Signing & execution
Review a provider-signed PDF and certificate evidence
Use a repeatable review sequence for a provider-returned signed PDF, certificate chain, timestamp and envelope evidence—without treating a visual signature or product record as automatic verification.
A provider-returned PDF, an activity timeline, and a signature image answer different questions. The provider-returned PDF needs its own signature and certificate review; the envelope shows what the product recorded; document formalities and authority remain separate. Use the applicable provider contract, organisation policy, and professional advice for the transaction instead of relying on a generic visual indicator.
Example only · independent review required
Provider-signed PDF review sheet
Example completed provider-signed PDF · Provider artifact review
Identify the final artifact
Retain the original provider-returned PDF and its provider reference. Do not substitute a re-exported, altered, or merely screenshot-based version for the artifact under review.
Verify the signed PDF independently
The enabled provider path first uses local pdfsig with the organisation's mounted NSS trust store to check CMS integrity and a trusted certificate chain. Preserve that verifier result and use the approved review process for the exact file you retained.
Apply certificate and time policy
Check certificate chain, signing time, revocation information, trusted timestamp policy, and any provider-specific assurance requirement that applies to the use case.
Reconcile the surrounding evidence
Match provider transaction data, callback result, recipient route, final document version, audit events, authority evidence, and execution formalities before closing the review.
Start with the original returned artifact
- 1Record the provider transaction or request reference with the envelope ID and the final document version. If the provider callback only reports an attempt outcome, recover the actual final artifact through the approved provider path before treating a request as complete.
- 2Store the exact returned PDF without editing or regenerating it. A later PDF export, print-to-PDF copy, or screenshot may not contain the same signed bytes or signature container.
- 3Keep the provider result and the application record together. The application timeline can help reconstruct the process, but it is not a replacement for the provider's signed artifact or verification result.
Validate the PDF signature separately from the product record
- Confirm that a PDF signature container and ByteRange structure are present only as an initial structural check; that alone does not establish a trusted signature.
- When the provider path is enabled, Wizard Legal runs local pdfsig with its configured NSS trust store before it persists the returned PDF. That checks the CMS signature and locally trusted certificate chain, and rejects an unavailable verifier, invalid signature, or untrusted chain.
- Review signing time, certificate validity, revocation information, and trusted timestamp status against the applicable policy and provider documentation. The automated local check deliberately disables online OCSP and AIA fetching, so it does not itself establish revocation or RFC 3161 timestamp validity.
- Investigate an absent signature, invalid chain, untrusted timestamp, mismatched document, unavailable revocation result, or provider-reference mismatch before describing the artifact as verified.
Close the complete transaction record
A certificate panel does not decide authority to sign, whether the parties received the intended document, whether witnesses or stamp/registration rules apply, or the legal effect of the transaction. Retain the final PDF, verification output, provider reference, signing timeline, approval/authority records, notices, and any required execution material together. Escalate situations needing a legal conclusion or a provider investigation rather than inferring a result from the interface.