Modern Signature Providers

HPDFSignatureProvider separates CMS parsing and encoding from private-key storage and platform cryptography

Verification algorithms

HPDFVerifyCMSSignatureEx verifies Ed25519 and Ed448 pure-mode CMS signatures through THPDFPlatformSignatureProvider or a caller-supplied provider and records the exact signature OID in THPDFSignatureInfo.SignatureAlgorithmOID

CMS parsing cross-checks the container digest set, signer digest, signature mechanism parameters, and optional RFC 6211 algorithm-protection attribute before hashing or provider dispatch; see CMS digest-algorithm consistency for statuses and detailed issue codes

ML-DSA-44, ML-DSA-65, and ML-DSA-87 use the platform provider when available, but loaded-document verification enables them only when the Catalog declares the HotPDF PDF 2.0 developer extension

Signing providers

THotPDF.SignPDFWithPFX and the PFX-backed HPDFCMSSignPDFStream overloads select RSA, ECDSA, Ed25519, or Ed448 from the matched PKCS#12 identity without a caller-supplied signing callback

ECDSA private scalars are signed through Windows CNG and returned as strict DER ECDSA values, while Ed25519 and Ed448 use an optional OpenSSL 3 libcrypto selected by THPDFCMSSignOptions.OpenSSLLibraryPath or the normal library search path

PureEdDSA signs the complete DER SET OF signed attributes rather than a precomputed attribute digest; Ed25519 pairs this input with SHA-512 document digests and Ed448 uses id-shake256-len with a 512-bit SHAKE256 output

THPDFCMSSignOptions.SignerIdentifier selects issuer-and-serial or X.509 SubjectKeyIdentifier identity encoding independently of the private-key provider; see CMS SubjectKeyIdentifier signers

THPDFCallbackSignatureProvider adapts application callbacks, while THPDFRemoteSignatureProvider applies bounded retry, cancellation, input, and signature limits around a remote transport

THPDFCSCSignatureProvider implements CSC API v2 remote signing over an application-supplied HTTP transport, including OAuth token refresh, credential and certificate-chain discovery, explicit hash-pinned SAD acquisition, bounded ordered multisign batches, synchronous or asynchronous signatures/signHash, bounded polling, RFC 3161 timestamps, cancellation, and content-addressed idempotent replay

THPDFPKCS11SignatureProvider serializes RSA and ECDSA operations against a caller-owned authenticated PKCS#11 session and private-key handle, selecting digest-specific RSA PKCS#1 v1.5, RSA-PSS, or raw ECDSA mechanisms without exporting key material

THPDFWindowsKeyStorageSignatureProvider opens persisted keys in the Microsoft smart-card KSP or any named CNG key-storage provider, optionally rejects software keys through the Impl Type property, applies silent or interactive access policy, and signs SHA-2 or SHA3 digests with RSA PKCS#1 v1.5, RSA-PSS, or ECDSA

CreateFromKeyHandle adapts an existing NCRYPT_KEY_HANDLE and can either borrow or own it, allowing applications that already manage smart-card, TPM, or vendor-HSM authentication to retain lifecycle control

HPDFCMSBuildSignedDataWithProvider builds detached CMS from the digest selected by THPDFCMSSignOptions.DigestAlgorithm, while HPDFCMSSignPDFStreamWithProvider signs an existing PDF signature placeholder through bounded stream copies, streamed range hashing, and fixed-width seek patches without retaining a complete second PDF

HPDFCMSEstimatePlaceholder derives a side-effect-free CMS size from an explicit signature length, a provider estimate, or the RSA certificate key size, then accounts for the exact static CMS shape and configured dynamic timestamp or counter-signature reserves

HPDFCMSSignPDFStreamWithProviderAutoSize and HPDFCMSSignPDFStreamWithExternalSignerAutoSize rebuild undersized unsigned placeholders before signing; post-sign retries require the provider capability spcSafeSignRetry, and external signer callbacks are never repeated after returning a signature

See CMS placeholder auto-sizing for sizing options, rebuild contracts, retry policy, and diagnostics

See CSC remote signature provider for transport, authorization, retry, polling, and budget contracts

See SHA3 PDF signatures and timestamps for digest policy, RFC 3161, Seed Value, provider, and streaming contracts

See Brainpool ECDSA signatures for named-curve certificate requirements, the curve-specific SHA-2 and SHA3 matrix, strict DER encoding, and fail-before-provider producer validation

Provider request contract

THPDFSignatureProviderRequest carries the signature algorithm and OID, digest OID, message or digest input kind, PSS salt length, public key or certificate, key identifier, operation identifier, signature, and algorithm context

A signing provider returns spsValid with a non-empty signature, while verification providers use spsValid or spsInvalid; unsupported, malformed, provider-error, and cancelled results remain distinct