Digital Signature Verification for .p7s, .sig and PDF Files
An online tool for verifying digital signatures: it opens .sig, .p7s and .p7m files, extracts the document from an attached signature and shows who signed it, when, and with which certificate. It checks RSA, RSA-PSS and ECDSA electronic signatures, Russian GOST R 34.10-2012 ones and signatures embedded in PDF files. The same page can also sign any file with your own key, producing a standard CMS signature.
How to verify a signature
The signature (.sig, .p7s) and the document, together or one after the other. A signed PDF is a single file.
Who signed, when, whether the document was changed and who issued the certificate — point by point.
The document from the signature, the signer’s certificate or a PDF verification report.
Open a .p7s, .sig or signed PDF and see who signed the document and when
Verification and signing run in your browser via WebCrypto
What the check shows
- Who signedName, job title, organization, IDs in the certificate and the certificate authority
- WhenSigning time, plus a trusted timestamp if there is one
- Whether the document changedSHA or GOST R 34.11-2012 hash and the signature math
- The document inside a .sigIf the document is inside the signature, you can open it and save it
RSA, ECDSA, GOST R 34.10-2012 and 2001, and signatures inside PDFs.
2 · Who is signing
The key is password-protected — enter the password to sign.
3 · How to sign
What you get
- A standard .sig fileCMS format: this page, OpenSSL and other programs can verify it
- Name and time are signedThey cannot be changed unnoticed — verification will catch it
- The key is yoursIt lives in this browser; the backup is a standard .p12 file
- Trusted timeA timestamp from a time server confirms when you signed
The recipient gets
Save a backup of your key. Without it, signing on another device or after clearing the browser will use a new key with a different fingerprint.
This is an electronic signature made with your own key, not a qualified one. Tax filings, public tenders and courts in many countries require a qualified signature (a QES under eIDAS in the EU, or one from an accredited certificate authority elsewhere), and wherever the law or the other party requires it, this signature is not enough. It does prove the file has not changed since signing, and parties can agree between themselves to accept it.