Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Add advanced PAdES and long-term signature validation

Aperta
#8,946 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

I maintainer di solito rispondono entro 1 giorno

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
15/100
Tipo di issue
Funzionalità
Chiarezza
Da chiarire
Stato di attività
Attiva

Direzione di ricerca

No implementation files or tests are named; this issue explicitly says not to implement the epic directly. Start by defining the target PAdES profiles and validation requirements, then split the work into focused child issues. Coordinate with #8335, #8943, #8944, and #8945, with automated regression and interoperability tests as the completion criteria.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

This is a roadmap and funding epic.

[!IMPORTANT]

Do not implement this epic directly.

This issue is for planning, research and funding of the PAdES and validation capabilities needed by future remote-signing, eIDAS and long-term document workflows.

Implementation should be split into focused child issues after each profile and validation requirement is clearly defined.

Background

External signing changes where the private-key operation happens, but it does not remove the need for correct PDF, CMS and PAdES processing.

Future eIDAS and long-term validation use cases may require stronger signature profiles, timestamps, revocation information and validation evidence.

These capabilities belong in the signing and validation layers, not in CSC, QTSP or hardware-provider integrations.

Goal

Extend LibreSign's PAdES and validation capabilities so that remote and local external signing can use the same standards-compliant document layer.

Areas to evaluate

The roadmap should evaluate and, where required, implement:

  • PAdES baseline profiles;
  • timestamp support;
  • certificate and chain validation;
  • OCSP and CRL handling;
  • embedding validation material for long-term validation;
  • preservation of existing signatures during incremental updates;
  • validation at signing time;
  • long-term validation behavior;
  • interoperability with independent PDF signature validators.

The exact target profiles, including B-B, B-T, B-LT and B-LTA, must be selected based on real use cases and standards requirements before implementation starts.

Why this matters

A remote signature is only useful if the resulting document remains interoperable and verifiable.

Keeping these capabilities in a common PAdES layer means that CSC, eIDAS trust services, HSMs and physical certificates can all reuse the same document implementation.

Business and funding value

Long-lived documents, public-sector workflows, regulated organizations and archival processes often require stronger validation guarantees than a basic digital signature.

Funding this work improves LibreSign for all signing methods, not only one provider or certificate type.

Dependencies

This epic can progress incrementally, but its priorities should be coordinated with:

  • #8335;
  • #8943 CSC support;
  • #8944 eIDAS trust service interoperability;
  • #8945 local and hardware-backed signing.

Out of scope

Provider authentication, credential discovery, OAuth and hardware communication are not part of this epic.

Done when

The selected PAdES profiles and validation requirements are implemented with automated regression and interoperability tests and can be reused by local and remote signing providers.

Lingua principale
PHP
Stelle
828
Fork
159
Merge medio
8h 14m
PR unite (30g)
556

Preparare l'ambiente

Apri in Codespaces

Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di LibreSign/libresign

Tutte le issue di LibreSign/libresign

Issue simili

Altre issue su PHP

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.