Sample code for 30+ languages & platforms
Zig

Sign PDF using PAdES-Baseline-B

See more PDF Signatures Examples

PAdES-Baseline-B is the most basic, entry-level profile of the PDF Advanced Electronic Signatures (PAdES) standard.

It means:

  • A PDF contains a CMS/PKCS#7 detached signature over the document’s byte range.
  • /SubFilter must be ETSI.CAdES.detached.
  • The signer’s X.509 certificate is included inside the signature.
  • The signature uses recognized secure algorithms (e.g., SHA-256 with RSA/ECDSA).
  • It proves document integrity (no changes since signing) and signer authenticity (certificate identifies who signed).
  • It does not include time-stamps, revocation data (CRL/OCSP), or long-term validation information — those appear only in higher levels (PAdES-Baseline-T, -LT, -LTA).

In short: Baseline-B = a standard PDF digital signature that ensures integrity and origin, but without time or revocation guarantees.

Chilkat Zig Downloads

Zig
const std = @import("std");
const chilkat = @import("chilkat");

pub fn main(init: std.process.Init) !void {
    const alloc = init.arena.allocator();

    const pdf = try chilkat.Pdf.init();
    defer pdf.deinit();

    // Load a PDF to be signed.
    pdf.loadFile("c:/someDir/my.pdf") catch {
        std.debug.print("{s}\n", .{try pdf.getLastErrorText(alloc)});
        return;
    };

    // Options for signing are specified in JSON.
    const json = try chilkat.JsonObject.init();
    defer json.deinit();

    json.updateString("subFilter", "/ETSI.CAdES.detached") catch {};
    json.updateBool("signingCertificateV2", true) catch {};
    json.updateBool("signingTime", true) catch {};
    json.updateString("signingAlgorithm", "pkcs") catch {};
    json.updateString("hashAlgorithm", "sha256") catch {};

    // -----------------------------------------------------------
    // The following JSON settings define the signature appearance.
    json.updateInt("page", 1) catch {};
    json.updateString("appearance.y", "top") catch {};
    json.updateString("appearance.x", "left") catch {};
    json.updateString("appearance.fontScale", "10.0") catch {};
    json.updateString("appearance.text[0]", "Digitally signed by: cert_cn") catch {};
    json.updateString("appearance.text[1]", "current_dt") catch {};
    json.updateString("appearance.text[2]", "Hello 123 ABC") catch {};

    // --------------------------------------------------------------
    // Load the signing certificate. (Use your own certificate.)
    // Note: There are other methods for using a certificate on an HSM (smartcard or token)
    // or from other sources, such as a cloud HSM, a Windows installed certificate,
    // or other file formats.
    const cert = try chilkat.Cert.init();
    defer cert.deinit();
    cert.loadPfxFile("c:/myPfxFiles/myPdfSigningCert.pfx", "pfxPassword") catch {
        std.debug.print("{s}\n", .{try cert.getLastErrorText(alloc)});
        return;
    };

    // Once we have the certificate object, tell the PDF object to use it for signing
    pdf.setSigningCert(cert) catch {
        std.debug.print("{s}\n", .{try pdf.getLastErrorText(alloc)});
        return;
    };

    // Sign the PDF, creating the output file.
    const out_file_path = "c:/someDir/mySigned.pdf";
    pdf.signPdf(json, out_file_path) catch {
        std.debug.print("{s}\n", .{try pdf.getLastErrorText(alloc)});
        return;
    };

    std.debug.print("Success.\n", .{});
}