Digital signatures not working properly with certificates with different cryptografy
- May 23, 2022
- 1 reply
- 4529 views
Adobe Reader and Acrobat have problems with creation of PAdES digital signature when I use a TEST certificate that has RSA 2K private kay, and this certificate was issued by TEST CA (not on EU trusted list, but this is not the issue) that signed this certificate with sha384ECDSA.
Adobe makes a signature and validates it successfully, but EU ETSI EN 319 102 compliant validation reports SIG-CRYPTO-FAILURE. Other signer programs and services, that are compliant with EU standards, do not have this issue.
I think this is a bug. I am considering to instruct the users not to use Adobe programs for signature creation and to use our signing service or any other EU compatible publicly available signature service such as EU DSS, if I do not get this issue solved. It looks like Adobe is confused by different crypto algorithms in certificate private key (RSA) and CA signature on certificate (ECDSA).
Attached are 2 signed PDFs, one signature is created by Adobe Acrobat Pro 2020, version 2020.005.30334 (it says it is ut to date (TestCERTILIA_novi_Acrobat), and one by EU ETSI EN 319 102 compliant DSS service (Test_novi_TESTCERTILIA_-signed-pades-baseline-b).
Any suggestions?
Thank you!
