OASIS Mailing List ArchivesView the OASIS mailing list archive below
or browse/search using MarkMail.

 


Help: OASIS Mailing Lists Help | MarkMail Help

dss-x message

[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]


Subject: RE: Fw: [dss-x] Visual Signatures profile



>  The first three items in your simple approach are fine - nothing
>  "problematic" there.
Hey, good start ;-)

>  The fourth, however, is the one that starts to introduce some
>  complexity.  In order to "lock down" a PDF after signing, you need
>  to use what it called a "certifying signature" along with "MDP"
>  (modification, detection and prevention) rules.
>   Doing so, of course, will prevent any future signing -
>  which would be problematic if the form really requires parallel
>  or sequential sigs. However, MDP rights allow you to prevent all
>  changes EXCEPT other signing - so perhaps that's the route to
>  consider...
Hmm, I'm not quite sure what you are talking about. I just meant that 
this profile doesn't do anything more than filling out the signature 
field, nothing fancy. No update of visible fields with e.g. signing time 
nor inserting a gold shimmering 'seal' icon.

I don't intend to apply any right management functions regarding future 
changes of the document. For me the signature is sufficient !

Greetings

Andreas

>
> -----Original Message-----
> From: Andreas Kuehne [mailto:kuehne@trustable.de]
> Sent: Tuesday, April 01, 2008 5:28 AM
> To: Leonard Rosenthol
> Cc: dss@lists.oasis-open.org
> Subject: Re: Fw: [dss-x] Visual Signatures profile
>
> Hi Leonard !
>
> Konrad said something very important yesterday :
>
> 'Think of requirements, not of existing solutions !'
>
> I hope I remember it correctly ... but it's true anyway. 2D barcodes 
> are
> funny stuff to impress my kids and colleagues, but our real use case is
> : Mass signing of PDF invoice documents. That's not a tricky 
> requirement
> at all, but I just can't do it using DSS right now !
>
> So I would like to go for a signing profile for PDF documents starting
> with the core's successful keep-it-simple approach in mind :
>
> - One signature at a time
> - Pre-configured signature field included in the document
> - DSS's signature placement enhanced to be a pointer into a PDF doc
> - No update of the PDF beyond the signature field
>
> Same for Verification. I have no experience with timestamps in PDFs,
> maybe the simple signature approach will fit ??
>
> This would introduce a new profile with focus on PDF as a signature
> container format, independent from the visual signature efforts. Does
> this makes sense to you ?
>
> More sophisticated profiles may aggregate this functionality, but 
> that's
> not my use case.
>
>
> Opinions welcome
>
> Andreas
>
>

___________________________________________________
Andreas Kühne
phone: +49 177 293 24 97
mailto: kuehne@trustable.de


Trustable Ltd.
Niederlassung Deutschland
Ströverstr. 18 - 59427 Unna
Amtsgericht Hamm HRB 5868

Directors
Andreas Kühne
Heiko Veit

Company UK
Company No: 5218868
Registered in England and Wales


[Date Prev] | [Thread Prev] | [Thread Next] | [Date Next] -- [Date Index] | [Thread Index] | [List Home]