Signed PDF Inspector
A PDF signature covers two exact byte ranges, omitting the signature container. This inspector checks those ranges against the actual Contents value and verifies supported detached CMS signatures against the covered bytes. It separately shows bytes added after that signed revision, certificate dates at your current clock and a path to an optional certificate you explicitly choose. A cryptographically correct signature is not by itself a trusted or unrevoked identity.
Key features
- Parse actual PDF AcroForm signature fields rather than searching for a signature-looking string
- Validate four-number ByteRange bounds and exact hexadecimal Contents gap
- Verify detached CMS signer signature and signed content with PKIjs
- Distinguish original signed revision from later appended bytes
- Optional local certificate path to a user-supplied PEM/DER anchor; revocation remains unknown
- Export the result as JSON without including the original PDF
How to use
- Select a signed PDF up to 20 MiB, or load the local example.
- Optionally select a PEM/DER certificate as an explicit trust anchor.
- Run inspection and read ByteRange, cryptographic signature, anchor and revocation rows separately.
- Check whether later PDF bytes are outside this signature's covered revision.
- Review signer certificate details and download the JSON report if needed.
Use cases
- Check whether an approval signature covers its original PDF revision
- Detect bytes added to a PDF after its first signature
- Compare a signer certificate path with a certificate you personally selected
Frequently asked questions
Does a verified signature mean the document is trustworthy?
No. It only proves the supported CMS signature matches the covered bytes and the included signer's public key. The identity and certificate chain need separate trust decisions; later bytes may also be outside the signed revision.
Does this detect changes after signing?
It counts bytes after this signature's covered revision. A later valid incremental update or second signature may be legitimate, but this tool does not interpret its semantic changes or certify allowed PDF permissions.
What does the supplied anchor result mean?
It attempts a local path from the signer certificate to the PEM/DER certificate you chose, at the local clock. Supplying an arbitrary certificate does not make it publicly trusted.
Are revoked certificates and timestamps checked?
No. No OCSP, CRL, trusted timestamp, long-term validation, PAdES profile or legal status is established. Revocation remains unknown even when a chain to the supplied anchor is found.
Which PDF signatures are supported?
AcroForm approval signatures with a hexadecimal Contents value, four-number ByteRange and detached adbe.pkcs7.detached or ETSI.CAdES.detached CMS are checked. Other subfilters, document timestamp signatures, encrypted PDFs and exotic encodings are reported as unknown or rejected.
Privacy
The PDF and optional certificate are read in this browser. This tool does not upload the documents or contact certificate authorities, OCSP responders or CRL servers. The bundled example is fetched from this site's own static files.
Comments & questions