Brainpool ECDSA Signatures
HotPDF creates and verifies detached CMS signatures with brainpoolP256r1, brainpoolP384r1, and brainpoolP512r1 certificates through the existing ECDSA signing-provider and loaded-signature pipelines
Allowed digest combinations
| Curve | Allowed digests |
|---|---|
brainpoolP256r1 | SHA-256, SHA-384, SHA-512, SHA3-256, SHA3-384, SHA3-512 |
brainpoolP384r1 | SHA-384, SHA-512, SHA3-384, SHA3-512 |
brainpoolP512r1 | SHA-512, SHA3-512 |
HPDFCMSBuildSignedDataEx, HPDFCMSBuildSignedDataWithProvider, external-signer workflows, stream signing, and multi-signer construction validate this matrix before dispatching a signing callback or provider
Verification reports a digest-algorithm mismatch when the signer digest, digest-specific ECDSA signature identifier, or Brainpool curve policy selects an incompatible combination
Strict certificate and signature encoding
The signer certificate must encode id-ecPublicKey with exactly one recognized ECParameters.namedCurve object identifier in SubjectPublicKeyInfo
Explicit or implicit curve parameters, trailing algorithm parameters, unknown curves, and ECDSA signature AlgorithmIdentifier parameters are rejected instead of being normalized
CMS signature values use canonical DER ECDSA-Sig-Value encoding, including minimally encoded positive r and s integers
Windows cryptographic provider
Local verification imports each Brainpool public point through the Windows CNG generic ECDSA provider with an immutable ECCCurveName property
If the operating system does not expose the requested named curve, HotPDF returns a distinct unsupported or provider-unavailable result and does not substitute a different curve
See modern signature providers, SHA3 PDF signatures and timestamps, and CMS digest-algorithm consistency for the surrounding producer and verifier contracts