You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用iText时PDF文件签名无效问题求助

Troubleshooting Swisscom Deferred PKCS#7 Signature Invalidity

Hey there, let's work through this PKCS#7 signature issue you're facing with Swisscom's digital signature service. I've tackled similar deferred signing problems before, so here are actionable steps to diagnose and fix it:

1. Double-Check Your Hash Generation Command

First, confirm that the hash you're submitting matches exactly what Swisscom expects. Your current command is:

DIGEST_VALUE=$(openssl dgst -binary -SHA256 $FILE | openssl enc -base64 -A)
  • Verify $FILE points to the unmodified PDF you intend to sign—no accidental file corruption or permission issues should prevent openssl from reading it fully.
  • Cross-check Swisscom's documentation to ensure they require SHA256 (some test environments might default to older algorithms like SHA1, though this is rare).
  • Try removing the -A flag: some services expect multi-line base64 encoding instead of a single line. Test both formats to see if that resolves the mismatch.

2. Confirm You're Signing the Correct PDF Hash

Deferred signing (the "PKCS#7 - Deferred S..." scenario) often requires hashing a specific signature field in the PDF, not the entire file. If you're generating a hash of the full PDF, the PKCS#7 response from Swisscom won't bind correctly to the document, resulting in an invalid signature.

To fix this:

  • Use a PDF tool (like iText, pdftk, or Adobe Acrobat's pre-sign feature) to create an empty signature field in your PDF first.
  • Generate the hash specifically for that signature field's placeholder content, not the entire document, then submit that hash to Swisscom.

3. Validate the PKCS#7 Response Structure

Instead of relying on external decoders, use openssl to inspect the response directly (save the PKCS#7 data to a file like signature.p7s):

  • Check the certificate chain:
    openssl pkcs7 -in signature.p7s -inform DER -print_certs
    
    Ensure the chain includes Swisscom's test CA certificate and your test user's certificate, with no expired or revoked entries.
  • Verify the signature structure (skip trust chain checks temporarily):
    openssl pkcs7 -in signature.p7s -inform DER -verify -noverify
    
    If this command throws errors, the PKCS#7 response itself is malformed, and you'll need to follow up with Swisscom's support or check your request parameters.

4. Properly Embed the PKCS#7 into the PDF

A standalone PKCS#7 file won't make the PDF signed—you need to embed it into the PDF's signature field. Use tools like:

  • pdftk (command-line) to inject the signature into the pre-created field.
  • iText (programmatic) for more control over the embedding process.
  • Adobe Acrobat's "Apply Signature" feature if you're doing this manually.

After embedding, use Adobe Acrobat to validate the signature—its error messages are more detailed and will point to whether the issue is with the hash, certificate, or embedding process.

If you still hit walls, share the exact validation error message (e.g., "Signature doesn't match document content" or "Untrusted certificate chain") and the output of the openssl commands above. That'll help narrow down the root cause faster.

内容的提问来源于stack exchange,提问作者boss

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:21:59