Adobe 22002486 Digital Signature User Guide - Page 92

Certification Workflow for Documents with Multiple Signers

Page 92 highlights

Acrobat 9 Family of Products Security Feature User Guide Signing Documents Certification Workflow for Documents with Multiple Signers 92 Figure 63 Certified document indicators Legal Attestations and Warnings Comments For documents with dynamic content, signer's may want to add a legal attestation or comment indicating the included content has been reviewed is specifically permitted. A legal attestation can only be added on certified documents and during signing. When this option is enabled by the signer's application settings, the Certify Document dialog displays a Review button which invokes the PDF Signature Report dialog. The dialog display a Warnings Comment field that allows the signer to choose from a default comment or to create a custom comment. The Enable Reviewing of Document Warnings and Prevent Signing Until Document Warnings Are Reviewed settings function in tandem and should be set together. Setting both these options to Always results in the highest degree of assurance that the signing process is not adversely impacted by malicious content. For details, see "Setting up the Signing Environment" on page 46. 6.2.1 Certification Workflow for Documents with Multiple Signers Certification allows document authors to define what changes are legal (possible), and it allows the recipient to identify whether a document's problematic features (content that could change the document appearance) originated with the certifier or not. More importantly, this gives the recipient the assurance that if these features in the document are indeed malicious, the certifier can be proven to be at fault. The recommended workflow for defensible signatures can then be described as follows: 1. The document author adds the requisite form fields and any other document customizations. Preventing certain future actions (e.g. to form fill in and signing) can be accomplished ahead of time via JavaScript or during signing. 2. The document is signed with a certification signature. If there is problematic content in the document, the certifier chooses Review and adds a Warnings Comment explaining why the content is OK. 3. The document is routed to the next person in the workflow. 4. The document recipient manually validates the certification signature if the application is not set up to validate signatures automatically. 5. Document integrity is verified by right clicking on the certification signature and then choosing Show Signature Properties > Legal tab > View Document Integrity Properties. This action invokes the PDF Signature Report dialog which displays a list of problematic content as well as the certifier's comment about that content (if any). For example, a certifier might state why they have added a link to a corporate web site, JavaScript, or some other item.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189

Acrobat 9 Family of Products
Signing Documents
Security Feature User Guide
Certification Workflow for Documents with Multiple Signers
92
Figure 63
Certified document indicators
Legal Attestations and Warnings Comments
For documents with dynamic content, signer’s may want to add a legal attestation or comment indicating
the included content has been reviewed is specifically permitted. A legal attestation can only be added on
certified documents and during signing. When this option is enabled by the signer’s application settings,
the Certify Document dialog displays a
Review
button which invokes the PDF Signature Report dialog.
The dialog display a
Warnings Comment
field that allows the signer to choose from a default comment or
to create a custom comment.
The
Enable Reviewing of Document Warnings
and
Prevent Signing Until Document Warnings Are
Reviewed
settings function in tandem and should be set together. Setting both these options to
Always
results in the highest degree of assurance that the signing process is not adversely impacted by malicious
content. For details, see
“Setting up the Signing Environment” on page 46
.
6.2.1
Certification Workflow for Documents with Multiple Signers
Certification allows document authors to define what changes are legal (possible), and it allows the
recipient to identify whether a document’s problematic features (content that could change the
document appearance) originated with the certifier or not. More importantly, this gives the recipient the
assurance that if these features in the document are indeed malicious, the certifier can be proven to be at
fault. The recommended workflow for defensible signatures can then be described as follows:
1.
The document author adds the requisite form fields and any other document customizations.
Preventing certain future actions (e.g. to form fill in and signing) can be accomplished ahead of time via
JavaScript or during signing.
2.
The document is signed with a certification signature. If there is problematic content in the document,
the certifier chooses
Review
and adds a Warnings Comment explaining why the content is OK.
3.
The document is routed to the next person in the workflow.
4.
The document recipient manually validates the certification signature if the application is not set up to
validate signatures automatically.
5.
Document integrity is verified by right clicking on the certification signature and then choosing
Show
Signature Properties > Legal
tab
> View Document Integrity Properties
. This action invokes the
PDF Signature Report dialog which displays a list of problematic content as well as the certifier’s
comment about that content (if any). For example, a certifier might state why they have added a link to
a corporate web site, JavaScript, or some other item.