Infopath 文档的签名证书已过期或被撤销
假设我有一个 Infopath 表单,今天由有效且活跃的用户进行了数字签名。
当该用户离开公司时,我们会禁用该帐户并吊销证书。这会导致问题,因为正确签名的旧文档被报告为无效。
我们如何维护 PKI 基础设施的完整性,并确保先前签署的有效文档在 Infopath 中仍然有效?
Suppose I have an Infopath form that is digitally signed today by a valid, and active user.
When that user leaves the company, we disable the account and revoke the certificate. This causes a problem since the old documents that were correctly signed are reported as being invalid.
How do we maintain the integrity of a PKI infrastructure and also ensure that the valid, prior signed documents still appear as valid within Infopath?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
你的验证码是哪里来的。在“正常”实现中,根据撤销日期检查签名日期以确定签名创建时的完整性。
您查看了撤销列表吗?列出的有效期终止日期是哪一天?
Where's your validation code from. In "normal" implementations, the signature date is checked against the revocation date to determine the signature integrity at the time it was created.
Did you have a look at the revocation list, what date is listed for termination of validity?
实际的消息应该是证书不再有效。文档签名时有效,用户仍可以查看有效的签名数据。措辞有点令人困惑,但该消息仅适用于当前的证书。它并不意味着该文档被篡改(这是不同的消息;)。
不幸的是,这也是培训/教育的问题。无法更改从办公产品发出的这些消息。您只需向用户解释该消息的真正含义,并在他们“忘记”、惊慌并每次给您打电话时保持耐心。
The actual message should be that the CERTIFICATE is no longer valid. It was valid when the doc was signed and the users can still view the valid signed data. The wording is a bit confusing but the message only applies to the certificate as it is currently. It does not imply that the document was tampered with (thats a different message ;).
Unfortunately it is a matter of training/education too. There is no way to alter those messages coming out of the office products. You just have to explain what the message really means to the users - and be patient when they "forget", panic, and call you each and every time.