Spire.PDF is a professional PDF library applied to creating, writing, editing, handling and reading PDF files without any external dependencies. Get free and professional technical support for Spire.PDF for .NET, Java, Android, C++, Python.

Thu Jun 01, 2023 11:55 am

Hi

We've noticed that when a signed PDF is opened on a different computer, the entire certificate chain is not present on the signature.
Since usually only the root certificate is trusted, this signature does not register as trusted for the new user.

Is there a way to include the entire chain in the signature?

JeroenRoefs
 
Posts: 15
Joined: Thu Mar 30, 2023 1:52 pm

Fri Jun 02, 2023 9:32 am

Hello,

Thank you for your inquiry.
Sorry to tell you that this feature is currently not supported. But, we have added this feature to our future features list with the ticket number SPIREPDF-6034. Once it is achieved in the future, I will inform you in time. Sorry for the inconvenience caused.

Sincerely,
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Fri Jun 02, 2023 10:22 am

Hi Wenly,

Thank you for your quick answer.
Do you have any timeline available about implementation?
Because we were in the assumption that we could provide full certificate trust by using your product and actually has sold it as such to a customer.

Thanks in advance,
Maarten

mkesselaers
 
Posts: 1
Joined: Thu May 11, 2023 6:47 am

Mon Jun 05, 2023 6:28 am

Hello,

Sorry for the late reply due to the weekend.
Unfortunately, we cannot provide you with a specific time schedule. Once this feature is implemented in the future, we will inform you immediately. Thank you for your understanding.

Sincerely
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Tue Jun 06, 2023 9:33 am

Hello,

Thank you for your patience!
Glad to inform you that we just released Spire.PDF Pack(Hot Fix) Version:9.6.0 which implements full certificate chain support. Please use this version and refer to the sample code below to test.
Code: Select all
            PdfDocument doc = new PdfDocument();
            doc.LoadFromFile("Sample.pdf");
      
            X509Certificate2Collection collection = new X509Certificate2Collection();

            //Provide the PFX file path, password, and X509KeyStorageFlags flag
            collection.Import("gary.pfx", "password", X509KeyStorageFlags.DefaultKeySet);

            PdfPKCS7Formatter formatter = new PdfPKCS7Formatter(collection[collection.Count - 1], false);
            formatter.ExtraCertificateStore = collection;//full certificate chain support. 

            PdfOrdinarySignatureMaker maker = new PdfOrdinarySignatureMaker(doc, formatter);
            PdfSignature signature = maker.Signature;

            //Setting Signature Information
            signature.Name = "test";
            signature.ContactInfo = "028-1381234567";
            signature.Location = "CN";
            PdfSignatureAppearance appearance = new PdfSignatureAppearance(signature);
            //setting label
            appearance.NameLabel = "Singer:";
            appearance.ContactInfoLabel = "ContactInfo:";
            appearance.LocationLabel = "Location:";
            appearance.ReasonLabel = "Reason:";
            appearance.DateLabel = "Date:";

            //Add a picture
            appearance.SignatureImage = PdfImage.FromFile("imagePath");
            //Picture mode, a total of two
            appearance.SignImageLayout = SignImageLayout.None;//normal
          //appearance.SignImageLayout = SignImageLayout.None;//stretching

            //Signature display mode, 5 types
            //1.Signature and signature details
            appearance.GraphicMode =GraphicMode.SignNameAndSignDetail;

            //The location of the signature in the pdf
            maker.MakeSignature("sognature", doc.Pages[0], 50, 500, 250, 150,appearance);

            doc.SaveToFile("result.pdf");


Sincerely
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Tue Jun 06, 2023 12:29 pm

Hi

Wow, thank you for the quick response!
I've been trying to get it to work but still running into issues.

I don't have a .pfx file, but a X509Certificate2 Object that I get via the C509Certificate2UI.SelectFromCollection method.
The certificate I'm trying to sign with comes from a smart card.

To build the collection I did the following:
Code: Select all
         var chain = new X509Chain();

         chain.Build(cert);

         var extraCerts = new X509Certificate2Collection();

         foreach (var element in chain.ChainElements)
         {
            extraCerts.Insert(0, element.Certificate);
         }

         PdfPKCS7Formatter formatter = new PdfPKCS7Formatter(extraCerts[extraCerts.Count - 1], false);
         formatter.ExtraCertificateStore = extraCerts; //full certificate chain support.


I can confirm that the collection holds the 3 certificates that I want.
But I'm still getting only one certificate on my signature.

JeroenRoefs
 
Posts: 15
Joined: Thu Mar 30, 2023 1:52 pm

Wed Jun 07, 2023 10:01 am

Hi,

Thank you for your feedback.
We are conducting further investigation, and we will inform you as soon as we have any results. Sorry for the inconvenience caused.

Sincerely
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Thu Jun 08, 2023 9:54 am

Hello,

Sorry to bother you.
Could you please provide us with the debug information and code of using Smart Card to generate the certificate chain? This would be very helpful for our further investigation. You could attach them here or send them to us via email ([email protected]). Thanks in advance.

Sincerely,
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Wed Jun 14, 2023 8:09 am

Hi

No problem.

This is the code I'm running:

Code: Select all
                static void GetDoubleSignature(PdfDocument doc, X509Certificate2 cert)
      {
         var chain = new X509Chain();

         chain.Build(cert);

         var extraCerts = new X509Certificate2Collection();

         foreach (var element in chain.ChainElements)
         {
            extraCerts.Insert(0, element.Certificate);
         }

         PdfPKCS7Formatter formatter = new PdfPKCS7Formatter(extraCerts[extraCerts.Count - 1], false);
         formatter.ExtraCertificateStore = extraCerts; //full certificate chain support.

         //formatter.OCSPService = new OCSPHttpService("http://ocsp.eid.belgium.be/");


         PdfOrdinarySignatureMaker maker = new PdfOrdinarySignatureMaker(doc, formatter);

         //The location of the signature in the pdf
         maker.MakeSignature("signature");
      }


And as you can see, the extraCerts collection contains 3 members:
Screenshot 2023-06-14 100242.png


When I view the resulting pdf on my own PC, where I did the signing, I can see the full chain:
Screenshot 2023-06-14 100631.png


When I view it on a different PC, I only see the "bottom" certificate:
Screenshot 2023-06-14 100748.png


If there's anything else you want, please let me know.

JeroenRoefs
 
Posts: 15
Joined: Thu Mar 30, 2023 1:52 pm

Wed Jun 14, 2023 9:54 am

Hello,

Thanks for sharing the information.
Our development team will investigate further based on the information you provided. Once it is resolved, I will inform you in time. Sorry for the inconvenience caused.

Sincerely,
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Tue Aug 01, 2023 7:04 am

Is there any update on this? Do you need more information from me?

JeroenRoefs
 
Posts: 15
Joined: Thu Mar 30, 2023 1:52 pm

Tue Aug 01, 2023 10:27 am

Hello,

Thanks for your follow-up.
Sorry, so far the issue SPIREPDF-6034 has not been completely solved. Due to the complexity of the issue regarding the certificate chain, the development team needs to investigate a lot of content, so the time required is relatively long. Our development team is still working hard to investigate. We are also continuously following up on this issue and will notify you promptly of any further updates. We hope you can understand.

Sincerely,
Wenly
E-iceblue support team
User avatar

Wenly.Zhang
 
Posts: 149
Joined: Tue May 16, 2023 2:19 am

Return to Spire.PDF