Clause-Addressable PAdES Profile Preflight
THotPDF.PreflightLoadedPAdES evaluates a loaded signature against one cumulative PAdES baseline or extended profile and returns every applicable requirement, including successful checks, with standards-clause and PDF-evidence provenance
Supported targets
Baseline targets are palBaseline_B_B, palBaseline_B_T, palBaseline_B_LT, and palBaseline_B_LTA; extended targets are palExtended_E_BES, palExtended_E_EPES, and palExtended_E_LTV
The generic palLegacy_adbePkcs7 value is not a PAdES profile and is rejected as a target
Evaluation contract
The stream overload preserves the caller-owned source position, while the file overload reopens the source used by LoadFromFile. A True function result means evaluation completed; use THPDFPAdESPreflightReport.Compliant to test conformance
var
Report: THPDFPAdESPreflightReport;
Requirement: THPDFPAdESPreflightRequirement;
begin
PDF.LoadFromFile('Signed.pdf');
if not PDF.PreflightLoadedPAdES(0, palBaseline_B_LT, Report) then
raise Exception.Create(string(Report.Issue));
for Requirement in Report.Requirements do
WriteLn(string(Requirement.RuleID), ': ',
BoolToStr(Requirement.Passed, True), ' at ',
string(Requirement.Clause), ' object ',
Requirement.ObjectNumber, ' revision ',
Requirement.RevisionIndex);
end;
Evidence inspected
Baseline and extended checks inspect the signature dictionary, complete /ByteRange coverage, CMS signature validity, signed-attribute cardinality, content type, message digest, signing-time constraints, /M, /Filter, /SubFilter, /Reason, and prohibited /Cert entries
ESS signing-certificate and signing-certificate-v2 checks hash the actual signer certificate and require a matching ESSCertID reference instead of accepting an attribute by name alone
Higher levels additionally inspect valid signature or document timestamps, DSS certificate and revocation arrays, the revision that introduced validation material, and whether a later document timestamp covers that DSS revision
Structured findings
Each THPDFPAdESPreflightRequirement reports its introducing Profile, normative Level, stable RuleID, Clause, PDF Path, ObjectNumber, RevisionIndex, Passed status, and diagnostic Message
FailedRequirementCount counts failed shall-level rules, while WarningCount counts failed should-level guidance. HighestConformingProfile identifies the highest cumulative profile that passed and is meaningful only when HasConformingProfile is true
See PAdES signature-policy validation, batch signature validation, and signature evidence acquisition