Skip to content

Electronic signature and seal

Every document signed with bb-sign carries two complementary elements. The signature is the signer’s: the stroke they drew or the name they typed, and it expresses their intent. The seal is applied by bb-sign on behalf of the organization that sent the envelope, with a digital certificate, and it guarantees that any later change to the PDF is detected. This page explains what each one contains and what it guarantees.

On the Add Your Signature screen, the signer chooses Draw (they trace their signature with a finger or the mouse) or Type (they type their full name and the application renders it in a handwriting typeface). bb-sign keeps an image of that signature together with the time, the IP address and the browser it was submitted from.

The signature identifies the signer and expresses their acceptance. The seal, described below, protects the integrity of the signed document.

When the last signer signs, bb-sign processes every document in the envelope in two steps.

First it stamps on the PDF one seal per signer, at the position the document’s marker indicates or, without a marker, at the bottom-right corner of the last page (see Documents). Each seal contains:

Element What it is
Name and email The signer’s, as the sender entered them.
Date The day they signed, in UTC.
Signature The image they drew or typed.
Hash A SHA-256 digest computed from the name, the email, the date, the envelope identifier and the certificate’s fingerprint. Part of it appears as text around the circular seal, and the seal’s pattern is derived from it.
QR code Links to bb-sign’s public verification page, with the envelope identifier and the start of the hash. See Verify a signed document.

Then bb-sign signs the whole PDF with the organization’s certificate: a detached CMS/PKCS#7 signature of type adbe.pkcs7.detached, with the SHA256withRSA algorithm. It is a standard PDF signature: Adobe Acrobat and compatible readers show it in their signature panel and indicate whether the document changed after it was signed.

This signature has a visible field at the bottom-right corner of the last page, reading “Digitally signed by” followed by the organization’s name and the date. It belongs to the organization, and there is one per document.

We recommend that each organization configure its own certificate, issued in its name. That way the seal carries the organization’s name and PDF readers recognize it as trusted. How to choose one, where to get it and how to upload it is explained in Your own certificate.

Until the organization configures its own, bb-sign seals with Binary Bridges’ testing certificate, whose subject is CN=Binary Bridges SAS, O=Binary Bridges SAS, L=Bogota, C=CO, and the visible field reads “Digitally signed by” Binary Bridges SAS. This certificate is self-signed: the seal still protects the document’s integrity and detects any change, but PDF readers show it as untrusted.

bb-sign embeds the organization’s certificate in the PDF (leaf only), without the chain of the authority that issued it. For a reader to show the signature as verified, it must have that authority’s root installed; that is why it pays to choose a certificate issued by an authority recognized by the readers your recipients use.