OxygenPDF

PDF digitaal ondertekenen met X.509-certificaat

Onderteken een PDF met een echt X.509-certificaat: zichtbare of onzichtbare CMS-handtekening met reden en locatie, volledig in je browser.

Real digital signatures, not drawn ones

What a digital signature actually is

A drawn signature is a picture pasted onto a page — it proves nothing and any editor can move or remove it. A digital signature is a CMS (PKCS#7) cryptographic structure embedded in the file itself: it binds your X.509 certificate to a hash of the exact bytes you signed. Change one byte afterwards and every PDF reader flags the document as modified.

This tool produces that real thing. You load a PKCS#12 bundle (.pfx or .p12) containing your private key and certificate, and the tool writes a signature dictionary with a proper /ByteRange and /Contents into the PDF — the same structure Adobe Acrobat creates. The result opens in Acrobat, Foxit, or any standards-based reader with the signature panel populated.

Visible or invisible

A visible signature also draws an appearance on a page you choose — signer name, reason, date, and optionally a scanned signature image — so a printed copy still shows the mark. An invisible signature embeds the same cryptographic proof with no visual stamp, which is what you want for integrity-only sealing of contracts, invoices, and audit exports.

Reason and location fields are recorded inside the signature dictionary itself, so verifiers see 'Approved for release — Jakarta' rather than guessing.

What you can configure

Every part of the signature is under your control.

PKCS#12 certificates

Load .pfx or .p12 bundles; the certificate chain rides inside the signature so verifiers can walk it.

Visible appearance

Nine-position placement grid, size control, optional signature image, and toggles for name/reason/date lines.

Invisible mode

Zero-rectangle signature field: pure integrity and authenticity proof with no visual change.

Tamper evidence

The signature covers the whole file byte range. Any later edit — even one byte — breaks verification.

Private by construction

Your .pfx never leaves the device. The private key is imported into the browser's WebCrypto engine as non-extractable for the signing operation, the CMS blob is built locally, and the finished file is generated in memory. There is no server round-trip at any point — you can disconnect from the network and signing still works.

Pair this tool with Validate Signature to check incoming signed PDFs, or with Timestamp PDF to add a trusted RFC 3161 timestamp that proves when the signed document existed.

PDF digitaal ondertekenen met X.509-certificaat: Veelgestelde vragen

Veelgestelde vragen over deze tool en de werking ervan.

Voor altijd gratis

Alle 119+ tools — voor altijd gratis
Visuele workflow-builder — koppel tools aan elkaar
Download desktop-app

Pro

$29 eenmalig
Meerdere bestanden tegelijk batchgewijs verwerken
Steun indie-ontwikkeling
14 dagen niet-goed-geld-teruggarantie

We gebruiken analytische cookies om te begrijpen hoe onze tools worden gebruikt en om de ervaring te verbeteren. Er worden nooit persoonlijke bestanden verzonden.