使用iText时PDF文件签名无效问题求助
Hey there, let's work through this PKCS#7 signature issue you're facing with Swisscom's digital signature service. I've tackled similar deferred signing problems before, so here are actionable steps to diagnose and fix it:
1. Double-Check Your Hash Generation Command
First, confirm that the hash you're submitting matches exactly what Swisscom expects. Your current command is:
DIGEST_VALUE=$(openssl dgst -binary -SHA256 $FILE | openssl enc -base64 -A)
- Verify
$FILEpoints to the unmodified PDF you intend to sign—no accidental file corruption or permission issues should prevent openssl from reading it fully. - Cross-check Swisscom's documentation to ensure they require SHA256 (some test environments might default to older algorithms like SHA1, though this is rare).
- Try removing the
-Aflag: some services expect multi-line base64 encoding instead of a single line. Test both formats to see if that resolves the mismatch.
2. Confirm You're Signing the Correct PDF Hash
Deferred signing (the "PKCS#7 - Deferred S..." scenario) often requires hashing a specific signature field in the PDF, not the entire file. If you're generating a hash of the full PDF, the PKCS#7 response from Swisscom won't bind correctly to the document, resulting in an invalid signature.
To fix this:
- Use a PDF tool (like iText, pdftk, or Adobe Acrobat's pre-sign feature) to create an empty signature field in your PDF first.
- Generate the hash specifically for that signature field's placeholder content, not the entire document, then submit that hash to Swisscom.
3. Validate the PKCS#7 Response Structure
Instead of relying on external decoders, use openssl to inspect the response directly (save the PKCS#7 data to a file like signature.p7s):
- Check the certificate chain:
Ensure the chain includes Swisscom's test CA certificate and your test user's certificate, with no expired or revoked entries.openssl pkcs7 -in signature.p7s -inform DER -print_certs - Verify the signature structure (skip trust chain checks temporarily):
If this command throws errors, the PKCS#7 response itself is malformed, and you'll need to follow up with Swisscom's support or check your request parameters.openssl pkcs7 -in signature.p7s -inform DER -verify -noverify
4. Properly Embed the PKCS#7 into the PDF
A standalone PKCS#7 file won't make the PDF signed—you need to embed it into the PDF's signature field. Use tools like:
pdftk(command-line) to inject the signature into the pre-created field.- iText (programmatic) for more control over the embedding process.
- Adobe Acrobat's "Apply Signature" feature if you're doing this manually.
After embedding, use Adobe Acrobat to validate the signature—its error messages are more detailed and will point to whether the issue is with the hash, certificate, or embedding process.
If you still hit walls, share the exact validation error message (e.g., "Signature doesn't match document content" or "Untrusted certificate chain") and the output of the openssl commands above. That'll help narrow down the root cause faster.
内容的提问来源于stack exchange,提问作者boss

