:{sig.GetSignDate()}");
    // 后续验证逻辑
}

内容的提问来源于stack exchange,提问作者giangnt15

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.05 18:50:23