SDK version: spire.pdf for Java version 10.1.9
I am having issues verifying two signatures applied on the same PDF.
When trying to verify the signatures, signature one always fails (with verifyDocModified returning true). The second signature verifies just fine.
I see the issue either with PDFs signed via e.g. Adobe Reader, or by using Spire.pdf directly.
Code to reproduce the issue:
- Code: Select all
public class TestSignPdf {
public static void main(final String[] args)
throws IOException {
LicenseProvider.setLicense("license.elic.xml");
// This is the example code to create a one-page PDF with some text on it
PdfDocument doc = new PdfDocument();
PdfPageBase page = doc.getPages().add(PdfPageSize.A4, new PdfMargins(35f));
String titleText = "What is Spire.pdf";
PdfSolidBrush titleBrush = new PdfSolidBrush(new PdfRGBColor(Color.BLUE));
PdfSolidBrush paraBrush = new PdfSolidBrush(new PdfRGBColor(Color.BLACK));
PdfTrueTypeFont titleFont = new PdfTrueTypeFont(new Font("Times New Roman",Font.BOLD,18));
PdfTrueTypeFont paraFont = new PdfTrueTypeFont(new Font("Times New Roman",Font.PLAIN,12));
PdfStringFormat format = new PdfStringFormat();
format.setAlignment(PdfTextAlignment.Center);
page.getCanvas().drawString(titleText, titleFont, titleBrush, new Point2D.Float((float)page.getClientSize().getWidth()/2, 20),format);
String paraText = "A nice SDK to read and write PDFs!";
PdfTextWidget widget = new PdfTextWidget(paraText, paraFont, paraBrush);
Rectangle2D.Float rect = new Rectangle2D.Float(0, 50, (float)page.getClientSize().getWidth(),(float)page.getClientSize().getHeight());
PdfTextLayout layout = new PdfTextLayout();
layout.setLayout(PdfLayoutType.Paginate);
widget.draw(page, rect, layout);
//Save to file
doc.saveToFile("unsigned.pdf");
doc.dispose();
// Here Starts the interesting part
// Essentially someone would have created the unsigned document, now
// reviewer#1 opens it and signs it:
doc.loadFromFile("unsigned.pdf");
addSignature(doc, "test.pfx", "test", 100, "signature1");
doc.saveToFile("signed.pdf");
doc.dispose();
// Now, reviewer#2 opens it and signs it again:
doc.loadFromFile("signed.pdf");
addSignature(doc, "test2.pfx", "test2", 400, "signature2");
doc.saveToFile("signed.signed.pdf");
doc.dispose();
// Check signatures
doc.loadFromFile("signed.signed.pdf");
PdfFormWidget form = (PdfFormWidget) doc.getForm();
PdfFormFieldWidgetCollection c = form.getFieldsWidget();
for (int i = 0; i < c.getCount(); i++) {
PdfField f = c.get(i);
if (f instanceof PdfSignatureFieldWidget) {
PdfSignature sig = ((PdfSignatureFieldWidget) f).getSignature();
System.out.println(
"signature '" + sig.getSignatureName() + "' valid: " + sig.verifySignature());
System.out.println(
"modified: " + sig.verifyDocModified());
}
}
}
private static void addSignature(
final PdfDocument doc,
final String pfxFile,
final String pfxPassword,
final float x,
final String signatureName) {
//Create X509Certificate2
PdfCertificate x509 = new PdfCertificate(pfxFile, pfxPassword);
X509Certificate2 cert = new X509Certificate2(pfxFile, pfxPassword);
//Create PdfOrdinarySignatureMaker
PdfOrdinarySignatureMaker signatureMaker =
new PdfOrdinarySignatureMaker(doc, x509);
//Set signature appearance
PdfSignatureAppearance signatureAppearance = new PdfSignatureAppearance(
signatureMaker.getSignature());
signatureAppearance.setNameLabel("Signer:");
//Set details for the signature1
com.spire.pdf.interactive.digitalsignatures.PdfSignature sig =
signatureMaker.getSignature();
sig.setName(cert.getSubject());
//Add the first signature
signatureMaker.makeSignature(
signatureName,
doc.getPages().get(0),
x,
300,
120,
70,
signatureAppearance);
}
}
The code above will print the following:
- Code: Select all
signature 'signature1' valid: false
modified: true
signature 'signature2' valid: true
modified: false
By using e.g., Adobe Reader, the document verifies just fine, but fails with Spire.pdf. Any suggestion what I am doing wrong?
Thanks for the help!