CMS SubjectKeyIdentifier Signers

HotPDF can identify the primary CMS signer by the X.509 subjectKeyIdentifier extension instead of an issuer name and certificate serial number

Selecting the identifier

HPDFCMSDefaultOptions sets THPDFCMSSignOptions.SignerIdentifier to cmsidIssuerAndSerialNumber so existing callers retain their deterministic CMS byte shape

Set the field to cmsidSubjectKeyIdentifier before calling HPDFCMSBuildSignedDataEx, a provider-based CMS builder, placeholder estimation, or a high-level signing overload that accepts THPDFCMSSignOptions

Options := HPDFCMSDefaultOptions(palBaseline_B_B);
Options.SignerIdentifier := cmsidSubjectKeyIdentifier;
CMS := HPDFCMSBuildSignedDataEx(KeyMaterial, DocumentDigest, Options);

Certificate requirement

The signer certificate must contain exactly one non-empty X.509 extension with OID 2.5.29.14 whose extension value contains a complete DER OCTET STRING

HotPDF fails before signing when that extension is missing, duplicated, empty, truncated, or malformed; it does not synthesize a key identifier from the public key

SigningCertificateV2 continues to bind the same certificate with its issuer and serial fields even when the SignerInfo SID uses the key identifier

Wire format and verification

The key identifier is encoded as primitive IMPLICIT [0], SignerInfo.version is 3, and the generated single-signer SignedData.version is 3 as required by RFC 5652

Verification requires the SID bytes to match the embedded certificate extension and rejects mismatched SID values, issuer-and-serial records with a non-1 signer version, SKI records with a non-3 signer version, and SKI containers whose outer version is below 3

The compact identity is useful for key-oriented certificate stores and workflows that do not retain issuer-name encodings, but consuming software must support the RFC 5652 SKI choice

HPDFCMSBuildCounterSignerInfo continues to use issuer-and-serial identities; configure the primary signer through THPDFCMSSignOptions

See modern signature providers and CMS digest-algorithm consistency