File Signature Workbench
This tool signs a bounded local file with a user-held ECDSA P-256 private key. The detached version 1 JSON manifest records the exact filename, byte length, SHA-256 digest and public key; its canonical fields are signed with SHA-256 ECDSA. Verification rereads the selected file and checks both its digest and the signature. A plain checksum cannot authenticate the key holder. This format is specific to this site and is not a PDF/CMS signature or certificate.
Key features
- Generate a signing key or import a local P-256 private JWK
- Sign exact local bytes and bind filename, size, SHA-256 and public key
- Download a detached version 1 .ttsig.json manifest and public JWK
- Verify a received file and reject changed bytes, damaged signatures and wrong keys
- Compare the SHA-256 fingerprint of the public key through an independent trusted channel
How to use
- Choose Sign, create or import a local signing key, and select a file up to 16 MiB.
- Sign and download the detached .ttsig.json manifest; share the public key separately if the verifier needs an independent comparison.
- Protect the private-key JSON if you explicitly choose to export it. It is not encrypted.
- Choose Verify, select the original file and its detached manifest, and optionally select the public JWK received through another channel.
- Read the byte-integrity and signature result, then compare the public-key fingerprint with a trusted source before attributing an identity.
Use cases
- Detect whether a small delivered binary changed after signing
- Share a detached signature alongside a file without embedding it in the file
- Check a release artifact against a public key already known to your team
- Demonstrate why a checksum and an authenticated public key answer different questions
Frequently asked questions
Does a successful check prove who signed the file?
No. A manifest can include any self-generated public key. It proves that the matching private key signed these fields, but identity needs a separately trusted key or fingerprint.
Can the key in the manifest be replaced?
The public key is inside the signed payload. Replacing it without resigning fails verification. An attacker could still create a new key and new manifest, so compare a separately obtained trusted key.
Does renaming the file affect verification?
Yes. The exact filename and byte length are signed along with the SHA-256 digest. Renaming or changing one byte requires a new signature.
Is the exported private key protected by a password?
No. The private JWK is unencrypted JSON and is downloaded only after a separate acknowledgement. Anyone who gets it can sign files under that key.
Can I use the manifest with PDF/CMS/OpenSSL tools?
The cryptographic operation is Web Crypto ECDSA P-256 with SHA-256 and P1363 signatures. The surrounding canonical JSON manifest is this site's own version 1 format, not PDF/CMS or an OpenSSL detached-signature container.
What limits apply?
Files are limited to 16 MiB, manifests to 8 KiB and key JSON to 4 KiB. Files are read in browser memory; large files and unsupported Web Crypto browsers are not accepted.
Privacy
File and key bytes stay in this browser tab's memory. Nothing is uploaded or automatically stored. The private key is exported only after you explicitly acknowledge that its JSON download is unencrypted. Keep that file private and backed up; anyone with it can sign as this key.
Comments & questions