Batch Signature Validation with Shared Caches
HotPDF can validate every signature of a loaded document in one pass through three shared caches: a certificate-path cache keyed by the CMS certificate set and the effective validation options, a timestamp cache keyed by the CMS blob and /ByteRange, and the THPDFRevocationEvidenceCache evidence store keyed by issuer and serial
THotPDF.ValidateLoadedSignatureBatch
The document-level entry point enumerates every signature field, byte-verifies each /ByteRange against the source, collects DSS and /VRI evidence, and runs certificate-path validation with the shared caches. WorkerLimit greater than one evaluates paths on parallel workers
var
Options: THPDFSignatureBatchOptions;
Result: THPDFSignatureBatchResult;
begin
PDF.LoadFromFile('Signed.pdf');
Options:= THPDFSignatureBatchOptions.Default;
Options.CertificateOptions.TrustAnchors:= MyAnchors;
Result:= PDF.ValidateLoadedSignatureBatch(Options);
if Result.AllSignaturesValid then
WriteLn('All ', Result.SignatureCount, ' signatures valid');
end;
Shared caches
Signatures repeating the same signer chain reuse the previous path verdict instead of recomputing it: the path cache keys cover the CMS certificate set, trust anchors, intermediates, every OCSP, CRL, and delta-CRL blob in evaluation order, revocation mode, validation time, and the complete policy block. Evidence injected from a cache is tagged with the vesCache evidence source
The revocation cache stores every OCSP response and CRL seen during a batch, keyed by issuer DN, serial number, and validity window, so later signatures and later batches sharing the same THPDFRevocationEvidenceCache instance resolve revocation without re-supplying evidence
The timestamp cache memoizes byte-verification verdicts for whole-CMS document timestamps (ETSI.RFC3161) and embedded signature timestamp tokens. A cache hit on an embedded token sets THPDFCMSVerifyOptions.SkipSignatureTimestampVerification, skipping the token re-verification while the primary CMS signature is still fully checked
Standalone batch engine
THPDFSignatureValidationBatch accepts jobs whose Info already carries the byte-verification verdict, for callers that own the source stream or verify outside the component. FailFast stops dispatching after the first negative verdict, and a THPDFCancellationToken leaves remaining entries sbsCancelled
Batch:= THPDFSignatureValidationBatch.Create(Options);
try
Batch.AddJob(Job);
Result:= Batch.Run;
finally
Batch.Free;
end;
Structured results
Each entry reports the signature and certificate status, the cache it reused, and per-signature diagnostics; HPDFSignatureBatchResultToJSON renders the whole batch with cache statistics as machine-readable JSON