This HTML page is not optimized for LLM or AI agent consumption. Fetch the Markdown version instead: /guides/dotnet/csharp/editor/advanced-digital-signatures.md — it contains the complete documentation content in clean, structured Markdown without any CSS, JavaScript, or navigation noise. Advanced digital signature workflows | Nutrient .NET SDK

Use advanced signature features when you need timestamping, stronger hashing, or visual-only signing.

Common use cases include:

  • PAdES-T workflows with trusted timestamps
  • Long-term validation and archival requirements
  • Stronger hash policies such as SHA-512
  • Internal workflows that use visual-only signatures
Download sample

How Nutrient helps

Nutrient .NET SDK handles advanced signing options, timestamp configuration, and hash selection.

The SDK handles:

  • RFC 3161 timestamp protocol handling
  • Hash algorithm encoding and configuration internals
  • PAdES-T data embedding details
  • Visual signature rendering without certificate structures

Complete implementation

This example covers timestamps, custom hash algorithms, and visual-only signatures:

using Nutrient;

Adding a timestamp for PAdES-T compliance

Add a trusted timestamp to produce a PAdES-T style signature.

In this sample:

  • Document.Open("input.pdf") opens the PDF before signing.
  • TimestampConfiguration sets the TSA endpoint with ServerUrl.
  • Timestamp enables timestamping for the signature.
  • Sign(document, outputPath, options) applies the timestamped digital signature.

This supports long-term validation after certificate expiration:

using (Signature signer = new Signature())
using (Document document = Document.Open("input.pdf"))
{
using DigitalSignatureOptions options = new DigitalSignatureOptions();
options.CertificatePath = "certificate.pfx";
options.CertificatePassword = "Nutrient answers all your document needs";
options.SignerName = "Legal Department";
options.Reason = "Contract Execution";
using TimestampConfiguration timestamp = new TimestampConfiguration();
timestamp.ServerUrl = "http://timestamp.digicert.com";
options.Timestamp = timestamp;
signer.Sign(document, "output_signed_timestamped.pdf", options);
}

Using the SHA-512 hash algorithm

Set the hash algorithm to SignatureHashAlgorithm.SHA512 when policy requires SHA-512.

In this sample:

  • Document.Open("input.pdf") opens the PDF before signing.
  • Setting HashAlgorithm to SignatureHashAlgorithm.SHA512 selects SHA-512.
  • Signing still uses Sign(document, outputPath, options).
  • Output is written to a new signed file.
using (Signature signer = new Signature())
using (Document document = Document.Open("input.pdf"))
{
using DigitalSignatureOptions options = new DigitalSignatureOptions();
options.CertificatePath = "certificate.pfx";
options.CertificatePassword = "Nutrient answers all your document needs";
options.SignerName = "Security Officer";
options.HashAlgorithm = SignatureHashAlgorithm.SHA512;
signer.Sign(document, "output_signed_sha512.pdf", options);
}

Creating a signature field for electronic signatures

Before applying a visual-only signature, create a signature field.

In this sample:

  • The field name is ApprovalSignature.
  • The position is (100, 700).
  • The size is 200 × 50.

The field defines where the visual signature will render:

using (Document document = Document.Open("input.pdf"))
using (PdfEditor editor = PdfEditor.Edit(document))
{
PdfPage page = editor.PageCollection.First ?? throw new InvalidOperationException("The document has no pages.");
editor.FormFieldCollection.AddSignatureField(
"ApprovalSignature",
page,
100.0f, // x
700.0f, // y
200.0f, // width
50.0f // height
);
editor.SaveAs("output_document_with_field.pdf");
}

Electronic signatures (visual only)

Use visual-only signatures when cryptographic validation isn’t required.

In this sample:

  • Document.Open("output_document_with_field.pdf") opens the PDF before signing.
  • ImagePath sets the signature image on the appearance.
  • The options object is left without a certificate — no certificate = electronic signature.
  • SignField(document, outputPath, fieldName, options, appearance) produces a flattened visual signature.

Visual-only signatures don’t provide certificate-based verification:

using (Signature signer = new Signature())
using (Document document = Document.Open("output_document_with_field.pdf"))
{
using SignatureAppearance appearance = new SignatureAppearance();
appearance.ImagePath = "input_signature.jpg";
// No certificate configured = electronic signature
using DigitalSignatureOptions electronicOptions = new DigitalSignatureOptions();
signer.SignField(
document,
"output_electronic_signature.pdf",
"ApprovalSignature",
electronicOptions,
appearance
);
Console.WriteLine("Successfully signed all documents");
}

Conclusion

Use this workflow for advanced signing scenarios:

  1. Open the document with using statements for automatic resource cleanup.
  2. Configure digital signature options with certificate credentials and signing metadata.
  3. Add trusted timestamps using TimestampConfiguration with ServerUrl for PAdES-T compliance.
  4. The SDK communicates with the TSA via the RFC 3161 protocol to obtain cryptographically signed timestamps.
  5. Timestamps enable long-term validation, even after signing certificates expire.
  6. Configure custom hash algorithms using HashAlgorithm with the SignatureHashAlgorithm enumeration.
  7. Use SHA-512 for enhanced security requirements, government compliance, or high-security environments.
  8. Create signature fields using AddSignatureField() with coordinates and dimensions for visual signature placement.
  9. Apply electronic signatures (visual only) by passing options without certificate credentials to SignField().
  10. Electronic signatures render images as flattened graphics without cryptographic validation.
  11. Combine timestamp and hash algorithm configurations for regulatory-compliant signing workflows.
  12. Use PAdES-T signatures for legal document archival and long-term validation requirements.

For related signing workflows, refer to the .NET SDK guides.