GroupDocs.Signature provides the ability to verify digital signatures in documents. Digital signatures provide a secure way to verify the authenticity and integrity of documents.
What is a Digital Signature?
A digital signature is a mathematical scheme for demonstrating the authenticity of digital messages or documents. It provides:
Authentication: Confirms the identity of the signer
Integrity: Ensures the document hasn’t been modified
Non-repudiation: Prevents the signer from denying they signed the document
How to Verify Digital Signatures
The Signature class provides the verify method which allows you to verify digital signatures in documents. Here’s how to use it:
Create a new instance of the Signature class and pass the source document path as a parameter.
Here’s an example of how to verify digital signatures in a document. The sample certificate certificate.pfx is protected with the password 1234567890:
fromgroupdocs.signatureimportSignaturefromgroupdocs.signature.optionsimportDigitalVerifyOptionsdefverify_digital_signatures():withSignature("signed.pdf")assignature:options=DigitalVerifyOptions("certificate.pfx")options.password="1234567890"# The subject of the signing certificate must contain this textoptions.subject_name="ProfJamesMoriarty"# The signing reason stored in the PDF signature must be equal to this textoptions.reason="Approved"result=signature.verify(options)ifresult.is_valid:print(f"Document was verified successfully: {len(result.succeeded)} valid digital signature(s).")else:print("Document failed verification process.")if__name__=="__main__":verify_digital_signatures()
signed.pdf is the sample file used in this example. Click here to download it.
certificate.pfx is the sample file used in this example. Click here to download it.
Document was verified successfully: 1 valid digital signature(s).
Verification performs two independent checks. First the signature itself is verified cryptographically: if the document was altered after signing, the result is not valid regardless of any other option. Then any criteria you set on DigitalVerifyOptions - certificate, subject name, issuer name, signing time, reason, contact or location - are matched. Both must pass for is_valid to be True. For PDF documents the cryptographic check was added in GroupDocs.Signature for Python via .NET 26.10; earlier versions compared only the criteria.
Verification criteria by document format
Not every property of DigitalVerifyOptions applies to every document format. A property that does not apply is ignored, so it can neither reject nor accept a signature. For example, comments has no effect on a PDF document, because PDF signatures have no comment field: use reason instead.
Property
PDF
Word Processing
Spreadsheet
Presentation
The certificate (certificate_file_path or certificate_stream): serial number and thumbprint
yes
yes
yes
yes
subject_name, issuer_name
yes
yes
no
no
sign_date_time_from, sign_date_time_to
yes
yes
yes
yes
reason, contact, location
yes
no
no
no
comments
no
yes
yes
yes
subject_name and issuer_name match when the subject or issuer of the signing certificate contains the value, case-sensitive. reason, contact and location must be equal to the values stored in the PDF signature.
Advanced Usage
Detect changes made after signing
Because the signature is checked cryptographically, any change to a signed PDF document makes its digital signature invalid. This example adds a text signature to a copy of the signed document and then verifies both files:
fromgroupdocs.signatureimportSignaturefromgroupdocs.signature.optionsimportDigitalVerifyOptions,TextSignOptionsdefverify_document_modified_after_signing():# Change a copy of the digitally signed documentwithSignature("signed.pdf")assignature:signature.sign("modified.pdf",TextSignOptions("Changed after signing"))forfile_namein("signed.pdf","modified.pdf"):withSignature(file_name)assignature:options=DigitalVerifyOptions("certificate.pfx")options.password="1234567890"result=signature.verify(options)print(f"{file_name}: valid = {result.is_valid}")if__name__=="__main__":verify_document_modified_after_signing()
signed.pdf is the sample file used in this example. Click here to download it.
certificate.pfx is the sample file used in this example. Click here to download it.