v0.3.0 — correct names, and signing the contract itself
Pre-releaseStill pre-release. No security review, no Czech eIDAS counsel review. The timestamps are real and independently verifiable; treat the app itself as unfinished.
Live at https://elkojo.github.io/xNotary/
Fixed: certificates misspelled people's names
The standard PDF fonts are WinAnsi-encoded, and Czech straddles that boundary — á é í pass, ř ě č ů ť do not. Certificates printed Rehor Cízek for Řehoř Čížek and Účetní záverka for závěrka. Half a name rendering and half not looks arbitrary to whoever receives it, and a misspelled name undercuts the attribution the certificate exists to make.
The certificates now embed subsets of Liberation covering Latin, Greek and Cyrillic — metric-compatible with Helvetica, so the layout that is measured to fit one A4 page did not move. 408 KB, in a chunk fetched only when a certificate is built.
Certificate 1 also prints the real file name in its verification commands again, instead of degrading to <your document>.
New: attest signatures on the document, not on a certificate about it
Have everyone sign the contract itself, then give Attest signatures both the signed files and the .ots (or the Certificate 1 carrying it). xNotary finds which revision of the signed file the proof timestamps — a search against the digest the proof already commits to, so a match is evidence rather than an assumption — and Certificate 2 then states the signatures are over the document itself, with the proof attached alongside.
If no revision matches, the certificate says nothing about a timestamp and still attaches the proof, so a reader can see exactly what was offered.
Narrower claims throughout
- Certificate 2 ships; How it works still called it a coming milestone. That page now describes the real workflow, including that signing happens outside xNotary.
- Bank iD SIGN produces an advanced signature, not a QES. It is out of the qualified-provider list and has its own section explaining the difference.
- The consent list now shows each signature's qualified claim, not only its issuer. "Certified by PostSignum" alone was the impressive half without the qualifying half.
- eIDAS is the worked example, not the frame. No user-facing statement is now true only inside the EU.
- The Commission's DSS instance titles itself "DSS Demonstration WebApp". Calling it the official validator claimed an assurance nobody gave, and it pointed users at uploading their document to a third party. The certificate names DSS run locally, or a qualified validation service, instead.
- Nothing suggests xNotary substitutes for an officially verified signature — in Czechia, § 6(2) of Act 12/2020 Sb. requires verifying from population-register data that the certificate belongs to the signer, which no static page can do.
- Times on a certificate are UTC and say so; times on screen name their zone.
Under the hood
125 → 140 tests. Two dependencies added: @pdf-lib/fontkit (runtime) and subset-font (dev only).