GlobalSign Certificates globalsigncertificates.com. Code Signing, OrganizationSSL Wildcard SAN, PersonalSign USB low, OrganizationSSL, DomainSSL SAN, Ukrainian site certification and company verification Center WebTrust - Ukraine
Ukrainian site certification and company verification Center, SSL, UA SSL Certificates CodeSigning Verify GlobalSign Certificates  Добро пожаловать в компанию Адграфикс Добро пожаловать в компанию Веб Траст Ураина Certificates Home Domains shop Магазин хостинга Certificates Current Site adgrafics - comfort in internet ! Contact us Page search Print version
+A | R | -A | |-| |<->|
* UAH. * RUR. US EU ( $1=8.6UAH )

Home
DomainSSL
OrganizationSSL
ExtendedSSL
WildCard SSL
SAN SSL сертификаты
SGC SSL сертификаты
AlphaSSL
AlphaSSL WildCard
Site Seal
Code Signing
PDF Signing
Personal PDF Signing
Department PDF Signing
FAQ PDF
Trial version

Vertical Industry Datasheets:

Example Certified PDFs:

MORE INFORMATION


All Products
Free Test SSL
Docs
About GlobalSign
Contact GlobalSign

Contact us
Order


DocumentSign Frequently Asked Questions

1. What are Certified Document Services (CDS)?
2. How does it work?
3.How do I get a DocumentSign Digital ID?
4.How is my organization vetted?
5.How are subscribers vetted?
6.Where can I review the Certificate Practice Statement for DocumentSign Digital IDs?
7.Where can I review the Certificate Policy Statement for DocumentSign Digital IDs?
8.Why must my private key associated with my DocumentSign Digital IDsbe stored on cryptographic hardware?
9.How do I know what type of DocumentSign Digital IDs is right for me?
10.How do I enroll for a DocumentSign Digital IDs?
11.What happens if I “lock” myself out of my GlobalSign furnished USB token?
12.Where can I get the GlobalSign for Adobe CA subordinate CA and what is the root hierarchy?
13.What information does the DocumentSign Digital IDs contain?
14. What Adobe applications work with CDS?
15. Where can I learn more about digitally signing Adobe PDF documents?
16. What technical requirements do I need to use a DocumentSign Digital IDs?
17.How can I learn more about server-based CDS implementations?
18.Where can I find the USB token drivers for XP / Vista systems?
19.Where can I find the USB token utilities for XP / Vista systems?
20.Where can I find the USB token drivers for Mac Systems?
21.What do I do if my DocumentSign Digital ID is lost or stolen?
22.How does a DocumentSign Digital ID differ from any other x.509v3 Certificate?
23.How does time-stamping work?
24.How long will my signature remain valid?
25. What are the differences between Certified and Approval Signatures?
26.What are some possible reasons on why my valid DocumentSignDigital ID produced a “question mark” at document opening?
27. Why aren't the ikey USB token drivers installing on my vista operating system?
28. Quick start help guide.
29. Are there any special security settings when enrolling withVisa and Internet Explorer 7/8?
30. I've upgraded my Acrobat and now Acrobat can't find my certificate on my token.

1. What are Certified Document Services (CDS)?
Certified DocumentServices (CDS) is a validation service for electronic documents specifically toattest to the authenticity and integrity of data through industry standard highlyubiquitous software (>800Million installations).  Created by the Adobe® Root Certificate authority,CDS enables document authors to sign Portable Document Format (PDF) files,using digital certificates, which then automatically validate when recipients usethe freely available Adobe® Acrobat® Reader software. No additional clientsoftware or configuration is required and the solution is multi-lingual throughthe wide variety of languages supported. http://www.adobe.com/products/reader/productinfo/languages/

CDS was designed to enable organizations and individuals who publish high-valuedocuments to large and disparate recipient groups to increase the assurancelevel that the document's integrity and authenticity are preserved. By adding Certifying Signatures and Approver Signature(s) to PDF filesdocument authors can increase this assurance level while at the same timereduce the burden of the recipient regarding how to determine if the documentcan be trusted.

Click here to learn more about CDS http://www.adobe.com/security/digsig/certifieddocs.html.

GlobalSign offers digital certificates compliant to the CDS program under the DocumentSign brand. DocumentSign Digital IDs are issued toindividuals and departments affiliated with verifiable organizations and allowauthors to add Certifying Signatures and Approver Signatures to PDFs.

2. How does it work?
DocumentSign DigitalIDs are “chained” to the inherently trusted Adobe root certificate found inAdobe Reader 6.0+ and Acrobat 6.0+.  Recipientswho open certified documents signed with CDS digital IDs receive one of threeeasy to understand trust messages.


Adobe Reader
Version

Certification VALID

Validity of author
NOT confirmed

Certification INVALID

 

Version 6 through 8

 

Version 9 onwards


3.How do I get a DocumentSign Digital ID?

Step 1:

Choose the certificate type that best suits your needs (Signing as a ‘naturalperson’ or as a ‘role’. i.e. PersonalSign or DepartmentSign)

Step 2:

Register for the service through the ‘buy now’ link.  GlobalSign then verifies the organization andforwards a LOA (Letter of Authorization) for the service.

Step 3:

Once the LOA is returned GlobalSign performs additional phone verificationchecks to ensure the subscriber is authorized to enroll for a digital ID by theOrganizational Representative who signs and agrees to the LOA. See CPS fordetails globalsign docs

Step 4:

Once validation checks are completed GlobalSign will provide the digitalID to the subscriber on a cryptographic device (typically an iKey USB token fromSafeNet).

4.How is my organization vetted?
After a Letter Of Authorization (LOA) is completed by an OrganizationalRepresentative authorized to bind the organization to the terms of theGlobalSign agreement and by reference the DocumentSign Digital ID for Adobe PDFCertificate Practice Statement, GlobalSign shall verify the Organization islegitimate using third party verification services such as Dun &Bradstreet.

Click here to obtain the LOA template

5.How are subscribers vetted?
An organization’s identity is verified by GlobalSign’s vetting team inaccordance with the steps described in the DocumentSignCertification Practice Statement. Enterprise subscribers are vetted andauthorized to enroll for a digital ID in their name or in the case of DepartmentSign,a role by authorized Registration Authorities that have been appointed by theOrganization Representative

6.Where can I review the Certificate Practice Statement for DocumentSign Digital IDs?
Click here for therepository where you will find the DocumentSignCertification Practice Statement.

7.Where can I review the Certificate Policy Statement for DocumentSign Digital IDs?
You can obtain theCertificate Policy by visiting: http://www.adobe.com/misc/pdfs/Adobe_CDS_CPv011604clean.pdf

8.Why does my private key associated with my DocumentSign Digital ID need to be stored on cryptographic hardware?
The Adobe CDSCertificate Policy highlights the need to ensure the security of the CDSprogram by ensuring all digital IDs are created on FIPS compliant CryptographicHardware. This maintains the 'singularity' of the Digital ID such that itcannot be duplicated, and therefore preserves non repudiation capabilities ofthe solution. The only exception to this are Test Certificates which have aseparate Test OID and therefore can be created outside of a hardware module.

9.How do I know what type of DocumentSign Digital ID is right for me?

PersonalSign Pro Digital ID for Adobe PDF – low Volume
A client based desktop solution designed for organizations with low volumerequirements (up to 500 annual signings) needing named individuals (e.g. JohnSmith) to add Certifying or Approval Signatures to PDFs. Authors digitally signusing the Adobe Acrobat software and a PersonalSign Pro Digital ID securelystored on a SafeNet FIPS 140-1 level 2 cryptographic USB token.

PersonalSign Pro Digital ID for Adobe PDF – normal Volume
A client based desktop solution designed for organizations with low volumerequirements (up to 1,500 annual signings) needing named individuals (e.g. JohnSmith) to add Certifying or Approval Signatures to PDFs. Authors digitally signusing the Adobe Acrobat software and a PersonalSign Pro Digital ID securelystored on a SafeNet FIPS 140-1 level 2 cryptographic USB token.

DepartmentSign Digital ID for Adobe PDF - lowvolume
A client based desktop solution designed for organizations with low volumerequirements (up to 2,000 annual signings) needing their departments e.g.Marketing Department or Legal Department to add Certifying or ApprovalSignatures to PDFs. Departments digitally sign using the Adobe Acrobat softwareand a PersonalSign Pro Digital ID securely stored on a SafeNet FIPS 140-1 level2 cryptographic USB token.

DepartmentSign Digital ID for Adobe PDF - mediumvolume
An automated solution to add Certifying and Approval Signatures to importantPDFs and designed for organizations with medium volume requirements (up to5,000 annual signings). A role-based DocumentSign Digital ID e.g. MarketingDepartment or Legal Department is issued and securely protected on a SafeNetFIPS 140-1 level 2 cryptographic device such as a Luna® PCI card.

Enterprise PKI for Adobe PDF
Includes two options for the Enterprise to manage the full life-cycle ofDocumentSign Digital IDs issued under their organization name. For example:

  • Distributed implementations of PersonalSign and DepartmentSign Digital IDs on USB tokensissued to individuals and departments

  • Centralized implementations(maintained on the organization's server) DocumentSign Digital IDs for eitherdepartments or individuals

Distributed implementationsinvolve providing organization administrators (acting as the organization'sRegistration Authority) a bulk quantity of PersonalSign Pro or DepartmentSignDigital IDs for low volume Certifying and Approval Signature requirements andthe associated Safenet USB tokens used to protect the Digital IDs.

Centralized, server-based implementations work with SafeNet hardware securitymodules (optionally sold) that are highly integrated with Adobe’s LiveCycle EnterpriseServer suite. The net result is a highly automated solution with robust signingfunctionality for high volume addition of Certifying and Approval Signature toPDFs. Low, Medium, and High volume signings are available. Contact yourGlobalSign sales representative for details.

10.How do I enroll for a DocumentSign Digital ID?
Low volumeDocumentSign Digital ID’s are provided on USB iKey 2032/4000 cryptographic tokenswhich are protected in transit to the customer via a customer provided passphrase.   Higher volume DepartmentSignDigital ID’s are may be provided on tokens too however it is more likely that aHSM (Hardware Security Module) will initially be delivered to the organizationand a CSR (Certificate Signing Request) would be submitted to GlobalSign havingbeen generated on the HSM by the Organization/Data Center.   The basic purchase process is highlightedbelow.  

An example LOA is illustrated here.


Adobe CDS Purchase Process

11.What happens if I “lock” myself out of my GlobalSign furnished USB token?
During the applicationprocess subscriber’s are required to personalize the USB token ‘passphrase’ witha 6 – 8 mix character secret value. This additional level of security isrequired by the DocumentSign CertificationPractice Statement. Subscribers are responsible forchanging the passphrase on receipt of the token.  DocumentSign Subscribers are also responsiblefor remembering the value and will be permanently locked out of their USB tokenafter (10) failed attempts. GlobalSign is unable to retrieve the passphrase andtherefore a new certificate will need to be purchased.

12. Where can I get the Adobe Root and GlobalSign for Adobe CA subordinate CA and what is the root hierarchy?
Visit adoberoot.cer for the Adobe Root Visit GlobalSignCDS.crt or GlobalSignCDS.der for the Adobe CA subordinate CA in CER and DER format.

The Adobe root hierarchy is a high security PKI implementation asfollows:

Adobe CDS Root Hierarchy

See FAQ for more details on how to install the Adobe Root CA using your Internet Explorer Browser.

13. What information does the DocumentSign Digital ID contain?
PersonalSign Pro DigitalIDs for Adobe PDF typically contain the following information:
Organization: ABC Company
OrganizationUnit: 123 Business Unit
CommonName: e.g. John Doe orMarketing Department
Email: e.g. john.doe@yahoo.com
CountryCode: e.g. US
State: e.g. Massachusetts
Locality:: e.g. Boston

14. What Adobe applications work with CDS?

Acrobat CDS AuthoringProducts:

Acrobat Professional v6.x through 9.x
Acrobat Standard v6.x through 9.x
Adobe LiveCycle Document Security Server v8.x and LiveCycle ES Digital Signatures
Acrobat CDS ValidationProducts:
Acrobat Professional v6.x through 9.x
Acrobat Standard v6.x through 9.x
Acrobat Elements v6.x through 9.x
Adobe Reader v6.x through 9.x
Adobe LiveCycle Document Security Server v.8.x and LiveCycle ES Digital Signatures


15. Where can I learn more about digitally signing Adobe PDF documents?
Go to the Adobeproduct help section and search under “digital signature” for detailedinformation.

16. What technical requirements do I need to use a DocumentSign Digital ID?

Software requirements for the SafeNet iKey 2032 USB token
Your computers must contain one of the following Microsoft operating systems:

Windows 2000Professional SP 4
Windows 2000 Server SP4
Windows Server 2003
Windows XPProfessional (SP 2)
Windows Vista
Mac OS X 10.5.4 (Contact GlobalSIgnsupport for special Mac only drivers)
Microsoft InternetExplorer V5.5 SP2 or higher
At this time supportfor the iKey supports both 32 bit and 64 bit versions  of the Vista operating system

Hardware requirements for the SafeNet iKey 2032 USB token

An available USB portfor your USB iKey token
Minimum of 128MB ofRAM

Software requirements for Adobe Acrobat Reader.
http://www.adobe.com/products/reader/productinfo/systemreqs/index.html
Software requirements for the Adobe Acrobat Family.
http://www.adobe.com/products/acrobatpro/productinfo/systemreqs/

17.How can I learn more about server-based CDS implementations?
Contact GlobalSign Adobe Sales on Tel US 603-570-7060 or Tel UK + 441622 766766 sales@globalsign.com to learn more about highly automated CDS solutions.

18.Where can I find the USB token drivers for XP / Vista systems?
Click below and selectSave As. Double click the application to begin installation of drivers.
DocumentSign for Adobe PDF 32 bit Drivers for 32 bit operatingsystems
DocumentSign for Adobe PDF 64 bit Drivers for 64 bit operatingsystems

Remember to reboot after driver installation and prior to initiatingyour first signature through Acrobat.

Please note that previous programs you have installed may also have usedInstallShield and therefore may require temporary files to be removed. You will be presented with the following error screen if this is the case.

Adobe PDF

To correct the problem, please delete the following directories.

C:\Program Files\Common Files\InstallShield\Professional\RunTime\10


and/or

C:\Program Files\Common Files\InstallShield\Professional\RunTime\11


19.Where can I find the USB token Utilities for XP / Vista systems?
Click below and selectSave As. Double click the application to begin installation of the utilities.
www.globalsign.com/support/adobe/documentsign.msi

Click here to view a demonstration on how USB Token Utilities and Drivers are installed


20. Where can I find the USB token drivers for Macsystems

Please download the MAC driver ISO image from thefollowing location:- www.globalsign.co.uk/support/cds/mac_102.iso  

STEP 1- Borderless Security Installation

Mac1

    1. Once the image has been downloaded, open the ISOimage.
    2. Open the bundles folder.
    3. Move the sfntPKCS.bundle to the desktop for usein step 3
    4. Doubleclick on the ‘Start Here.html’ and follow the SafeNet Borderless Security PKfor Macintosh 1.0.2 installation instructions

STEP 2- Insert your USB Token and ensure the green light is lit.

STEP 3– Configure Adobe Professional Part 1

    1. Click on the Document Menu and select SecuritySettings
    2. Expand the ‘Digital IDs’ menu item and Click on thePKCS#11 Modules option.
    3. Click on the ‘Attach Module’ and drag the sfntPKCS.bundle from the desktop into the location

MAC_2

STEP 4– Configure Adobe Professional Part 2

    1. Once installed, click on the ‘PKCS#11 Modules’ menuwhich now has the ‘SafeNet PKCS#11 Module’
    2. If the Token is not detected then click on ‘Refresh’
    3. Thenclick on ‘Login’ and enter the appropriate PassPhrase which was set up withGlobalSign during the purchase process.

MAC_3


STEP 5& 6 – This only needs to be done once prior to you first PDF signing –Install the Intermediate issuing CA.

MAC_4

    1. Click on the Document Menu and select Manage TrustedIdentities
    2. Click on the default ‘Display’ and select‘Certificates’ rather than ‘Contacts’.
    3. Click on the ‘Add Contact’ Button
    4. Browse to the desktop and select the GlobalSignCDS.crtfile.  Once identified click on the Import Button.

MAC_5

You are now ready to sign Adobe PDF documents. Additional helpful information is also located in the ISO file.


21.What do I do if my DocumentSign Digital ID islost or stolen?
DocumentSign Digital ID holders should immediately report their lost orstolen certificate to their company administrator that issued their CDScertificate.  A request for revocationform is located in the GlobalSignRepository.

22. How does a DocumentSign Digital ID differfrom any other x.509v3 certificate?
No need for pre-established or pre-understood trust decisions, no needfor software plug ins, no desktop or client side configuration, no swappingtrusted CAs. No special configuration for time-stamping and OCSP. It’s alreadyintegrated and ready to use out of the box.

23. How does time-stamping work?
DocumentSign DigitalIDs contain a special extension that supported Adobe products will use to gainaccess to a highly available and highly trusted RFC 3161 trusted clock. Thisassures relying parties of the exact date and time of the signature.

24. How long will my signature remain valid?
If digitally signed on-line, with a valid timestamp and revocation checkusing Acrobat default settings, your signature shall remain valid well afterthe certificate has expired or even if it was revoked after the fact. However,note both Adobe Acrobat and LiveCycle Server are highly configurable. Dependingon configuration settings on particular versions, signature validation may relyon different methods. Consult your Adobe product specific documentation formore details.


25. What are the differences between Certified andApproval signatures?
Most digitalsignatures are referred to as approval signatures. Signatures that certify aPDF are called certifying signatures. Only the first person to sign a PDF (mostoften, the author) can add a certifying signature. A certifying signatureattests to the contents of the document and allows the signer to specify thetypes of changes allowed for the document to remain certified. Changes to thedocument are detected in the Signatures panel.

Approval signatures are performed when someone signs a document to showconsent, approval, or acceptance. A certified document is one that has acertification signature applied by the originator when the document is readyfor use. The originator specifies what changes are allowed; choosing one ofthree levels of modification permitted:

no changes
form fill-in only
form fill-in and commenting

Valid approval signaturesproduce a “green check mark” and certified signatures produce a “blue ribbon”.Both types of digital signatures provide embedded OCSP and RFC 3161 compliantservices resulting in valid signatures well past the life of the DocumentSignDigital ID that signed them.

See example of a Certified PDF containing Approval Signatures


26. What are some possible reasons on why myvalid DocumentSign Digital ID produced a “question mark” at document opening?
Potential issues couldbe as follows:

Port 80 is blocked, therefore supported Adobe products cannot reach the OCSP and/ or Time-stamping servers needed for validation
The document of digital signature was performed “off-line”
Author or recipients are not signing or validating with Adobe Reader or Acrobat 6.0+

27. Why isn’t the ikey USB token driversinstalling on my Vista operating system?
One reason may be yourUser Account Control (UAC) setting. You may need to disable the UAC by going tothe Windows Vista Control Panel and select User Accounts:

User Account Control

Click on the option for Turn User Account Control On or Off:

User Account Control

Uncheck the Use User Account Control (UAC) to help protect your computer:

User Account Control

This must be doneprior to installing the drivers and re-enable after successful driverinstallation. You may reinstate User Account Control after installation forsecurity for your system.

28.Quick start help guide:

QuickStartGuide.pdf

29.I'm having difficulty enrolling with Vista and Internet Explorer 7/8. Are there any special security settings I should be aware of?

Yes, because of the unique nature of the Adobe Root that is not inherently trusted in Windows, and the Active X controls required to install the digital ID on the required Cryptographic Service Provider, there are several security settings that require modification. Subsequent to successful certificate enrollment, GlobalSign strongly recommends that default settings be re-established.

30. I've upgraded my Acrobat and now Acrobat can't find my certificate on my token.

Although, Acrobat should be able to “discover” yourdigital ID on your USB token (after initial set-up that includes installationthe USB drivers and token utilities and installing the certificate using theMicrosoft IE browser), upgrades may disturb certain settings that required youto modify Acrobat security settings.  Inthe remote case, you experience this problem, try adding the PKCS11 SafeNet DLLmanually by following the following steps using Adobe Acrobat:

1. Click on"Advanced" located on the top menu bar

2. Select "Security Settings"

3. Select "Digital IDs"

4. PKCS#11 modules then browse for the dkck201.dll foundin your Systems32 folder.

Copyright © 1997-2010 adgrafics ®


\"".TITLE." SSL сертификаты VeriSign GeoTrust Thawte Comodo GlobalSign TrustWave покупка SSL...
издатель: Ukrainian site certification and company verification Center WebTrust - Ukraine тематика: GlobalSign Certificates, GlobalSign сертификаты, GlobalSign сертифифікати, globalsigncertificates.com GlobalSign Certificates globalsigncertificates.com. Code Signing, OrganizationSSL Wildcard SAN, PersonalSign USB low, OrganizationSSL, DomainSSL SAN,
Wildcard SSL certificates | Networksolutions EV certificates with green bar | ECC technology