PKCS#7 detached + CAdES + RFC 3161 timestamps, generation (pdfSign) and verification (pdfSignature/pdfTimestamp/pdfCertChain), plus the PAdES-LT Document Security Store builder (pdfDssBuilder). Most modules are fwModules (fw-bound: asn1, rsa, ecc, ed25519, sha256, sha384, sha512, bitArray, pem); pdfSigOids and pdfSha1 are lighter dispatch/legacy-hash helpers shared by the rest of the family.
| Module | Returns | Deps | Description |
|---|---|---|---|
pdfSignature |
{ typeSignature, verifySignature, verifyAllSignatures, verifyPk, locatePkcs7, DIGEST_OIDS, SIG_OIDS } |
pdfErrors, pdfParser, pdfSigOids, fw crypto |
§12.8 + ISO TS 32001/32002 — verify. |
pdfSign |
{ sign, HASH_TABLE, … } (plus _-prefixed test helpers) |
pdfErrors, pdfSigOids, pdfByteRange, pdfDssBuilder, pdfIncrementalWriter, pdfParser, pdfDocument, fw crypto |
PAdES generation, levels B/T/LT/LTA. |
pdfByteRange |
{ computeByteRange, extractSignedBytes, findContentsField, auditByteRange } |
pdfErrors |
/ByteRange §12.8.1 + hardened audit. |
pdfTimestamp |
{ parseTimestampToken, verifyTimestamp, extractTimestampFromUnsignedAttrs, OID_TST_INFO, OID_AA_TIMESTAMP } |
pdfErrors, pdfSigOids, fw crypto |
RFC 3161 §12.8.5. |
pdfCertChain |
{ parseCertificate, extractCertsFromCms, extractCertFromPem, findIssuer, validateChainOrder } |
pdfErrors, pdfSigOids, fw asn1, pem |
X.509 chain §12.8.3. |
pdfDssBuilder |
{ buildDss } |
pdfErrors, pdfSha1, bitArray |
PAdES-LT Document Security Store, §12.8.4.3. |
pdfSigOids |
{ DIGEST_OIDS, SIG_DISPATCH_OIDS, KEY_ALG_OIDS, SIG_ALG_OIDS_VERBOSE, OID_TST_INFO, OID_AA_TIMESTAMP, lookupDigest, lookupSigAlg, lookupKeyAlg, lookupSigVerbose, shortOid } |
asn1Oid |
Shared OID dispatch tables. |
pdfSha1 |
{ fn, hash } |
bitArray, utf8 |
Legacy SHA-1 — DSS /VRI keys only. |
Verification pattern
const sig = runtime.resolve('pdfSignature');
const typed = sig.typeSignature(sigField.v);
const result = sig.verifySignature(typed, documentBytes, fwBundle);
// `result.verified` / `result.pkVerified` reflect the ACTUAL outcome of the
// public-key check (RSA-PSS / ECDSA / Ed25519) — the check is wired and
// executed by construction. There is no `pdf/sig/pk-verify-not-wired` code;
// a failed check surfaces a specific `errors[]` record instead (see
// `pdfSignature`'s Errors table).
See also
pdfSignatureField— carrier in the AcroForm.- Crypto — encryption (orthogonal).