CMS Digest-Algorithm Consistency

HotPDF diagnoses inconsistent CMS algorithm identifiers before reading signed document ranges, hashing content, building certificate paths, or invoking a signature provider

Consistency checks

The current SignerInfo.digestAlgorithm must be present in the enclosing SignedData.digestAlgorithms set, while unrelated extra algorithms remain permitted for interoperable multi-signer containers

Digest-specific RSA PKCS#1 v1.5 and ECDSA signature OIDs, and the explicit hash in RSA-PSS parameters, must select the same digest as SignerInfo.digestAlgorithm

When the RFC 6211 CMSAlgorithmProtection signed attribute is present, it must occur once with one value, and its protected digest and signature AlgorithmIdentifier values must match the actual SignerInfo fields

Absent and DER NULL parameters compare as equivalent for no-parameter algorithm identifiers; other parameters compare exactly so parameterised signature mechanisms cannot be silently normalized

Machine-readable result

HPDFParseCMSSignature preserves successfully parsed metadata but sets THPDFSignatureInfo.Status to svDigestAlgorithmMismatch when a consistency check fails

Verification returns svDigestAlgorithmMismatch, validation reports use vfcDigestAlgorithmMismatch, and JSON emits digestAlgorithmMismatch without collapsing the condition into malformed CMS, unsupported algorithm, or content digest mismatch

THPDFSignatureInfo.DigestAlgorithmOID records the signer digest OID and THPDFSignatureInfo.DigestConsistencyIssue selects one of the following causes

JSON signer objects expose the same information as digestAlgorithmOID and digestConsistencyIssue with the values signerDigestNotDeclared, signatureDigestMismatch, algorithmProtectionDigestMismatch, or algorithmProtectionSignatureMismatch

Timestamps and precedence

RFC 3161 document timestamps and unsigned signature-timestamp tokens use the same checks, and their THPDFTimestampInfo.DigestConsistencyIssue value identifies an inconsistent nested CMS container

Structural errors still fail as malformed CMS, unknown signer digests remain unsupported, and the first deterministic consistency issue is retained in container, algorithm-protection, then signature-mechanism order

See modern signature providers and THotPDF.VerifyLoadedSignatureWithOptions for provider and loaded-document verification contracts