Spire.PDF is a professional PDF library applied to creating, writing, editing, handling and reading PDF files without any external dependencies. Get free and professional technical support for Spire.PDF for .NET, Java, Android, C++, Python.

Mon Feb 06, 2023 1:57 pm

Hi,

Is it possible to add a signature to a PDF file using a Cloud based HSM provider like Google, AWS or Azure?

Thanks, Andy

andygarratt
 
Posts: 5
Joined: Thu Jul 01, 2021 12:18 pm

Tue Feb 07, 2023 10:10 am

Hello,

Thanks for your inquiry.
The scenario you mentioned can be achievd, however, I suggest you can first create project to test this scenario.

Sincerely
Abel
E-iceblue support team
User avatar

Abel.He
 
Posts: 1010
Joined: Tue Mar 08, 2022 2:02 am

Tue Feb 07, 2023 10:45 am

Thanks Abel,

Do you have an examples of this or sample code?

The only example I can find is using a pfx which I believe is no longer deemed as valid by Adobe (they will show it as invalid as the certificate has to be on a HSM or USB FIPs device).

We already have a licensed and in support subscription for Spire.PDF.

Thanks, Andy

andygarratt
 
Posts: 5
Joined: Thu Jul 01, 2021 12:18 pm

Wed Feb 08, 2023 7:18 am

Hello,

Thanks for your feedback.
In Azure, to make sure that the pfx file can be used correctly and the signature is valid in the result Pdf file, you need to add and set the Azure app setting WEBSITE_LOAD_USER_PROFILE to 1 according to the help document(as shown in the screenshot below).

Sincerely
Abel
E-iceblue support team
User avatar

Abel.He
 
Posts: 1010
Joined: Tue Mar 08, 2022 2:02 am

Wed Feb 08, 2023 7:36 am

Hi Abel,

If using a Cloud Based HSM there is no PFX file.

Thanks, Andy

andygarratt
 
Posts: 5
Joined: Thu Jul 01, 2021 12:18 pm

Wed Feb 08, 2023 8:11 am

Hello,

Thanks for your feedback.
If the cloud Based Hsm don't support pfx file, the signature will become invalid in result pdf and there is no solution for it.

Sincerely
Abel
E-iceblue support team
User avatar

Abel.He
 
Posts: 1010
Joined: Tue Mar 08, 2022 2:02 am

Wed Feb 08, 2023 8:43 pm

Hi Abel,

You can use Cloud HSM's to sign PDF files, as an example GemBox.PDF supports it as per this forum post.

https://forum.gemboxsoftware.com/t/how- ... oudhsm/568

So there is no restriction from the PDF side, thats a supported process, my question is if it is something Spire.PDF can support, or if it's something planned (since Adobe do not allow trusted signatures using pfx file anymore, from Adobe's Trusted list)?

Thanks, Andy

andygarratt
 
Posts: 5
Joined: Thu Jul 01, 2021 12:18 pm

Thu Feb 09, 2023 11:19 am

Hello,

Thanks for your feedback.
Now, our product support using an actual HSM that the certificate’s private key never leaves the HSM to do signature, you can refer to the following code:
I attached the CustomPKCS7SignatureFormatter.cs file

Code: Select all
using PDFTest.Security.DigitalSignature;
using Spire.Pdf;
using Spire.Pdf.Graphics;
using Spire.Pdf.Security;
using System.Drawing;
using System.Security.Cryptography.X509Certificates;

namespace TestPdfHsm32292
{
    internal class Program
    {
        static void Main(string[] args)
        {
            PdfDocument doc = new PdfDocument();
            doc.LoadFromFile(@"test.pdf");
            X509Certificate2 cert = new X509Certificate2(@"gary.pfx", "e-iceblue");
            //create CustomPKCS7SignatureFormatter
            CustomPKCS7SignatureFormatter customPKCS7SignatureFormatter = new CustomPKCS7SignatureFormatter(cert);
            PdfSignature signature = new PdfSignature(doc, doc.Pages[0], customPKCS7SignatureFormatter, "signature0");
            signature.Bounds = new RectangleF(new PointF(90, 550), new SizeF(270, 90));
            signature.GraphicsMode = GraphicMode.SignDetail;
            signature.NameLabel = "Signer:";
            signature.Name = "Test";
            signature.Reason = "The certificate of this document";
            signature.DistinguishedNameLabel = "DN: ";
            signature.DocumentPermissions = PdfCertificationFlags.AllowFormFill | PdfCertificationFlags.ForbidChanges;
            signature.SignDetailsFont = new PdfFont(PdfFontFamily.TimesRoman, 10f);
            signature.SignNameFont = new PdfFont(PdfFontFamily.Courier, 15);
            signature.SignImageLayout = SignImageLayout.None;
            //Save pdf file.
            doc.SaveToFile(@"output.pdf", Spire.Pdf.FileFormat.PDF);
        }
    }
}


Sincerely
Abel
E-iceblue support team
User avatar

Abel.He
 
Posts: 1010
Joined: Tue Mar 08, 2022 2:02 am

Thu Feb 09, 2023 11:55 am

Thanks Abel,

I'm not sure that sample is correct though, it suggests you are creating a certificate and not using an existing certificate in the HSM? Please let me know if I am wrong though.

To help undertsand the requirement, for a trusted signing certificate for Adobe the issuer has to meet the AATL requirements which state (https://helpx.adobe.com/content/dam/hel ... ents20.pdf):

"EE4
All end-entity key pairs must:
.....
(c) be stored in a secure cryptographic hardware device that:
1) is certified:
i. FIPS 140-2 Level 2; or
ii. Common Criteria (ISO 15408 & ISO 18045) - Protection Profiles CEN prEN
14169 (all parts applicable to the device type) or standards such as CEN EN
419 241 series or equivalent, for remotely managed devices; or
iii. by an EU Member State as a Qualified Signature Creation Device (QSCD) after
1 July 2016, or that was recognized as a Secure Signature Creation Device
(SSCD) by an EU Member State designated body before 1 July 2016.
2) is controlled by the signer (or by the subscriber if the signer is not a physical person):
i. either directly, by possession (after secure hand-over to the subscriber when
applicable). In this case:
1. the activation of the private key must require the signer’s
authentication;
2. the device must prevent exportation or duplication of the private key.
ii. or via a third party managing the secure cryptographic hardware device on
behalf of the signer. In this case:
1. the key activation must rely on at least a 2-factor authentication (2FA)
process;
2. no duplication of the private key is allowed, except for duly
documented service availability purpose, and the duplicated key must
abide at least the same security measures as the original;
3. the third party must disclose to Adobe the documentation (technical,
procedural and operational) on the management of the secure
cryptographic hardware device;
4. the third party agrees on an annual verification of the conformity of
the service with its Practice Statement, or must be certified against
standards like the CEN EN 419 241 series listed above or equivalent."

So to be able to sign a PDF with a publically trusted certificate a pfx can no longer be used, as the private key needs to remain in the HSM at all times, be it a cloud HSM, a HSM in a computer or a FIPS USB Drive.

The certificate is fine to be outside of the HSM, the private key however cannot be exported.

Cheers, Andy

andygarratt
 
Posts: 5
Joined: Thu Jul 01, 2021 12:18 pm

Fri Feb 10, 2023 10:15 am

Hello,

Thanks for your feedback.
We need some time to do further investigation, and I'll give you feedback asap after investigation.

Sincerely
Abel
E-iceblue support team
User avatar

Abel.He
 
Posts: 1010
Joined: Tue Mar 08, 2022 2:02 am

Return to Spire.PDF