Validating signatures
Check a document's digital signatures — whether it changed, whether each signature is genuine, whether you trust the signer — and adding to it.
Nixt PDF checks every digital signature in a document on your computer, and answers three separate questions about each one:
- Has the document changed since it was signed?
- Is the signature genuine — was it made with the key in the signer’s certificate?
- Do you trust the signer — is the certificate, or one that issued it, one you have chosen to trust?
A green tick in other software often stands for all three at once. Nixt PDF shows each answer on its own, because a document can be unchanged and genuinely signed by someone you have no reason to trust.
At a glance: the signature badge
A signed document shows a badge on the window’s bar, next to its name:
- Signed — every signature checks, and nothing has been added since.
- Otherwise, the most serious result among the signatures, such as Changed after signing, Does not match or Not genuine.
Rest the pointer on the badge for what it means. A document with only empty signature fields shows no badge.
The Signatures dialog
- On the Fill & Sign tab, click Check signatures… — or Protect › Signatures…, or More › Signatures….
- The Signatures dialog lists every signature field in the document, signed or not.
A document with none says This document is not signed and has no signature field in it.
What each signature shows
- The result of checking it — see Results.
- Who signed, as you judge it — see Trust. Rest the pointer on it for an explanation.
- The field’s name. A timestamp applied to the whole document is marked (a timestamp on the document).
- A sentence explaining the result. When a signature can’t be checked, it says Nixt PDF cannot check this signature because and the reason.
- Done after it was signed — what has been added to the document since, when anything has. See What was done after signing.
Then the details the signature carries, when it has them:
| Detail | What it tells you |
|---|---|
| Typed by the signer | The name the signer’s software wrote into the signature. It isn’t checked. |
| The certificate says | The name, organisation and country in the signer’s certificate. |
| Issued by | Who issued the certificate. |
| Made with its key | Yes — the signature checks against the certificate, or No. |
| Signed at | When it was signed. |
| The document says | A different signing time recorded in the document, when there is one. |
| Timestamped | The time and the authority that timestamped it, with — which does not check added if the timestamp’s own signature fails. |
| Reason, Place, Contact | What the signer entered. |
| Certifies it | For a certifying signature: Allowing and what it allows. |
| Hashed with | The hash algorithm, such as SHA-256. |
| Signs revision | Which revision of the file it signs. |
| Added since | How much of the file was added after it was signed, such as 12% of the file. |
And these buttons, for a signed field:
| Button | What it does |
|---|---|
| Go to it | Closes the dialog and goes to the signature’s page. |
| Certificate… | Opens the signer’s certificate. See The Certificate dialog. |
| Trust this signer… or Trust and a name … | Opens the certificate to trust — the signer’s own, or the authority at the top of its chain. Shown when the signer isn’t already trusted. |
| Save the version that was signed… | Saves the document exactly as it was when this signature was made. Shown when something was added afterwards. |
Results
| Result | What it means |
|---|---|
| Unchanged since it was signed | Every byte the signature covers is the byte that was signed, the signature was made with the key in its certificate, and it covers the whole file. |
| Changed after signing | The signed part is intact, and something has been added to the file since. What was added is listed. Filling in a form or signing again is expected; changing what the pages say is not. |
| Does not match | The document doesn’t match what the signature says it should. It has been altered since it was signed. |
| Not genuine | The signature was not made by the key in the certificate it carries. Either the signature or the document has been tampered with, and nothing it claims can be relied on. |
| Cannot be checked | The signature uses something Nixt PDF doesn’t check. The reason is given. |
| Broken | The signature doesn’t say which part of the file it covers, or says something the file can’t satisfy. |
| Not signed | An empty signature field. Common and not a problem: a form sent out to be signed has one on every copy. |
Changed after signing is normal for a document that was signed and then filled in, commented on or signed again — every later signature leaves earlier ones in this state. Read Done after it was signed to decide whether what was added matters.
Trust
| Label | What it means |
|---|---|
| Trusted by you | The certificate, or the authority that issued it, is one you have chosen to trust. |
| Self-signed | The certificate vouches for itself. Only trust it if you know it is theirs — compare its fingerprint with one they give you some other way. |
| Issuer not trusted | The certificate was issued by an authority you haven’t chosen to trust. |
| Certificate out of date | A certificate involved wasn’t valid at the time the document says it was signed. |
| Signer not known | The signature carries no certificate Nixt PDF could read. |
Trust is judged only against certificates you added yourself. Nixt PDF comes with none, so a signature from an authority you haven’t added shows Issuer not trusted until you trust it.
Trusting a signer
- In the Signatures dialog, click Trust this signer… (or Trust followed by the authority’s name).
- In the Certificate dialog, check the SHA-256 fingerprint with the signer or the authority some other way.
- Click Trust it.
The dialog updates to show the new result. To manage everything you trust, use Trusted certificates…; see Digital IDs.
What was done after signing
When a signature doesn’t cover the end of the file, Nixt PDF compares the document as it was signed with the document as it is, and lists what changed:
- What is drawn on page 2 was changed (or on several pages) — shown in red.
- 1 page was added or pages were removed — added pages are shown in red.
- form fields were added, removed, or filled in or changed.
- Signed again, 1 time.
- comments were added, changed or removed.
- Its bookmarks, attachments or opening behaviour were changed.
Changes to what the pages draw are the ones that alter what was signed. Stamps fixed to the page, redaction and edited text all count.
Certified documents
A certifying signature says what may change afterwards. When what was done goes beyond that, the dialog says in red What was done after it breaks its certification: it allowed only and what it allowed, and the badge on the window’s bar shows Does not match.
Seeing what was signed
Click Save the version that was signed… to save the document exactly as the signer saw it. The name starts as the document’s name followed by -as-signed.pdf. The message says Saved the document as it was when it was signed.
Adding to a signed document
Nixt PDF adds your changes after the signed part of the file, so the signatures stay intact and anyone checking them is told what was added. The first time you choose a tool that changes a signed document, a dialog explains what that means for this document:
| Dialog title | What it says |
|---|---|
| This document is signed | What you add is kept apart from what was signed, so the signatures stay intact, and anyone checking them is told exactly what was added. |
| This document is certified for filling in, signing and comments | Comments, stamps and signatures keep the certification. Changing what is drawn on the pages breaks it. |
| This document is certified for filling in and signing | Filling in the form and signing keep the certification. Comments, stamps and anything drawn on the page break it. |
| This document is certified against any change | Anything you add breaks the certification, and every reader will say so. |
Click Change it anyway to go on, or Leave it as it is to keep the document as it is.
Signatures Nixt PDF checks
- Signatures in the PAdES and PKCS#7 formats, including older SHA-1 and X.509 kinds, and document timestamps.
- RSA signatures and elliptic-curve signatures on the P-256, P-384 and P-521 curves.
- Signatures in password-protected documents.
- Timestamps on signatures, which are checked too. A timestamp that checks is the time a signature is judged at.
When a signature uses something else, it shows Cannot be checked and the reason, such as it uses a digest Nixt PDF does not implement.
What checking doesn’t tell you
The Signatures dialog ends with What this does not tell you:
- Whether a certificate has been revoked since it was used. Finding out means asking the certificate’s issuer, over the network, about the document you’re reading, and Nixt PDF doesn’t send anything about your documents anywhere.
What the checks do establish is whether the document has changed, whether the signature was made with the key in its certificate, and whether that certificate is one you have chosen to trust.
Something unclear or out of date on this page? Tell us.