Advanced digital signature workflows
Use advanced signature features when you need timestamping, stronger hashing, or visual-only signing.
Common use cases include:
- PAdES-T workflows with trusted timestamps
- Long-term validation and archival requirements
- Stronger hash policies such as SHA-512
- Internal workflows that use visual-only signatures
How Nutrient helps
Nutrient .NET SDK handles advanced signing options, timestamp configuration, and hash selection.
The SDK handles:
- RFC 3161 timestamp protocol handling
- Hash algorithm encoding and configuration internals
- PAdES-T data embedding details
- Visual signature rendering without certificate structures
Complete implementation
This example covers timestamps, custom hash algorithms, and visual-only signatures:
using Nutrient;Adding a timestamp for PAdES-T compliance
Add a trusted timestamp to produce a PAdES-T style signature.
In this sample:
Document.Open("input.pdf")opens the PDF before signing.TimestampConfigurationsets the TSA endpoint withServerUrl.Timestampenables timestamping for the signature.Sign(document, outputPath, options)applies the timestamped digital signature.
This supports long-term validation after certificate expiration:
using (Signature signer = new Signature())using (Document document = Document.Open("input.pdf")){ using DigitalSignatureOptions options = new DigitalSignatureOptions(); options.CertificatePath = "certificate.pfx"; options.CertificatePassword = "Nutrient answers all your document needs"; options.SignerName = "Legal Department"; options.Reason = "Contract Execution";
using TimestampConfiguration timestamp = new TimestampConfiguration(); timestamp.ServerUrl = "http://timestamp.digicert.com"; options.Timestamp = timestamp;
signer.Sign(document, "output_signed_timestamped.pdf", options);}Using the SHA-512 hash algorithm
Set the hash algorithm to SignatureHashAlgorithm.SHA512 when policy requires SHA-512.
In this sample:
Document.Open("input.pdf")opens the PDF before signing.- Setting
HashAlgorithmtoSignatureHashAlgorithm.SHA512selects SHA-512. - Signing still uses
Sign(document, outputPath, options). - Output is written to a new signed file.
using (Signature signer = new Signature())using (Document document = Document.Open("input.pdf")){ using DigitalSignatureOptions options = new DigitalSignatureOptions(); options.CertificatePath = "certificate.pfx"; options.CertificatePassword = "Nutrient answers all your document needs"; options.SignerName = "Security Officer"; options.HashAlgorithm = SignatureHashAlgorithm.SHA512;
signer.Sign(document, "output_signed_sha512.pdf", options);}Creating a signature field for electronic signatures
Before applying a visual-only signature, create a signature field.
In this sample:
- The field name is
ApprovalSignature. - The position is
(100, 700). - The size is
200 × 50.
The field defines where the visual signature will render:
using (Document document = Document.Open("input.pdf"))using (PdfEditor editor = PdfEditor.Edit(document)){ PdfPage page = editor.PageCollection.First ?? throw new InvalidOperationException("The document has no pages.");
editor.FormFieldCollection.AddSignatureField( "ApprovalSignature", page, 100.0f, // x 700.0f, // y 200.0f, // width 50.0f // height );
editor.SaveAs("output_document_with_field.pdf");}Electronic signatures (visual only)
Use visual-only signatures when cryptographic validation isn’t required.
In this sample:
Document.Open("output_document_with_field.pdf")opens the PDF before signing.ImagePathsets the signature image on the appearance.- The options object is left without a certificate — no certificate = electronic signature.
SignField(document, outputPath, fieldName, options, appearance)produces a flattened visual signature.
Visual-only signatures don’t provide certificate-based verification:
using (Signature signer = new Signature())using (Document document = Document.Open("output_document_with_field.pdf")){ using SignatureAppearance appearance = new SignatureAppearance(); appearance.ImagePath = "input_signature.jpg";
// No certificate configured = electronic signature using DigitalSignatureOptions electronicOptions = new DigitalSignatureOptions();
signer.SignField( document, "output_electronic_signature.pdf", "ApprovalSignature", electronicOptions, appearance ); Console.WriteLine("Successfully signed all documents");}Conclusion
Use this workflow for advanced signing scenarios:
- Open the document with
usingstatements for automatic resource cleanup. - Configure digital signature options with certificate credentials and signing metadata.
- Add trusted timestamps using
TimestampConfigurationwithServerUrlfor PAdES-T compliance. - The SDK communicates with the TSA via the RFC 3161 protocol to obtain cryptographically signed timestamps.
- Timestamps enable long-term validation, even after signing certificates expire.
- Configure custom hash algorithms using
HashAlgorithmwith theSignatureHashAlgorithmenumeration. - Use SHA-512 for enhanced security requirements, government compliance, or high-security environments.
- Create signature fields using
AddSignatureField()with coordinates and dimensions for visual signature placement. - Apply electronic signatures (visual only) by passing options without certificate credentials to
SignField(). - Electronic signatures render images as flattened graphics without cryptographic validation.
- Combine timestamp and hash algorithm configurations for regulatory-compliant signing workflows.
- Use PAdES-T signatures for legal document archival and long-term validation requirements.
For related signing workflows, refer to the .NET SDK guides.