- Author: Nicola Asuni <info@tecnick.com>
- Copyright: 2026 Nicola Asuni - Tecnick.com LTD
- License: https://www.gnu.org/copyleft/lesser.html GNU-LGPL v3 (see LICENSE)
- Source: https://github.com/tecnickcom/tc-lib-pdf-sign
Com\Tecnick\Pdf\Sign
Classes:
- Config: Immutable signature configuration value object.
- Exception: Custom Exception class for the PDF signature library.
- RevokedException: Thrown when a responder or a CRL states that a certificate is revoked.
- Signer: Package-internal orchestration entry point that ties the CMS builder, the RFC 3161 timestamp codec, and the LTV material collector together behind two host-facing calls.
Enums:
- DigestAlgorithm: Backed enum for the supported message-digest algorithms.
- SignatureProfile: Backed enum for the supported signature profiles.
Com\Tecnick\Pdf\Sign\Cms
Classes:
- Asn1: Minimal DER ASN.1 encoder/decoder used to assemble and inspect CMS/CAdES structures, RFC 3161 timestamp messages, and OCSP requests.
- Builder: Native builder for a detached CAdES-BES CMS SignedData, suitable for a PAdES B-B signature (/SubFilter /ETSI.CAdES.detached).
- Certificate: Reads the TBSCertificate fields that CMS and OCSP structures quote verbatim: the issuer and subject Names, the serial number, and the public key bits.
- Oid: The object identifiers of the CMS content types and signed attribute types this library emits and reads.
- SignatureVerifier: Verifies the signature of a DER structure that follows the X.509 shape of a signed body, an AlgorithmIdentifier, and a signature BIT STRING.
- SignedDataVerifier: Verifies a CMS SignedData that carries its own content, which is the shape of an RFC 3161 timestamp token.
- SigningRequest: Validated, immutable record of everything the CMS signed attributes are derived from.
Enums:
- SignatureEncoding: Backed enum for the encoding of a signature handed to Builder::buildFromSignature().
Com\Tecnick\Pdf\Sign\Ltv
Classes:
- Crl: RFC 5280 CertificateList reader.
- ValidationMaterial: Collects the long-term validation (LTV) material embedded in a PDF Document Security Store (DSS): the certificate DERs, OCSP responses, and CRLs.
Enums:
- SkipReason: Machine-readable classification of a discarded revocation URL, passed to the $onSkip observer alongside the human-readable message.
Com\Tecnick\Pdf\Sign\Ocsp
Classes:
- Client: RFC 6960 OCSP codec.
- Request: An OCSP request together with the CertID it asks about, which RFC 6960 section 3.2 requires the response to be matched against before it is accepted.
Com\Tecnick\Pdf\Sign\Output
Classes:
- DocTimeStamp: Emits a document timestamp value object (/Type /DocTimeStamp, /SubFilter /ETSI.RFC3161) whose /Contents is a bare RFC 3161 timestamp token.
- Dss: Emits the Document Security Store (DSS) PDF objects for a signature: the certificate, OCSP, and CRL streams, a VRI entry, and the DSS dictionary.
- PdfString: Encodes a text value as a PDF string token, either through a host-supplied encoder (which may apply UTF-16, escaping, and encryption) or, when none is given, a built-in fallback.
- Signature: Emits the /Sig value dictionary (the object referenced by a signature field’s /V): the fixed skeleton, the /SubFilter, and the /ByteRange and /Contents placeholders that the host rewrites while signin
- Widget: Emits a signature field’s widget annotation (/Subtype /Widget, /FT /Sig).
Com\Tecnick\Pdf\Sign\Timestamp
Classes: