Digital IDs

What a digital ID is, making a self-signed one, the .p12 and .pfx files Nixt PDF reads, how keys are handled, and trusted certificates.

A digital ID is a file that holds two things: a certificate, which names you and can be shared with anyone, and a private key, which makes signatures and must be kept secret. The file is protected with a password. Digital IDs usually come as .p12 or .pfx files.

You use a digital ID to sign with a digital ID. Other people use your certificate to check that a signature is really yours.

How Nixt PDF handles your digital ID

  • Your digital ID is never stored. There is no list of digital IDs in Nixt PDF and nothing is added to your system’s keychain. You choose the file each time you sign.
  • Your password is never stored. You type it each time you sign.
  • Both are forgotten when the signing dialog closes. The file’s contents and the password are used for that one signature and nothing holds on to them.
  • Nothing is sent anywhere. Opening a digital ID and making a signature happen on your computer. The only thing that ever leaves it is a fingerprint of a signature, and only when you ask for a trusted timestamp.

Because nothing is kept, keep your digital ID file somewhere safe and backed up, and remember its password. If you lose either, Nixt PDF can’t recover them.

Getting a digital ID

  • From your organisation or a certificate authority. Signatures made with an ID issued by an authority other people already trust are shown as trusted by their software. Export it as a .p12 or .pfx file with a password, and use it straight away.
  • By making a self-signed one in Nixt PDF, below. A self-signed ID is enough for signatures between people who trust each other’s certificates, but nobody’s software trusts it until they choose to.

Making a self-signed digital ID

  1. On the Fill & Sign tab, click Create a digital ID… (or choose More › Create a digital ID…).
  2. In the Create a digital ID dialog, fill in who it names:
FieldWhat it’s for
Your nameRequired. Starts with the name in Your details.
EmailOptional.
OrganisationOptional.
DepartmentOptional.
CountryOptional. A two-letter country code, such as GB or US.
  1. Choose the kind of key:
ChoiceWhat the dialog says
RSA, 2048 bitsRead by every PDF reader, including old ones. The default.
RSA, 3072 bitsStronger, and slower to make.
ECDSA P-256As strong as RSA 3072, and small. Older readers cannot check it.
  1. Under Valid for, choose 1 year, 2 years, 3 years, 5 years (the default) or 10 years.
  2. Type a password in Password for the file, and again in The password again. It must be at least eight characters — this password is all that protects the key.
  3. Leave Trust it on this computer, so signatures made with it show as trusted here ticked, or untick it.
  4. Tick Readable by older software (triple DES rather than AES — weaker, so only if it is needed) only if older software you rely on can’t open the file otherwise.
  5. Click Create and save…. It reads Making it… while the key is made, which can take a moment.
  6. In the Save your digital ID dialog, choose where to keep the file. The name starts as your name followed by digital ID.p12.

Create and save… is dimmed until Your name is filled in, the two passwords match and are at least eight characters, and Country is empty or two letters.

The certificate is made for signing documents only.

If you cancel the save dialog, the dialog says Not saved. The digital ID has been thrown away — nothing of it was kept. Nothing is left behind.

Your digital ID is made

When the file is saved, the message says Saved your digital ID. Keep the file and its password safe: Nixt PDF kept neither. The dialog changes to Your digital ID is made and shows the certificate’s fingerprint — a long string of letters and numbers that identifies it.

  • Click Save the certificate to share… to save the certificate on its own, as a .cer file named after you. It contains no private key.
  • Click Done to close.

Sign with your new ID from Fill & Sign › Digital ID or More › Sign with a digital ID….

Sharing your certificate

For someone to see your signatures as trusted, they need to trust your certificate.

  1. Send them your certificate file — from Save the certificate to share…, or from Save it… in the Certificate dialog.
  2. Read them its fingerprint some other way — by phone or in person — so they can check the file they received really is yours.
  3. They add it with Trusted certificates… and compare the fingerprint before they click Trust it.

Digital ID files Nixt PDF can open

Nixt PDF opens .p12 and .pfx files protected in any of the common ways, including the older ways used by some older exports. The key inside must be one PDF readers can check:

  • RSA keys
  • Elliptic-curve keys on the P-256, P-384 or P-521 curves

The file must contain both the certificate and its private key. If it contains the issuing authorities’ certificates too, they are included in the signature.

When a digital ID doesn’t open

MessageWhat it meansWhat to do
That file is not a digital ID. A digital ID is a .p12 or .pfx file.The file isn’t a digital ID file.Choose the .p12 or .pfx file.
That password does not open this digital ID. Passwords are exact — check the capitals.The password is wrong.Type it again, checking capitals and keyboard layout.
This digital ID is protected in a way Nixt PDF cannot openThe file uses protection Nixt PDF doesn’t read. The message may add the detail.Export the ID again from the software that holds it, with standard AES protection.
This file holds certificates but no private key, so it cannot sign anything. It may be the public half of somebody’s ID.It’s a certificate, not a digital ID.Use the file that includes the private key.
This file holds a private key but no certificate to go with it.The certificate is missing.Export the ID again with its certificate.
This digital ID’s key is of a kind Nixt PDF cannot sign with. RSA and the three NIST elliptic curves are the kinds PDF readers check.The key type isn’t supported.Use an RSA or P-256, P-384 or P-521 key.
Nixt PDF could not open that digital ID followed by detailsSomething unexpected went wrong.Try again; if it repeats, export the ID again.

Trusted certificates

When Nixt PDF checks a signature, it answers who signed by comparing the signer’s certificate with the certificates you have chosen to trust. Nothing is trusted unless you add it.

  1. On the Fill & Sign tab, click Trusted certificates… (or choose More › Trusted certificates…).
  2. The Trusted certificates dialog lists each certificate you trust, with:
    • who it belongs to;
    • Self-signed, or Issued by and the issuer, and until the date it expires;
    • its fingerprint.

When you trust none, it says None yet.

Adding a trusted certificate

  1. In the Trusted certificates dialog, click Add a certificate….
  2. In the Choose a certificate (.cer, .crt, .pem) dialog, choose the certificate file. A file can hold several certificates.
  3. For each certificate, a Trust dialog shows its name and fingerprint. Compare the fingerprint with one its owner gave you some other way.
  4. Click Trust it, or Cancel to skip that certificate.

Trusting a certificate also trusts every certificate it issued. Trusting an organisation’s issuing certificate therefore trusts every signer that organisation issued an ID to.

A file that isn’t a certificate shows its name followed by is not a certificate Nixt PDF can read.

You can also trust a certificate from the Signatures dialog, with Trust this signer…; see Validating signatures.

Removing a trusted certificate

In the Trusted certificates dialog, click Stop trusting beside it. Signatures made with it are no longer shown as trusted.

Your trusted certificates are kept on this computer, filed under their fingerprints.

The Certificate dialog

Everything it says… in the signing dialog, and Certificate… in the Signatures dialog, open the Certificate dialog:

FieldWhat it shows
Belongs toThe name, organisation and country.
EmailEmail addresses in the certificate, when there are any.
Issued byThe issuer, or Itself (self-signed).
Valid from, Valid untilThe dates the certificate is valid between.
KeyThe kind of key, such as RSA 2048 or ECDSA P-256.
May be used forWhat the certificate allows its key to do, in the certificate’s own terms, such as digitalSignature.
Serial numberThe certificate’s serial number.
SHA-256 fingerprintThe fingerprint to compare with its owner’s.

Buttons:

  • Trust it or Stop trusting it — adds the certificate to, or removes it from, your trusted certificates.
  • Save it… — saves the certificate as a .cer file.
  • Close.

Something unclear or out of date on this page? Tell us.