Verify Digital Signatures in Document

Verify Digital Signatures in Document

GroupDocs.Signature provides the ability to verify digital signatures in documents. Digital signatures provide a secure way to verify the authenticity and integrity of documents.

What is a Digital Signature?

A digital signature is a mathematical scheme for demonstrating the authenticity of digital messages or documents. It provides:

  • Authentication: Confirms the identity of the signer
  • Integrity: Ensures the document hasn’t been modified
  • Non-repudiation: Prevents the signer from denying they signed the document

How to Verify Digital Signatures

The Signature class provides the verify method which allows you to verify digital signatures in documents. Here’s how to use it:

  1. Create a new instance of the Signature class and pass the source document path as a parameter.
  2. Instantiate the DigitalVerifyOptions object with the required options.
  3. Call the verify method of the Signature class instance and pass the DigitalVerifyOptions to it.
  4. Check the is_valid property of the returned VerificationResult.

Here’s an example of how to verify digital signatures in a document. The sample certificate certificate.pfx is protected with the password 1234567890:

from groupdocs.signature import Signature
from groupdocs.signature.options import DigitalVerifyOptions


def verify_digital_signatures():
    with Signature("signed.pdf") as signature:
        options = DigitalVerifyOptions("certificate.pfx")
        options.password = "1234567890"
        # The subject of the signing certificate must contain this text
        options.subject_name = "ProfJamesMoriarty"
        # The signing reason stored in the PDF signature must be equal to this text
        options.reason = "Approved"

        result = signature.verify(options)

        if result.is_valid:
            print(f"Document was verified successfully: {len(result.succeeded)} valid digital signature(s).")
        else:
            print("Document failed verification process.")


if __name__ == "__main__":
    verify_digital_signatures()

signed.pdf is the sample file used in this example. Click here to download it.

certificate.pfx is the sample file used in this example. Click here to download it.

Document was verified successfully: 1 valid digital signature(s).

Download full output

Note
Verification performs two independent checks. First the signature itself is verified cryptographically: if the document was altered after signing, the result is not valid regardless of any other option. Then any criteria you set on DigitalVerifyOptions - certificate, subject name, issuer name, signing time, reason, contact or location - are matched. Both must pass for is_valid to be True. For PDF documents the cryptographic check was added in GroupDocs.Signature for Python via .NET 26.10; earlier versions compared only the criteria.

Verification criteria by document format

Not every property of DigitalVerifyOptions applies to every document format. A property that does not apply is ignored, so it can neither reject nor accept a signature. For example, comments has no effect on a PDF document, because PDF signatures have no comment field: use reason instead.

PropertyPDFWord ProcessingSpreadsheetPresentation
The certificate (certificate_file_path or certificate_stream): serial number and thumbprintyesyesyesyes
subject_name, issuer_nameyesyesnono
sign_date_time_from, sign_date_time_toyesyesyesyes
reason, contact, locationyesnonono
commentsnoyesyesyes

subject_name and issuer_name match when the subject or issuer of the signing certificate contains the value, case-sensitive. reason, contact and location must be equal to the values stored in the PDF signature.

Advanced Usage

Detect changes made after signing

Because the signature is checked cryptographically, any change to a signed PDF document makes its digital signature invalid. This example adds a text signature to a copy of the signed document and then verifies both files:

from groupdocs.signature import Signature
from groupdocs.signature.options import DigitalVerifyOptions, TextSignOptions


def verify_document_modified_after_signing():
    # Change a copy of the digitally signed document
    with Signature("signed.pdf") as signature:
        signature.sign("modified.pdf", TextSignOptions("Changed after signing"))

    for file_name in ("signed.pdf", "modified.pdf"):
        with Signature(file_name) as signature:
            options = DigitalVerifyOptions("certificate.pfx")
            options.password = "1234567890"
            result = signature.verify(options)
            print(f"{file_name}: valid = {result.is_valid}")


if __name__ == "__main__":
    verify_document_modified_after_signing()

signed.pdf is the sample file used in this example. Click here to download it.

certificate.pfx is the sample file used in this example. Click here to download it.

Binary file (PDF, 210 KB)

Download full output

More Resources

GitHub Examples

You may easily run the code above and see the feature in action in our GitHub examples:

Free Online Apps

Along with the full-featured Python library, we provide simple but powerful free online apps.

To sign PDF, Word, Excel, PowerPoint, and other documents you can use the online apps from the GroupDocs.Signature App Product Family.

Close
Loading

Analyzing your prompt, please hold on...

An error occurred while retrieving the results. Please refresh the page and try again.