OxygenPDF

X.509 PDF CMS ,

X.509 PDF, CMS ,;,,、。,、,,。

Real digital signatures, not drawn ones

What a digital signature actually is

A drawn signature is a picture pasted onto a page — it proves nothing and any editor can move or remove it. A digital signature is a CMS (PKCS#7) cryptographic structure embedded in the file itself: it binds your X.509 certificate to a hash of the exact bytes you signed. Change one byte afterwards and every PDF reader flags the document as modified.

This tool produces that real thing. You load a PKCS#12 bundle (.pfx or .p12) containing your private key and certificate, and the tool writes a signature dictionary with a proper /ByteRange and /Contents into the PDF — the same structure Adobe Acrobat creates. The result opens in Acrobat, Foxit, or any standards-based reader with the signature panel populated.

Visible or invisible

A visible signature also draws an appearance on a page you choose — signer name, reason, date, and optionally a scanned signature image — so a printed copy still shows the mark. An invisible signature embeds the same cryptographic proof with no visual stamp, which is what you want for integrity-only sealing of contracts, invoices, and audit exports.

Reason and location fields are recorded inside the signature dictionary itself, so verifiers see 'Approved for release — Jakarta' rather than guessing.

What you can configure

Every part of the signature is under your control.

PKCS#12 certificates

Load .pfx or .p12 bundles; the certificate chain rides inside the signature so verifiers can walk it.

Visible appearance

Nine-position placement grid, size control, optional signature image, and toggles for name/reason/date lines.

Invisible mode

Zero-rectangle signature field: pure integrity and authenticity proof with no visual change.

Tamper evidence

The signature covers the whole file byte range. Any later edit — even one byte — breaks verification.

Private by construction

Your .pfx never leaves the device. The private key is imported into the browser's WebCrypto engine as non-extractable for the signing operation, the CMS blob is built locally, and the finished file is generated in memory. There is no server round-trip at any point — you can disconnect from the network and signing still works.

Pair this tool with Validate Signature to check incoming signed PDFs, or with Timestamp PDF to add a trusted RFC 3161 timestamp that proves when the signed document existed.

X.509 PDF CMS ,: 常見問題

關於此工具及其運作方式的常見問題。

永久免費

超過 119 種工具 — 永久免費
視覺化工作流程建構工具 — 自由串連多項工具

Pro

$29 單次付費
一次批次處理多個檔案
支持獨立開發
14 天退款保證

我們使用分析技術來了解工具的使用情況並改善使用者體驗。我們絕不會傳送您的任何個人檔案。