iText: what type of certificates do people use to automate PDF signing on Linux?

后端 未结 1 2085
攒了一身酷
攒了一身酷 2021-01-03 13:45

I have a low volume (<500 PDFs/year) application for automated digital-signing of PDF files using iText in Java on Linux.

I\'ve got iText adding a digital signat

相关标签:
1条回答
  • 2021-01-03 14:18

    Regarding signing with your SSL certificate: in a future iText version, we make require that the key-usage of the certificate indicates that the certificate can be used for non-repudiation. For now, we make checking the key-usage the responsibility for the developer, but in a perfect world, you should only sign with certificates suited for non-repudiation, and your SSL certificate probably doesn't allow this.

    Regarding the green check mark: unless you can ask the consumers of your PDFs to add the root certificate of your certificate to the list of trusted identities, you'll always need a public/private key stored on hardware to get a green check mark.

    Regarding the price of an HSM / USB key. USB keys are much cheaper, but usually they are meant for manual use (usually they have a limit of signing only once every second). I think that GlobalSign has a flavor of keys that work on Linux. As for HSMs, one of our customers told us that he bought one from Utimaco because it was less expensive (but I don't know what budget he had or spent).

    No price info, but maybe a good read for inspiration: http://www.opendnssec.org/wp-content/uploads/2011/01/A-Review-of-Hardware-Security-Modules-Fall-2010.pdf

    0 讨论(0)
提交回复
热议问题