Brainpool ECDSA Signatures

HotPDF creates and verifies detached CMS signatures with brainpoolP256r1, brainpoolP384r1, and brainpoolP512r1 certificates through the existing ECDSA signing-provider and loaded-signature pipelines

Allowed digest combinations

CurveAllowed digests
brainpoolP256r1SHA-256, SHA-384, SHA-512, SHA3-256, SHA3-384, SHA3-512
brainpoolP384r1SHA-384, SHA-512, SHA3-384, SHA3-512
brainpoolP512r1SHA-512, SHA3-512

HPDFCMSBuildSignedDataEx, HPDFCMSBuildSignedDataWithProvider, external-signer workflows, stream signing, and multi-signer construction validate this matrix before dispatching a signing callback or provider

Verification reports a digest-algorithm mismatch when the signer digest, digest-specific ECDSA signature identifier, or Brainpool curve policy selects an incompatible combination

Strict certificate and signature encoding

The signer certificate must encode id-ecPublicKey with exactly one recognized ECParameters.namedCurve object identifier in SubjectPublicKeyInfo

Explicit or implicit curve parameters, trailing algorithm parameters, unknown curves, and ECDSA signature AlgorithmIdentifier parameters are rejected instead of being normalized

CMS signature values use canonical DER ECDSA-Sig-Value encoding, including minimally encoded positive r and s integers

Windows cryptographic provider

Local verification imports each Brainpool public point through the Windows CNG generic ECDSA provider with an immutable ECCCurveName property

If the operating system does not expose the requested named curve, HotPDF returns a distinct unsupported or provider-unavailable result and does not substitute a different curve

See modern signature providers, SHA3 PDF signatures and timestamps, and CMS digest-algorithm consistency for the surrounding producer and verifier contracts