Wizard Legal
DocumentationProduct guides and practical next steps
DocumentationSigning & execution

Signing & execution

Review a provider-signed PDF and certificate evidence

Use a repeatable review sequence for a provider-returned signed PDF, certificate chain, timestamp and envelope evidence—without treating a visual signature or product record as automatic verification.

5 min readUpdated 6 August 2026

A provider-returned PDF, an activity timeline, and a signature image answer different questions. The provider-returned PDF needs its own signature and certificate review; the envelope shows what the product recorded; document formalities and authority remain separate. Use the applicable provider contract, organisation policy, and professional advice for the transaction instead of relying on a generic visual indicator.

Example only · independent review required

Provider-signed PDF review sheet

Example completed provider-signed PDF · Provider artifact review

Identify the final artifact

Retain the original provider-returned PDF and its provider reference. Do not substitute a re-exported, altered, or merely screenshot-based version for the artifact under review.

Release gate

Verify the signed PDF independently

The enabled provider path first uses local pdfsig with the organisation's mounted NSS trust store to check CMS integrity and a trusted certificate chain. Preserve that verifier result and use the approved review process for the exact file you retained.

Release gate

Apply certificate and time policy

Check certificate chain, signing time, revocation information, trusted timestamp policy, and any provider-specific assurance requirement that applies to the use case.

Release gate

Reconcile the surrounding evidence

Match provider transaction data, callback result, recipient route, final document version, audit events, authority evidence, and execution formalities before closing the review.

Release gate
No implied pass result: this is a review artifact, not a signed PDF, provider receipt, certificate chain, revocation result, timestamp result, or assertion that a provider method is enabled.
Keep the returned final PDF, provider transaction reference, verification output, and relevant envelope evidence together. Investigate a failed, missing, expired, or mismatched check before representing a provider-signed artifact as verified.

Start with the original returned artifact

  1. 1Record the provider transaction or request reference with the envelope ID and the final document version. If the provider callback only reports an attempt outcome, recover the actual final artifact through the approved provider path before treating a request as complete.
  2. 2Store the exact returned PDF without editing or regenerating it. A later PDF export, print-to-PDF copy, or screenshot may not contain the same signed bytes or signature container.
  3. 3Keep the provider result and the application record together. The application timeline can help reconstruct the process, but it is not a replacement for the provider's signed artifact or verification result.

Validate the PDF signature separately from the product record

  • Confirm that a PDF signature container and ByteRange structure are present only as an initial structural check; that alone does not establish a trusted signature.
  • When the provider path is enabled, Wizard Legal runs local pdfsig with its configured NSS trust store before it persists the returned PDF. That checks the CMS signature and locally trusted certificate chain, and rejects an unavailable verifier, invalid signature, or untrusted chain.
  • Review signing time, certificate validity, revocation information, and trusted timestamp status against the applicable policy and provider documentation. The automated local check deliberately disables online OCSP and AIA fetching, so it does not itself establish revocation or RFC 3161 timestamp validity.
  • Investigate an absent signature, invalid chain, untrusted timestamp, mismatched document, unavailable revocation result, or provider-reference mismatch before describing the artifact as verified.

Close the complete transaction record

A certificate panel does not decide authority to sign, whether the parties received the intended document, whether witnesses or stamp/registration rules apply, or the legal effect of the transaction. Retain the final PDF, verification output, provider reference, signing timeline, approval/authority records, notices, and any required execution material together. Escalate situations needing a legal conclusion or a provider investigation rather than inferring a result from the interface.