Built-in signing services
This document describes the signing services that are provided out-of-the-box with the software and fully compatible will all the built-in workflows.
Static configuration must be added in application-workflow.yml configuration file.
Simple Electronic Signature
This signing service is intended to provide digital signatures for natural persons to sign documents without any legal requirements, such as orders, conditions agreements, etc.
Depending the service's configuration, the digital signature may contain the signatory name or only its username.
Digital signatures created by this signing service are not going to be trusted by Adobe Approved Trusted List (AATL) unless one of the certificates in the chain is explicitly trusted on the user's computer.
Configuration
The signing service is activated by default and does not necessarily require a configuration unless the signature attributes requirements are different than the default values.
application-workflow.yml
signing-services:
ses-pdf:
signature:
subject-dn-pattern: "CN={username}" <1>
digest-algorithm: SHA256 <2>
signature-algorithm: RSA <3>
key-length: 2048 <4>
tsa-url: http://tsa.company.com <5>
tsa-username: tsaUsername <6>
tsa-password: tsaPassword <7>
ignore-missing-revocation-data-alerts: false <8>
check-revocation-for-untrusted-chains: false <9>- Distinguished Name to be used in the certificate. It may be overridden using a contract's meta data. In addition to the
{username}, different placeholders referring to existing contract's meta data may be added :userEmail,firstname,lastname,phoneNumberandcountryCode. Default :CN={username} - Digest algorithm. Default :
SHA256 - Signature algorithm. Default :
RSA - Signature key's length. Default :
2048 - Time Stamp Authority URL to enable Long-Term Validation (LTV) signatures
- username for Basic authentication against Time Stamp Authority
- password for Basic authentication against Time Stamp Authority (the Authentication requires the definition of an host connection: configuration implicitly use tsa-url host and port)
- Ignore errors when revocation data are not included from certificates (optional, must not be enabled on production environment). Default:
false - Enable revocation checking for untrusted certificate chains (optional). Default:
false
**
Contract's meta data
Contract's metadata
{
"metaData" : {
"remoteSigningService" : "ses-pdf", <1>
"distinguishedNamePattern" : "CN={firstname} {lastname} ({userEmail}, {phoneNumber})", <2>
"firstname" : "John", <3>
"lastname" : "Doe", <4>
"userEmail" : "john.doe@example.com", <5>
"phoneNumber" : "+41761234567" <6>
},
}- The signing service identifier (required)
- Overrides default DN pattern (optional)
- Attribute required by the overridden DN (optional)
- Attribute required by the overridden DN (optional)
- Attribute required by the overridden DN (optional)
- Attribute required by the overridden DN (optional)
Local Keystore
This signing service is intended to provide digital signatures based on a certificate associated to a legal person / entity and configured server-side. This service can by typically used to sign documents published internally into a company.
Digital signatures created by this signing service are not going to be trusted by Adobe Approved Trusted List (AATL) unless one of the certificates in the chain is explicitly trusted on the user's computer.
Configuration
The signing service supports one ore multiple keystores that need to be configured statically.
application-workflow.yml
signing-services:
keystores: <1>
keystore-example: <2>
keystore-path: conf/keyStore.p12 <3>
keystore-password: changeit <4>
keystore-type: pkcs12 <5>
another-keystore:
keystore-path: conf/anotherKeystore.p12
keystore-password: changeit- List of keystore configuration (required)
- Identifier of the keystore (required)
- Path of the keystore (required)
- Password of the keystore (required)
- Type of the keystore (optional). Default :
pkcs12
Contract's meta data
Contract's metadata
{
"metaData" : {
"remoteSigningService" : "local-keystore", <1>
"localKeystoreIdentifier" : "keystore-example" <2>
},
}- The signing service identifier (required)
- The keystore identifier (required)
SMS Authentication
This signing service aims to enforce security of a synchronous signing service (such as an electronic seal) with an OTP verification sent by SMS to the end-user.
Configuration
This signing service requires the deployment of a dedicated SMS Authorization server module provided by SwissSign.
It requires as well the following configuration in configuration file application-workflow.yml to be activated.
application-workflow.yml
workflow:
sms-auth:
auth:
url: http://localhost:8080/authentication <1>
username: admin <2>
password: changeit <3>
timeout: 5m <4>- URL of the authentication module (required)
- Username for basic authentication (required)
- Password for basic authentication (required)
- Timeout duration of the authentication request (optional). Default:
5m
Contract's meta data
Contract's metadata
{
"metaData" : {
"remoteSigningService" : "sms-auth", <1>
"delegatedRemoteSigningService" : "signing-service-identifier" <2>
}
}- The signing service identifier (required)
- The synchronous signing service that will issue the signature after user confirmation (required)
Swisscom All-In Signing Service
Qualified Electronic Signature
This signing service offers qualified electronic signatures for natural persons. Electronic signatures are suitable for signing digital contracts that are provided to the signatory via an online signature portal or an application. The advantage over a handwritten signature is that electronic signatures can ensure the integrity, authenticity and timing of the signature by one person on the digital document.
The signing service for Qualified Electronic Signature requires that signatories are registered in the Swisscom RA-App with a level of assurance for Qualified signature prior being able to sign a document.
Read more : https://trustservices.swisscom.com/en/smart-registration-service/
Configuration
application-workflow.yml
signing-services:
swisscom-on-demand:
keystore-path: /conf/swisscom.p12 <1>
keystore-password: changeit <2>
swisscom-on-demand-qes:
claimed-identity: ais-90days-trial-withRAservice:OnDemand-Advanced4 <3>
distinguished-name-pattern: cn=TEST ${givenname} ${surname},givenname=${givenname},surname=${surname},c=${countryCode},serialNumber=${serialNumber} <4>
jurisdiction: zertes <5>
alternative-claimed-identities: <6>
eidas-ppu: <7>
claimed-identity: company.ppu:OnDemand-Qualified-EU
distinguished-name-pattern: template:name
jurisdiction: eidas- Path of the keystore containing TLS Client Certificate (required)
- Password of the keystore (required)
- Default claimed identity defined by the agreement (required)
- Default distinguished name pattern defined by the agreement (required)
- Default jurisdiction [
zertes,eidas] defined by the agreement (optional). Default :zertes - Configuration for additional claimed identities configuration bound to the same contract (optional)
- Identifier of the alternative claim identity
Contract's meta data
Contract's metadata
{
"metaData" : {
"remoteSigningService" : "swisscom-on-demand-qes", <1>
"phoneNumber" : "+41761234567", <2>
"locale" : "de", <3>
"alternativeClaimedIdentity" : "eidas-ppu" <4>
},
}- The signing service identifier (required)
- The phone number (E.164) of the user (required)
- The locale of the user [
fr,en,de,it] (optional). Default:en - The identifier of the alternative claimed identity, if not set the primary claimed is used (optional)
Advanced Electronic Signature
This signing service offers advanced electronic signatures for natural persons. Electronic signatures are suitable for signing digital contracts that are provided to the signatory via an online signature portal or an application. The advantage over a handwritten signature is that electronic signatures can ensure the integrity, authenticity and timing of the signature by one person on the digital document.
The signing service for Advanced Electronic Signature requires that signatories are registered in the Swisscom RA-App with a level of assurance for Advanced signature prior being able to sign a document.
Configuration
application-workflow.yml
signing-services:
swisscom-on-demand:
keystore-path: /conf/swisscom.p12 <1>
keystore-password: changeit <2>
swisscom-on-demand-ades:
claimed-identity: ais-90days-trial-withRAservice:OnDemand-Advanced4 <3>
distinguished-name-pattern: cn=TEST ${given_name} ${family_name},givenname=${given_name},surname=${family_name},c=${country},serialNumber=${evidence_id} <4>
jurisdiction: zertes <5>
alternative-claimed-identities: <6>
zertes-ppu: <7>
claimed-identity: company.ppu:OnDemand-Advanced-CH
distinguished-name-pattern: template:name
jurisdiction: zertes- Path of the keystore containing TLS Client Certificate (required)
- Password of the keystore (required)
- Default claimed identity defined by the agreement (required)
- Default distinguished name pattern defined by the agreement (required)
- Default jurisdiction [
zertes,eidas] defined by the agreement (optional). Default :zertes - Configuration for additional claimed identities configuration bound to the same contract (optional)
- Identifier of the alternative claim identity
Contract's meta data
Contract's metadata
{
"metaData" : {
"remoteSigningService" : "swisscom-on-demand-ades", <1>
"phoneNumber" : "+41761234567", <2>
"locale" : "de", <3>
"alternativeClaimedIdentity" : "zertes-ppu" <4>
},
}- The signing service identifier (required)
- The phone number (E.164) of the user (required)
- The locale of the user [
fr,en,de,it] (optional). Default:en - The identifier of the alternative claimed identity, if not set the primary claimed is used (optional)
Electronic Seal
For legal entities (e.g. organisational signatures), this signing service offers advanced seals. Electronic seals are suitable for mass mailing of documents and invoices. In addition, an electronic seal ensures integrity, the timing of the seal by a legal entity and authenticity on digital documents.
Configuration
application-workflow.yml
signing-services:
swisscom-electronic-seal:
keystore-path: /conf/swisscom.p12 <1>
keystore-password: changeit <2>
claimed-identity: ais-90days-trial:static-saphir4-ch <3>
signer-distinguished-name: cn=All-in Signing Service TEST account,o=TEST Swisscom (Schweiz) AG,c=CH <4>
additional-interfaces: <5>
seal-company-a: <6>
keystore-path: /conf/swisscom_company-a.p12
keystore-password: changeit
claimed-identity: company-a:static-saphir4-ch
signer-distinguished-name: cn=Company Name,o=Company Name AG (Schweiz),c=CH- Path of the keystore containing TLS Client Certificate (required)
- Password of the keystore (required)
- Default claimed identity defined by the agreement (required)
- Default distinguished name pattern defined by the agreement (required)
- Configuration for additional interfaces configuration (optional)
- Identifier of the alternative seal interface
Contract's meta data
Contract's metadata
{
"metaData" : {
"remoteSigningService" : "swisscom-electronic-seal", <1>
"swisscomSealInterfaceId" : "seal-company-a" <2>
},
}- The signing service identifier (required)
- The identifier of the alternative seal interface, if not set the primary interface is used (optional)