使用iText实现带OCSP的PDF签名:吊销验证问题求助
Hey, great to see you've got your core PDF signing workflow up and running! Let's start by recapping your current working process to set the stage:
- Create a blank signature field in the target PDF
- Generate the hash of that signature field and send it to your signing web service
- Fetch the completed signature object from the service
- Embed this signature object into the PDF's signature field
I'm glad @mlk helped you iron out the invalid signature issue earlier—nice progress! Now, the problem you're facing is that your signatures lack OCSP (Online Certificate Status Protocol) information, which is critical for proper revocation verification. Let's walk through how to add this to your workflow.
Updated Workflow to Include OCSP Data
OCSP provides real-time confirmation that the signer's certificate hasn't been revoked, so we need to integrate fetching and embedding this data into your signing process. Here's the adjusted step-by-step:
Fetch the OCSP response after getting the signature object
- First, extract the OCSP responder URL from the signer's digital certificate (look for the
Authority Information Accessextension; it will have an entry pointing to the OCSP service) - Send an OCSP request to that URL. Most responders require both the signer's certificate and the issuer's root/CA certificate to process the request
- Validate the OCSP response before using it: check that it's signed by a trusted OCSP responder, confirm the certificate status is "good", and ensure the response is within its validity window
- First, extract the OCSP responder URL from the signer's digital certificate (look for the
Attach the OCSP response to your signature object
- Most PDF signing libraries let you embed revocation data in the signature's CMS (Cryptographic Message Syntax) structure, or via the PDF signature dictionary's
RevocationInfoArchivalentry - Ensure the OCSP response is in DER-encoded format (the standard for OCSP data) when embedding it
- Most PDF signing libraries let you embed revocation data in the signature's CMS (Cryptographic Message Syntax) structure, or via the PDF signature dictionary's
Complete the signature embedding as before
- Now when you embed the updated signature object (with OCSP data included), PDF viewers will automatically perform revocation checks using that embedded data, resolving your verification problems
Quick Pro Tips
- If your signing web service has an option to include OCSP data in the returned signature object, use that! It saves you from handling the OCSP fetch and validation manually
- Never skip validating the OCSP response—adding untrusted or expired OCSP data can lead to new signature validation failures instead of fixing the old ones
内容的提问来源于stack exchange,提问作者boss

