From signing to validation and long-term protection
PL/SIGN covers more than signature creation. Build complete Oracle signing workflows with local or external signing, trusted timestamps, long-term PAdES profiles and detailed signature validation.
Local or external signing
Sign directly with RSA signing material supplied to PL/SIGN, or use a two-phase external signing workflow when the private key must remain outside Oracle.
- Local RSA signing
- HSM integration
- Remote and cloud signing services
- QTSP signing workflows
- Prepare and complete APIs for CAdES and PAdES
Approval and certification signatures
Create ordinary PAdES approval signatures or certification signatures that define permitted later changes to the PDF using DocMDP permissions.
- Approval signatures
- Certification signatures
- DocMDP permissions 1, 2 and 3
- Existing or newly created signature fields
- Incremental PDF signing
RFC 3161 trusted timestamps
Add standards-based signature timestamps to CAdES and PAdES signatures and validate timestamp responses against the expected message imprint and nonce.
- CAdES B-T and PAdES B-T
- RFC 3161 timestamp requests
- Timestamp response validation
- PL/SQL callback-based TSA integration
- Direct HTTPS TSA integration
PAdES B-LT
Build long-term validation into signed PDFs by validating supplied certificate and revocation evidence and embedding the required validation material in the PDF DSS.
- Trust anchors and certificate chains
- OCSP response validation
- CRL validation
- Certificate path validation
- DSS validation material embedding
PAdES B-LTA archival protection
Add PDF document timestamps after the validation-evidence stage and renew them later to extend archival protection for long-lived signed documents.
- PDF Document Timestamps
- B-LT to B-LTA workflows
- External TSA transport
- Direct HTTPS TSA support
- Document Timestamp renewal
Signature validation
Inspect existing PDF signatures and timestamps with read-only validation APIs that return detailed technical and long-term validation results to your Oracle application.
- PDF signature structure and ByteRange
- CMS and cryptographic signature validation
- Signing certificate and timestamp status
- Profile and long-term validation status
- Trust, certificate path and revocation status
Validation you can integrate into application logic
PL/SIGN does not reduce validation to a simple valid or invalid flag. Applications can inspect detailed status information for each discovered signature and document timestamp.
Technical validation
Validate PDF structure, signature ByteRange, CMS content, cryptographic signature, signing certificate, timestamp and PAdES profile without modifying the document.
Trust and revocation validation
Supply your own trusted roots, intermediate certificates, OCSP responses and CRLs to evaluate certificate paths, trust and revocation at the required validation time.
Structured validation results
Use explicit PASS, FAIL, INDETERMINATE, UNSUPPORTED, NOT_APPLICABLE and NOT_CHECKED states together with per-signature diagnostics in your own application workflow.
