Add advanced PAdES and long-term signature validation
I maintainer di solito rispondono entro 1 giorno
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 5/5
- Tempo stimato
- Più di una settimana
- Idoneità per principianti
- 15/100
- Tipo di issue
- Funzionalità
- Chiarezza
- Da chiarire
- Stato di attività
- Attiva
- Ambito
- cryptography, security
Direzione di ricerca
No implementation files or tests are named; this issue explicitly says not to implement the epic directly. Start by defining the target PAdES profiles and validation requirements, then split the work into focused child issues. Coordinate with #8335, #8943, #8944, and #8945, with automated regression and interoperability tests as the completion criteria.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
This is a roadmap and funding epic.
[!IMPORTANT]
Do not implement this epic directly.
This issue is for planning, research and funding of the PAdES and validation capabilities needed by future remote-signing, eIDAS and long-term document workflows.
Implementation should be split into focused child issues after each profile and validation requirement is clearly defined.
Background
External signing changes where the private-key operation happens, but it does not remove the need for correct PDF, CMS and PAdES processing.
Future eIDAS and long-term validation use cases may require stronger signature profiles, timestamps, revocation information and validation evidence.
These capabilities belong in the signing and validation layers, not in CSC, QTSP or hardware-provider integrations.
Goal
Extend LibreSign's PAdES and validation capabilities so that remote and local external signing can use the same standards-compliant document layer.
Areas to evaluate
The roadmap should evaluate and, where required, implement:
- PAdES baseline profiles;
- timestamp support;
- certificate and chain validation;
- OCSP and CRL handling;
- embedding validation material for long-term validation;
- preservation of existing signatures during incremental updates;
- validation at signing time;
- long-term validation behavior;
- interoperability with independent PDF signature validators.
The exact target profiles, including B-B, B-T, B-LT and B-LTA, must be selected based on real use cases and standards requirements before implementation starts.
Why this matters
A remote signature is only useful if the resulting document remains interoperable and verifiable.
Keeping these capabilities in a common PAdES layer means that CSC, eIDAS trust services, HSMs and physical certificates can all reuse the same document implementation.
Business and funding value
Long-lived documents, public-sector workflows, regulated organizations and archival processes often require stronger validation guarantees than a basic digital signature.
Funding this work improves LibreSign for all signing methods, not only one provider or certificate type.
Dependencies
This epic can progress incrementally, but its priorities should be coordinated with:
- #8335;
- #8943 CSC support;
- #8944 eIDAS trust service interoperability;
- #8945 local and hardware-backed signing.
Out of scope
Provider authentication, credential discovery, OAuth and hardware communication are not part of this epic.
Done when
The selected PAdES profiles and validation requirements are implemented with automated regression and interoperability tests and can be reused by local and remote signing providers.
- Lingua principale
- PHP
- Stelle
- 828
- Fork
- 159
- Merge medio
- 8h 14m
- PR unite (30g)
- 556
Preparare l'ambiente
Avvia il container di sviluppo del progetto nel browser, con il tuo account GitHub.
- Nessun Dockerfile né file Docker Compose
- Ha un modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di LibreSign/libresign
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 83/100
LibreSign/libresign#9007 · 1 reazione ·
I maintainer di solito rispondono entro 1 giorno
-
backend enhancement php
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
I maintainer di solito rispondono entro 1 giorno
-
Validation page says "This document is valid" for a document with no signatureForse già presa @maia-andre l’ha presa 5 giorni fa. Aperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
good first issue
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
LibreSign/libresign#8284 · 5 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
backend enhancement frontend javascript php
Difficoltà 4/5 3-5 giorni Idoneità per principianti 22/100
I maintainer di solito rispondono entro 1 giorno
Tutte le issue di LibreSign/libresign
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
codeigniter4/CodeIgniter4#10616 ·
I maintainer di solito rispondono entro 1 giorno
-
bug code quality
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
SemanticMediaWiki/SemanticMediaWiki#7149 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 65/100
google/site-kit-wp#13825 ·
I maintainer di solito rispondono entro 3 giorni
-
Made by AI module: MCP type: bug
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
I maintainer di solito rispondono entro 1 giorno