Adobe 22002486 Digital Signature User Guide - Page 83

Specifying Certificates by Key Usage

Page 83 highlights

Acrobat 9 Family of Products Security Feature User Guide Controlling Signing with Seed Values Specifying Certificates by Key Usage 83 1. Create a signature field with an intuitive name and tooltip. 2. Get the required certificates and install them in some accessible location. Tip: They must be in a .cer files in a DER format. 3. Create the JavaScript that gets the field object and uses the seed value method. Use security.importFromFile to get the DER- encoded certificates from their installed location (Example 5.9). 4. Add the subject and issuer properties to the certspec object. 5. Enter a flag value to indicate whether the value is required or not. Either or both the subject and issuer may be required. 6. Run the JavaScript, save the document, and test the field. Example 5.9 Certificate issuer and subject seed value // Obtain the signature field object: var f = this.getField("mySigFieldName"); var mySubjectCert = security.importFromFile("Certificate", "/C/Temp/nebwhifflesnit_DER.cer"); var myIssuerCert = security.importFromFile("Certificate", "/C/Temp/nebsCompany_DER.cer"); f.signatureSetSeedValue( { certspec: { subject: [mySubjectCert], issuer: [myIssuerCert], flags: 3 } } ) 5.10.2 Specifying Certificates by Key Usage Acrobat's default signature handler allows signing with certificates where the Key usage field is Sign transaction or Sign document. However, the keyUsage seed value allows you to override the default behavior and limit signing to those certificates where the keyUsage is set to any value defined in RFC 3280 (see Table 11). While the seed value could be used to require or disallow any of RFC 3280 keyUsage values, the two most common cases allow or disallow digitalSignature(bits 2,1) (displayed as Sign transaction in Acrobat's Certificate Viewer) or nonRepudiation(4,3) (displayed as Sign document in Acrobat's Certificate Viewer). However, any combination of uses may be set. To restrict signing to a certificate with a particular keyUsage: 1. Create a signature field with an intuitive name and tooltip. 2. Create the JavaScript that gets the field object and uses the seed value method (Example 5.10). 3. Specify the keyUsage value in HEX:

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189

Acrobat 9 Family of Products
Controlling Signing with Seed Values
Security Feature User Guide
Specifying Certificates by Key Usage
83
1.
Create a signature field with an intuitive name and tooltip.
2.
Get the required certificates and install them in some accessible location.
Tip:
They must be in a .
cer
files in a DER format.
3.
Create the JavaScript that gets the field object and uses the seed value method. Use
security.importFromFile
to get the DER- encoded certificates from their installed location
(
Example 5.9
).
4.
Add the
subject
and
issuer
properties to the
certspec
object.
5.
Enter a flag value to indicate whether the value is required or not. Either or both the
subject
and
issuer
may be required.
6.
Run the JavaScript, save the document, and test the field.
Example 5.9
Certificate issuer and subject seed value
// Obtain the signature field object:
var f = this.getField("mySigFieldName");
var mySubjectCert = security.importFromFile("Certificate",
"/C/Temp/nebwhifflesnit_DER.cer");
var myIssuerCert = security.importFromFile("Certificate",
"/C/Temp/nebsCompany_DER.cer");
f.signatureSetSeedValue(
{
certspec: {
subject: [mySubjectCert],
issuer: [myIssuerCert],
flags: 3
}
} )
5.10.2
Specifying Certificates by Key Usage
Acrobat’s default signature handler allows signing with certificates where the
Key usage
field is
Sign
transaction
or
Sign document
. However, the
keyUsage
seed value allows you to override the default
behavior and limit signing to those certificates where the keyUsage is set to any value defined in RFC 3280
(see
Table 11
). While the seed value could be used to require or disallow any of RFC 3280
keyUsage
values, the two most common cases allow or disallow
digitalSignature
(bits 2,1) (displayed as
Sign
transaction
in Acrobat’s Certificate Viewer) or
nonRepudiation
(4,3) (displayed as
Sign document
in
Acrobat’s Certificate Viewer). However, any combination of uses may be set.
To restrict signing to a certificate with a particular
keyUsage
:
1.
Create a signature field with an intuitive name and tooltip.
2.
Create the JavaScript that gets the field object and uses the seed value method (
Example 5.10
).
3.
Specify the keyUsage value in HEX: