Sample code for 30+ languages & platforms
Xbase++

Sign PDF using PAdES-Baseline-B

See more PDF Signatures Examples

PAdES-Baseline-B is the most basic, entry-level profile of the PDF Advanced Electronic Signatures (PAdES) standard.

It means:

  • A PDF contains a CMS/PKCS#7 detached signature over the document’s byte range.
  • /SubFilter must be ETSI.CAdES.detached.
  • The signer’s X.509 certificate is included inside the signature.
  • The signature uses recognized secure algorithms (e.g., SHA-256 with RSA/ECDSA).
  • It proves document integrity (no changes since signing) and signer authenticity (certificate identifies who signed).
  • It does not include time-stamps, revocation data (CRL/OCSP), or long-term validation information — those appear only in higher levels (PAdES-Baseline-T, -LT, -LTA).

In short: Baseline-B = a standard PDF digital signature that ensures integrity and origin, but without time or revocation guarantees.

Chilkat Xbase++ Downloads

Xbase++
LOCAL nSuccess
LOCAL oPdf
LOCAL oJson
LOCAL oCert
LOCAL cOutFilePath

nSuccess := 0

oPdf := CreateObject("Chilkat.Pdf")

//  Load a PDF to be signed.
nSuccess := oPdf:LoadFile("c:/someDir/my.pdf")
IF (nSuccess == 0)
    ? oPdf:LastErrorText
    oPdf:destroy()
    RETURN
ENDIF

//  Options for signing are specified in JSON.
oJson := CreateObject("Chilkat.JsonObject")

oJson:UpdateString("subFilter", "/ETSI.CAdES.detached")
oJson:UpdateBool("signingCertificateV2", 1)
oJson:UpdateBool("signingTime", 1)
oJson:UpdateString("signingAlgorithm", "pkcs")
oJson:UpdateString("hashAlgorithm", "sha256")

//  -----------------------------------------------------------
//  The following JSON settings define the signature appearance.
oJson:UpdateInt("page", 1)
oJson:UpdateString("appearance.y", "top")
oJson:UpdateString("appearance.x", "left")
oJson:UpdateString("appearance.fontScale", "10.0")
oJson:UpdateString("appearance.text[0]", "Digitally signed by: cert_cn")
oJson:UpdateString("appearance.text[1]", "current_dt")
oJson:UpdateString("appearance.text[2]", "Hello 123 ABC")

//  --------------------------------------------------------------
//  Load the signing certificate. (Use your own certificate.)
//  Note: There are other methods for using a certificate on an HSM (smartcard or token)
//  or from other sources, such as a cloud HSM, a Windows installed certificate,
//  or other file formats.
oCert := CreateObject("Chilkat.Cert")
nSuccess := oCert:LoadPfxFile("c:/myPfxFiles/myPdfSigningCert.pfx", "pfxPassword")
IF (nSuccess == 0)
    ? oCert:LastErrorText
    oPdf:destroy()
    oJson:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Once we have the certificate object, tell the PDF object to use it for signing
nSuccess := oPdf:SetSigningCert(oCert)
IF (nSuccess == 0)
    ? oPdf:LastErrorText
    oPdf:destroy()
    oJson:destroy()
    oCert:destroy()
    RETURN
ENDIF

//  Sign the PDF, creating the output file.
cOutFilePath := "c:/someDir/mySigned.pdf"
nSuccess := oPdf:SignPdf(oJson, cOutFilePath)
IF (nSuccess == 0)
    ? oPdf:LastErrorText
    oPdf:destroy()
    oJson:destroy()
    oCert:destroy()
    RETURN
ENDIF

? "Success."

oPdf:destroy()
oJson:destroy()
oCert:destroy()