填写表格 Web 应用程序上的电子签名是否有标准实施?
我有一位客户有兴趣在一份很长(40 个问题)的卖家申请表中添加电子签名支持。 我有点困惑是否存在金融界人士期望看到的现有标准或流程?
我当然可以添加一个系统,在该系统中我们根据他们的回复生成一堆文本,让申请人用他们的私钥签名并上传公钥 - 但这似乎对人们提出了很多要求。 现在非书呆子都安装了 PGP 吗?
有没有标准的方法? 有没有在金融界工作过的人做过这件事并且效果很好?
I have a client who is interested in adding in electronic signature support to a long (40 question) seller application form. I'm a little stumped on whether there is an existing standard or process that's out there that folks in the financial world would expect to see?
I could certainly add in a system where we generate a bunch of text based on their responses, have the applicant sign it with their private key and upload a public key- but that seems like a lot to ask of people. Do non-nerds even have PGP installed these days?
Is there a standard approach to this out there? Anyone work in the financial world that's done this and had it work well?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(3)
如果这些表格要与公众共享,您需要知道(并且可以验证,这是最难的部分)所有这些人们可以用来签署这些表格的证书的制作者,这几乎是不可能的。
在封闭的环境中(如工作人员、医生......),所有用户都应该持有证书(具有您信任的预先已知的 CA),并且您应该确保表格是由可信的人发送的(不可否认、完整性。 ..)这是签署表格的更好方案,否则我不建议您使用签署的表格来实现您的目标。
If these forms are meant to be shared throught to a general public you'll need to know (and can validate, that's the hardest part) all the producers of these amount of certificates people could use to sign these forms, and it's almost impossible.
With closed environments (like functionaries, doctors...) where all the users are suposed to hold a certificate (with a pre-known CA you trust) and you should be sure the form is sended by someone trusted (non repudation, integrity...) it's a better scenario to sign a form, otherwise I do not recomend you to use signed forms to achieve your goal.
我们使用 Alphatrust 的 电子签名软件。
We use Alphatrust's e-Sign Software.
签名试图达到什么目的? 您是否想验证该表格是否确实来自特定卖家? (如果是这样,您必须提前知道他们的公钥。)您是否试图让卖家在以后对他们的答案负责? (在这种情况下,您可能需要某种第三方的参与。)
有时人们要求电子签名只是因为它们听起来很简洁。
What purpose is the signature trying to fill? Are you trying to verify that the form actually came from a specific seller? (If so, you would have to know their public key ahead of time.) Are you trying to hold the seller accountable for their answers at a later date? (In that case, you might need some kind of third-party involved.)
Sometimes people ask for electronic signatures just because they sound neat.