For curiosity I took a look at the signature, too. Here's what I got: 2012-01-31 20:04:13,281 ERROR (http-0.0.0.0-8080-7) [de.trustable.signingserver.Verifier] Signature ERROR from signer # 0 : javax.crypto.BadPaddingException: Invalid PKCS#1 padding: encrypted message and modulus lengths do not match!
The decrypted signature content difinitly doesn't look like having a padding applied: 2012-01-31 20:04:13,281 DEBUG (http-0.0.0.0-8080-7) [de.trustable.signingserver.Verifier] unpadded decrypted 1a:e3:f9:19:c4:31:7d:9c:90:6e:0a:f3:a1:23:79:db:25:47:36:80:d6:a7:da:50:09:97:cb:ad:ab:a9:50:66:21:c0:84:f5:20:97:1e:0c:f1:40:ef:5f:58:d5:05:1a:f3:50:60:93:d6:8e:3c:78:9a:e1:fa:5b:a0:93:0f:f5:04:ef:e1:6b:43:63:27:0e:f0:c3:94:d7:9f:bf:3c:29:91:1c:f2:91:a6:7c:b0:56:b3:66:20:c2:45:80:d9:d4:c6:c1:f1:1f:c1:ab:13:ee:9e:6b:84:fe:54:2d:b4:83:61:5c:0a:43:92:28:35:d1:2f:76:ad:ed:28:89:ba:49:18:dd:88:a9:a5:89:7e:2c:cf:e4:f9:17:68:db:20:f4:c4:65:16:f6:ef:15:e5:8e:75:2d:7c:87:43:00:3d:aa:05:5a:30:50:38:0e:96:9f:4d:29:d1:1b:d9:4d:12:42:0e:f8:88:fa:40:90:a8:15:cd:46:37:bb:58:51:54:08:d1:e6:85:dc:75:f9:fb:b2:4a:d6:2d:94:54:ec:57:2b:43:8f:56:10:ac:84:eb:ce:e2:99:e7:0d:68:2c:29:c0:92:95:14:bf:fb:e4:5d:db:2f:6e:4a:dd:34:51:21:b8:6f:80:a1:0f:78:f2:8d:19:5c:99:3c:0c:cb:e1:fb:e3: This problem usually stems from unmatching signing keys / certificates. Up tol this point no details of the signature (signed attributes ...) are relevant. Greetings Andreas K. > Yes, we do indeed fail validation. Just not enough here to do anything > useful. > > Leonard > > On 1/31/12 5:33 PM, "mkl" <m...@wir-sind-cool.org> wrote: > >> Max, >> >> madmax wrote >>> I am attaching the the signed PDF as well as the full Java and JSP code >>> and lastly I made a recording on how it runs within internet explorer >>> showing the interaction with the smartcard, servlet and itext. >>> >>> http://itext-general.2136553.n4.nabble.com/file/n4344394/sample-1.pdf >> Hhmmm, this one might be of interest for Leonard, too --- after a first >> inspection the signature looks ok to me. >> >> Well, yes, it does not contain any signed attributes, not even an ESS >> signing certificate attribute. Therefore, this signature doesn't stand a >> chance to fulfil any decent signature profile. But as a minimalist CMS >> signature it looks ok. >> >> Regards, Michael >> >> -- >> View this message in context: >> http://itext-general.2136553.n4.nabble.com/Sign-and-PDF-with-SmartCard-and >> -web-browser-only-tp4319344p4345021.html >> Sent from the iText - General mailing list archive at Nabble.com. >> >> -------------------------------------------------------------------------- >> ---- >> Keep Your Developer Skills Current with LearnDevNow! >> The most comprehensive online learning library for Microsoft developers >> is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, >> Metro Style Apps, more. Free future releases when you subscribe now! >> http://p.sf.net/sfu/learndevnow-d2d >> _______________________________________________ >> iText-questions mailing list >> iText-questions@lists.sourceforge.net >> https://lists.sourceforge.net/lists/listinfo/itext-questions >> >> iText(R) is a registered trademark of 1T3XT BVBA. >> Many questions posted to this list can (and will) be answered with a >> reference to the iText book: http://www.itextpdf.com/book/ >> Please check the keywords list before you ask for examples: >> http://itextpdf.com/themes/keywords.php > > ------------------------------------------------------------------------------ > Keep Your Developer Skills Current with LearnDevNow! > The most comprehensive online learning library for Microsoft developers > is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, > Metro Style Apps, more. Free future releases when you subscribe now! > http://p.sf.net/sfu/learndevnow-d2d > _______________________________________________ > iText-questions mailing list > iText-questions@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/itext-questions > > iText(R) is a registered trademark of 1T3XT BVBA. > Many questions posted to this list can (and will) be answered with a > reference to the iText book: http://www.itextpdf.com/book/ > Please check the keywords list before you ask for examples: > http://itextpdf.com/themes/keywords.php > -- Andreas Kühne phone: +49 177 293 24 97 mailto: kue...@trustable.de Trustable Ltd. Niederlassung Deutschland Ströverstr. 18 - 59427 Unna Amtsgericht Hamm HRB 5868 Directors Andreas Kühne, Heiko Veit Company UK Company No: 5218868 Registered in England and Wales ------------------------------------------------------------------------------ Keep Your Developer Skills Current with LearnDevNow! The most comprehensive online learning library for Microsoft developers is just $99.99! Visual Studio, SharePoint, SQL - plus HTML5, CSS3, MVC3, Metro Style Apps, more. Free future releases when you subscribe now! http://p.sf.net/sfu/learndevnow-d2d _______________________________________________ iText-questions mailing list iText-questions@lists.sourceforge.net https://lists.sourceforge.net/lists/listinfo/itext-questions iText(R) is a registered trademark of 1T3XT BVBA. Many questions posted to this list can (and will) be answered with a reference to the iText book: http://www.itextpdf.com/book/ Please check the keywords list before you ask for examples: http://itextpdf.com/themes/keywords.php