Clause-Addressable PAdES Profile Preflight

THotPDF.PreflightLoadedPAdES evaluates a loaded signature against one cumulative PAdES baseline or extended profile and returns every applicable requirement, including successful checks, with standards-clause and PDF-evidence provenance

Supported targets

Baseline targets are palBaseline_B_B, palBaseline_B_T, palBaseline_B_LT, and palBaseline_B_LTA; extended targets are palExtended_E_BES, palExtended_E_EPES, and palExtended_E_LTV

The generic palLegacy_adbePkcs7 value is not a PAdES profile and is rejected as a target

Evaluation contract

The stream overload preserves the caller-owned source position, while the file overload reopens the source used by LoadFromFile. A True function result means evaluation completed; use THPDFPAdESPreflightReport.Compliant to test conformance

var
  Report: THPDFPAdESPreflightReport;
  Requirement: THPDFPAdESPreflightRequirement;
begin
  PDF.LoadFromFile('Signed.pdf');
  if not PDF.PreflightLoadedPAdES(0, palBaseline_B_LT, Report) then
    raise Exception.Create(string(Report.Issue));

  for Requirement in Report.Requirements do
    WriteLn(string(Requirement.RuleID), ': ',
      BoolToStr(Requirement.Passed, True), ' at ',
      string(Requirement.Clause), ' object ',
      Requirement.ObjectNumber, ' revision ',
      Requirement.RevisionIndex);
end;

Evidence inspected

Baseline and extended checks inspect the signature dictionary, complete /ByteRange coverage, CMS signature validity, signed-attribute cardinality, content type, message digest, signing-time constraints, /M, /Filter, /SubFilter, /Reason, and prohibited /Cert entries

ESS signing-certificate and signing-certificate-v2 checks hash the actual signer certificate and require a matching ESSCertID reference instead of accepting an attribute by name alone

Higher levels additionally inspect valid signature or document timestamps, DSS certificate and revocation arrays, the revision that introduced validation material, and whether a later document timestamp covers that DSS revision

Structured findings

Each THPDFPAdESPreflightRequirement reports its introducing Profile, normative Level, stable RuleID, Clause, PDF Path, ObjectNumber, RevisionIndex, Passed status, and diagnostic Message

FailedRequirementCount counts failed shall-level rules, while WarningCount counts failed should-level guidance. HighestConformingProfile identifies the highest cumulative profile that passed and is meaningful only when HasConformingProfile is true

See PAdES signature-policy validation, batch signature validation, and signature evidence acquisition