fix: add DocMDP reference to catalog for certification signatures - #166
akkaraponph wants to merge 2 commits into
Conversation
Codecov Report❌ Patch coverage is
Additional details and impacted files@@ Coverage Diff @@
## main #166 +/- ##
==========================================
- Coverage 63.21% 60.27% -2.95%
==========================================
Files 46 47 +1
Lines 3934 4194 +260
==========================================
+ Hits 2487 2528 +41
- Misses 1447 1666 +219
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
|
@akkaraponph thanks — this is a real gap, and #165 found the same thing a day earlier. I've opened #169 which combines both, credited to you and @uinoushi. The one change from your approach: an existing Since your goal was Acrobat recognition, would you be able to test #169 with the documents you were checking against? What I'd like to confirm is that Acrobat now shows the "Certified by …" banner, and that the permission level you set ( Generated by Claude Code |
Summary
Add the required document-catalog
/Perms << /DocMDP N 0 R >>entry when creating aCertificationSignature.This is a PDF structural interoperability fix for Adobe Acrobat certification recognition. Without the catalog pointer, Acrobat may treat a cryptographically valid certification signature as a normal approval signature and omit the “Certified by …” banner.
The implementation:
/Perms, preserving the first-certification-signature requirement.This does not guarantee trust status; that still depends on the recipient’s trusted certificate chain and revocation validation.
Verification
gofmt -w sign/pdfcatalog.go sign/pdfcatalog_test.go sign/sign_test.gogo test ./... -count=1