Skip to content

Releases: intoolswetrust/jsignpdf

JSignPdf_3_2_1

Choose a tag to compare

@github-actions github-actions released this 28 Sep 16:53

Version 3.2.1

A bug-fix release for the JavaFX GUI, with two fixes contributed by the community. Thanks to Ladislav Nemec and Milos Jakubicek.

  • Output suffix no longer piles up when switching presets — loading a preset with a different output suffix used to append it to the previous one (document_EM.pdf became document_EM_DL.pdf instead of document_DL.pdf). A derived output name is now recomputed with the new suffix, a name you typed yourself is kept, and a new session no longer starts with the output file name left over from the last run. See pull request 505.
  • Proxy port is saved even without pressing Enter — a port typed into the TSA / Validation settings was only committed on Enter, so the DSS engine could quietly connect to the proxy on port 80. The field now commits on focus loss too, and out-of-range values are rejected. See pull request 512.
  • Unconfirmed field edits are no longer lost — signing or timestamping via a keyboard shortcut, closing the window, and saving or loading a preset now pick up the proxy port and font size fields as shown on screen. File > Exit (Ctrl+Q) now saves the signing options, as closing the window already did.
  • Linux Flatpak bundle on the GitHub release — it is now built from the same manifest as the Flathub one, so smartcard and YubiKey signing work there too.
  • Dependency updates — BouncyCastle 1.86 and other routine library bumps.

JSignPdf_3_2_0

Choose a tag to compare

@github-actions github-actions released this 14 Sep 13:54

Version 3.2.0

A feature release. You can now sign into a form's existing signature fields, add or refresh a document timestamp without signing at all, and see a live preview of the visible signature as you place it — plus more control over output, better diagnostics, and a batch of signing and appearance fixes.

  • Sign into an existing signature field — documents that pre-place a signature box per signer can now be signed into it instead of getting a new field on top. Pick it from the Signature field combo in the JavaFX Signature Appearance panel, or with --sig-field (--list-sig-fields prints what a document offers); the field's own rectangle and page are used. Both engines support it. See issue 223.
  • Append a document timestamp without signing — jsignpdf -eng dss --timestamp-only -ts <URL> doc.pdf adds an ETSI.RFC3161 document timestamp to any PDF with no key, to give it a trusted point in time or to refresh a PAdES B-LTA archive timestamp before its TSA certificate expires. In the UI it's the Timestamp toolbar button and Signing > Add Timestamp… (Ctrl+T). Needs the DSS engine. See issue 141.
  • Live preview of the visible signature — the signature text and background image are rendered inside the rectangle on the page preview while you place, move and resize it, pages are rasterized at print resolution (300 DPI), and empty signature fields are shaded so you can see where a form author placed them. See issue 479.
  • Choose where the signed file goes — the GUI gains an Output directory field and a suffix on/off switch, with a warning when the resulting name would overwrite the input; under Flatpak the chosen directory is granted through the desktop portal. See issue 483.
  • PSS-only certificates sign correctly on hardware tokens (DSS engine) — a certificate marked id-RSASSA-PSS, as eIDAS qualified certificates increasingly are, previously failed to sign on PKCS#11 tokens with a SignatureAlgorithm ... does not match error; the DSS engine now takes the algorithm from the certificate and produces real PSS. See issue 255.
  • New debug output for signing diagnostics — enable it on the new General tab of Preferences or with -o debug=true to log the signing certificate chain and, for the DSS engine, every AIA/CRL/OCSP request and the trust anchors it loaded. Off by default. See issue 452.
  • Other improvements — pick the interface language with the new Language selector (ui.language, issue 444); sign very large PDFs without a bigger heap via buffering.mode=temp (issue 178); the DSS engine now layers a background image behind the signature graphic and auto-scales text to fit the box (issue 433); DSS timestamp requests carry a nonce (issue 33); visible-signature images keep their aspect ratio on the DSS engine (issue 460) and description text fills the whole box on OpenPDF (issue 479); append mode no longer refuses to sign when it can't bump the declared PDF version (issue 467); clear the Recent files list on its own (issue 453); and the bundled Norwegian Bokmål translation now actually loads.

JSignPdf_3_2_0-RC-2

JSignPdf_3_2_0-RC-2 Pre-release
Pre-release

Choose a tag to compare

Version 3.2.0

A feature release. You can now sign into a form's existing signature fields, add or refresh a document timestamp without signing at all, and see a live preview of the visible signature as you place it — plus more control over output, better diagnostics, and a batch of signing and appearance fixes.

  • Sign into an existing signature field — documents that pre-place a signature box per signer can now be signed into it instead of getting a new field on top. Pick it from the Signature field combo in the JavaFX Signature Appearance panel, or with --sig-field (--list-sig-fields prints what a document offers); the field's own rectangle and page are used. Both engines support it. See issue 223.
  • Append a document timestamp without signing — jsignpdf -eng dss --timestamp-only -ts <URL> doc.pdf adds an ETSI.RFC3161 document timestamp to any PDF with no key, to give it a trusted point in time or to refresh a PAdES B-LTA archive timestamp before its TSA certificate expires. In the UI it's the Timestamp toolbar button and Signing > Add Timestamp… (Ctrl+T). Needs the DSS engine. See issue 141.
  • Live preview of the visible signature — the signature text and background image are rendered inside the rectangle on the page preview while you place, move and resize it, pages are rasterized at print resolution (300 DPI), and empty signature fields are shaded so you can see where a form author placed them. See issue 479.
  • Choose where the signed file goes — the GUI gains an Output directory field and a suffix on/off switch, with a warning when the resulting name would overwrite the input; under Flatpak the chosen directory is granted through the desktop portal. See issue 483.
  • PSS-only certificates sign correctly on hardware tokens (DSS engine) — a certificate marked id-RSASSA-PSS, as eIDAS qualified certificates increasingly are, previously failed to sign on PKCS#11 tokens with a SignatureAlgorithm ... does not match error; the DSS engine now takes the algorithm from the certificate and produces real PSS. See issue 255.
  • New debug output for signing diagnostics — enable it on the new General tab of Preferences or with -o debug=true to log the signing certificate chain and, for the DSS engine, every AIA/CRL/OCSP request and the trust anchors it loaded. Off by default. See issue 452.
  • Other improvements — pick the interface language with the new Language selector (ui.language, issue 444); sign very large PDFs without a bigger heap via buffering.mode=temp (issue 178); the DSS engine now layers a background image behind the signature graphic and auto-scales text to fit the box (issue 433); DSS timestamp requests carry a nonce (issue 33); visible-signature images keep their aspect ratio on the DSS engine (issue 460) and description text fills the whole box on OpenPDF (issue 479); append mode no longer refuses to sign when it can't bump the declared PDF version (issue 467); clear the Recent files list on its own (issue 453); and the bundled Norwegian Bokmål translation now actually loads.

JSignPdf_3_2_0-RC-1

JSignPdf_3_2_0-RC-1 Pre-release
Pre-release

Choose a tag to compare

Version 3.2.0

A feature release. You can now sign into a form's existing signature fields, add or refresh a document timestamp without signing at all, and see a live preview of the visible signature as you place it — plus more control over output, better diagnostics, and a batch of signing and appearance fixes.

  • Sign into an existing signature field — documents that pre-place a signature box per signer can now be signed into it instead of getting a new field on top. Pick it from the Signature field combo in the JavaFX Signature Appearance panel, or with --sig-field (--list-sig-fields prints what a document offers); the field's own rectangle and page are used. Both engines support it. See issue 223.
  • Append a document timestamp without signing — jsignpdf -eng dss --timestamp-only -ts <URL> doc.pdf adds an ETSI.RFC3161 document timestamp to any PDF with no key, to give it a trusted point in time or to refresh a PAdES B-LTA archive timestamp before its TSA certificate expires. In the UI it's the Timestamp toolbar button and Signing > Add Timestamp… (Ctrl+T). Needs the DSS engine. See issue 141.
  • Live preview of the visible signature — the signature text and background image are rendered inside the rectangle on the page preview while you place, move and resize it, pages are rasterized at print resolution (300 DPI), and empty signature fields are shaded so you can see where a form author placed them. See issue 479.
  • Choose where the signed file goes — the GUI gains an Output directory field and a suffix on/off switch, with a warning when the resulting name would overwrite the input; under Flatpak the chosen directory is granted through the desktop portal. See issue 483.
  • PSS-only certificates sign correctly on hardware tokens (DSS engine) — a certificate marked id-RSASSA-PSS, as eIDAS qualified certificates increasingly are, previously failed to sign on PKCS#11 tokens with a SignatureAlgorithm ... does not match error; the DSS engine now takes the algorithm from the certificate and produces real PSS. See issue 255.
  • New debug output for signing diagnostics — enable it on the new General tab of Preferences or with -o debug=true to log the signing certificate chain and, for the DSS engine, every AIA/CRL/OCSP request and the trust anchors it loaded. Off by default. See issue 452.
  • Other improvements — pick the interface language with the new Language selector (ui.language, issue 444); sign very large PDFs without a bigger heap via buffering.mode=temp (issue 178); the DSS engine now layers a background image behind the signature graphic and auto-scales text to fit the box (issue 433); DSS timestamp requests carry a nonce (issue 33); visible-signature images keep their aspect ratio on the DSS engine (issue 460) and description text fills the whole box on OpenPDF (issue 479); append mode no longer refuses to sign when it can't bump the declared PDF version (issue 467); clear the Recent files list on its own (issue 453); and the bundled Norwegian Bokmål translation now actually loads.

JSignPdf_3_2_0-BETA-1

JSignPdf_3_2_0-BETA-1 Pre-release
Pre-release

Choose a tag to compare

Version 3.2.0

A release about getting out of your way. The improvements below smooth over the rough edges you hit while signing: less guessing when something goes wrong, and fewer surprises when it goes right.

  • Sign into an existing signature field — documents that pre-place a signature box for each signer can now be signed into those boxes instead of getting a new field on top. Pick the field from the new Signature field combo in the JavaFX Signature Appearance panel, or on the command line with --sig-field (a field name, #N for the N-th field in document order, or auto for the first empty one); --list-sig-fields prints what a document offers. The field's own rectangle and page are used, so the position options are ignored and the appearance is drawn even without -V. A name that matches no empty field is an error rather than a silently created stray field, and --overwrite / PDF encryption are refused because a non-incremental rewrite would drop your co-signers' signatures. Both bundled engines support it. See issue 223.
  • New debug output for signing diagnostics — enable it on the new General tab of Preferences, or with debug=true in advanced.properties (or -o debug=true for a single CLI run), to log the signing certificate chain (subject, issuer, serial, validity, key usage, QC statements, and the AIA and CRL distribution-point URLs of each certificate) plus, for the DSS engine, the trust anchors it loaded and every AIA, CRL, and OCSP request with the target URL, the certificate it is for, the response size, the outcome, and the elapsed time. It is off by default so normal runs stay quiet; -q silences everything regardless. See issue 452.
  • Preferences dialog gains a General tab gathering the signing-engine selection and the new debug toggle; both apply immediately.
  • Visible signature images keep their aspect ratio with the DSS engine — background and graphic images were previously stretched to fill the signature box and came out distorted. A --bg-scale of zero still stretches to fill; any other value fits the image and centers it, matching the OpenPDF engine. See issue 460.
  • Clear list in the Recent files menu — the File menu's recent-files trail can now be emptied on its own, which previously required a factory reset that discarded every other setting as well. The item appears only when there is something to clear. See issue 453.
  • Pick the interface language — a new Language selector on the General tab of Preferences lets you choose the UI language explicitly instead of always following the operating-system locale; System default stays the default. It is stored as ui.language in advanced.properties and works on the command line too (-o ui.language=de, e.g. to read --help in German). The setting is read at startup, so restart to apply it, and it affects interface text only — number/date formatting and the signed output are unchanged. See issue 444.
  • Sign very large PDFs without a bigger heap — set buffering.mode=temp in advanced.properties (or -o buffering.mode=temp for a single run) to stage the document in temporary files instead of on the Java heap, so its size no longer has to fit in -Xmx. A 400 MB document that fails with an out-of-memory error under a 512 MB heap signs fine on both engines with this on. Optionally point buffering.tempDir at a fast disk; with the DSS engine, add -Djava.io.tmpdir too if your system temporary directory is small or RAM-backed. The signed output is identical either way; the cost is disk space and a little speed. See issue 178.
  • Norwegian translation is now loaded — the bundled Norwegian Bokmål translation shipped under a file name (messages_nb-NO.properties) that Java's resource loader never matched, so it silently rendered English. Renaming it to messages_nb.properties makes it apply for both nb and nb-NO locales.

JSignPdf_3_1_0

Choose a tag to compare

@github-actions github-actions released this 13 Jul 10:21

Version 3.1.0

Packaging-focused release: the fat jar is gone and every supported platform ships a native installer with its own bundled Java runtime. Also introduces a pluggable signing-engine architecture with a new EU DSS (PAdES) engine.

  • Per-platform native installers built with jpackage and a bundled Zulu+FX 21 runtime, so no system Java is required: Windows MSI, Linux DEB and RPM, and macOS DMG, each alongside a portable ZIP. Flatpak bundles are published for Linux x64 and aarch64.
  • Two cross-platform ZIPs for users who already have Java 21: a full ZIP carrying JavaFX natives for all platforms (with a Swing fallback when none match) and a minimal ZIP without JavaFX for headless/CLI signing and downstream packagers.
  • Fat jar dropped — the shaded all-in-one jar is no longer produced; the cross-platform ZIPs use bin/jsignpdf.sh and bin\jsignpdf.cmd launchers instead. The library jar published to Maven Central is unchanged.
  • Pluggable signing engines selectable with the new --list-engines and -eng / --engine options or the Engine selector in Preferences. JSignPdf ships OpenPDF as the default engine.
  • New EU DSS (PAdES) engine (id dss) producing PAdES signatures at the ETSI baseline levels B, T, LT, and LTA, which the OpenPDF engine cannot create.
  • Default hash algorithm is now SHA-256 (was SHA-1) for signing that relies on the implicit default. An explicit or saved hash.algorithm is untouched, and SHA-1 stays selectable for the OpenPDF engine.
  • CLI signatures now append by default, matching the GUI. Use the new --overwrite flag to replace existing signatures; the legacy --append / -a flag is kept as a no-op.
  • Signed Windows installers — the Windows MSI installers are Authenticode-signed via SignPath, so they install without an unknown-publisher warning. Pre-release builds ship unsigned.
  • Configurable default output suffix — the _signed marker appended to the output file name can now be changed with the new output.suffix key in advanced.properties, so non-English users can localize it (e.g. _firmado). It feeds both GUIs and the default for the CLI -os / --out-suffix option.
  • Checksums for every artifact — a jsignpdf-<version>-SHA256SUMS.txt file now covers all published release assets.

JSignPdf_3_1_0-RC-5

JSignPdf_3_1_0-RC-5 Pre-release
Pre-release

Choose a tag to compare

Version 3.1.0

Packaging-focused release: the fat jar is gone and every supported platform ships a native installer with its own bundled Java runtime. Also introduces a pluggable signing-engine architecture with a new EU DSS (PAdES) engine.

  • Per-platform native installers built with jpackage and a bundled Zulu+FX 21 runtime, so no system Java is required: Windows MSI, Linux DEB and RPM, and macOS DMG, each alongside a portable ZIP. Flatpak bundles are published for Linux x64 and aarch64.
  • Two cross-platform ZIPs for users who already have Java 21: a full ZIP carrying JavaFX natives for all platforms (with a Swing fallback when none match) and a minimal ZIP without JavaFX for headless/CLI signing and downstream packagers.
  • Fat jar dropped — the shaded all-in-one jar is no longer produced; the cross-platform ZIPs use bin/jsignpdf.sh and bin\jsignpdf.cmd launchers instead. The library jar published to Maven Central is unchanged.
  • Pluggable signing engines selectable with the new --list-engines and -eng / --engine options or the Engine selector in Preferences. JSignPdf ships OpenPDF as the default engine.
  • New EU DSS (PAdES) engine (id dss) producing PAdES signatures at the ETSI baseline levels B, T, LT, and LTA, which the OpenPDF engine cannot create.
  • Default hash algorithm is now SHA-256 (was SHA-1) for signing that relies on the implicit default. An explicit or saved hash.algorithm is untouched, and SHA-1 stays selectable for the OpenPDF engine.
  • CLI signatures now append by default, matching the GUI. Use the new --overwrite flag to replace existing signatures; the legacy --append / -a flag is kept as a no-op.
  • Signed Windows installers — the Windows MSI installers are Authenticode-signed via SignPath, so they install without an unknown-publisher warning. Pre-release builds ship unsigned.
  • Configurable default output suffix — the _signed marker appended to the output file name can now be changed with the new output.suffix key in advanced.properties, so non-English users can localize it (e.g. _firmado). It feeds both GUIs and the default for the CLI -os / --out-suffix option.
  • Checksums for every artifact — a jsignpdf-<version>-SHA256SUMS.txt file now covers all published release assets.

JSignPdf_3_1_0-RC-4

JSignPdf_3_1_0-RC-4 Pre-release
Pre-release

Choose a tag to compare

Version 3.1.0

Packaging-focused release: the fat jar is gone and every supported platform ships a native installer with its own bundled Java runtime. Also introduces a pluggable signing-engine architecture with a new EU DSS (PAdES) engine.

  • Per-platform native installers built with jpackage and a bundled Zulu+FX 21 runtime, so no system Java is required: Windows MSI, Linux DEB and RPM, and macOS DMG, each alongside a portable ZIP. Flatpak bundles are published for Linux x64 and aarch64.
  • Two cross-platform ZIPs for users who already have Java 21: a full ZIP carrying JavaFX natives for all platforms (with a Swing fallback when none match) and a minimal ZIP without JavaFX for headless/CLI signing and downstream packagers.
  • Fat jar dropped — the shaded all-in-one jar is no longer produced; the cross-platform ZIPs use bin/jsignpdf.sh and bin\jsignpdf.cmd launchers instead. The library jar published to Maven Central is unchanged.
  • Pluggable signing engines selectable with the new --list-engines and -eng / --engine options or the Engine selector in Preferences. JSignPdf ships OpenPDF as the default engine.
  • New EU DSS (PAdES) engine (id dss) producing PAdES signatures at the ETSI baseline levels B, T, LT, and LTA, which the OpenPDF engine cannot create.
  • Default hash algorithm is now SHA-256 (was SHA-1) for signing that relies on the implicit default. An explicit or saved hash.algorithm is untouched, and SHA-1 stays selectable for the OpenPDF engine.
  • CLI signatures now append by default, matching the GUI. Use the new --overwrite flag to replace existing signatures; the legacy --append / -a flag is kept as a no-op.
  • Signed Windows installers — the Windows MSI installers are Authenticode-signed via SignPath, so they install without an unknown-publisher warning. Pre-release builds ship unsigned.
  • Configurable default output suffix — the _signed marker appended to the output file name can now be changed with the new output.suffix key in advanced.properties, so non-English users can localize it (e.g. _firmado). It feeds both GUIs and the default for the CLI -os / --out-suffix option.
  • Checksums for every artifact — a jsignpdf-<version>-SHA256SUMS.txt file now covers all published release assets.

JSignPdf_3_1_0-RC-3

JSignPdf_3_1_0-RC-3 Pre-release
Pre-release

Choose a tag to compare

Version 3.1.0

Packaging-focused release: the fat jar is gone and every supported platform ships a native installer with its own bundled Java runtime. Also introduces a pluggable signing-engine architecture with a new EU DSS (PAdES) engine.

  • Per-platform native installers built with jpackage and a bundled Zulu+FX 21 runtime, so no system Java is required: Windows MSI, Linux DEB and RPM, and macOS DMG, each alongside a portable ZIP. Flatpak bundles are published for Linux x64 and aarch64.
  • Two cross-platform ZIPs for users who already have Java 21: a full ZIP carrying JavaFX natives for all platforms (with a Swing fallback when none match) and a minimal ZIP without JavaFX for headless/CLI signing and downstream packagers.
  • Fat jar dropped — the shaded all-in-one jar is no longer produced; the cross-platform ZIPs use bin/jsignpdf.sh and bin\jsignpdf.cmd launchers instead. The library jar published to Maven Central is unchanged.
  • Pluggable signing engines selectable with the new --list-engines and -eng / --engine options or the Engine selector in Preferences. JSignPdf ships OpenPDF as the default engine.
  • New EU DSS (PAdES) engine (id dss) producing PAdES signatures at the ETSI baseline levels B, T, LT, and LTA, which the OpenPDF engine cannot create.
  • Default hash algorithm is now SHA-256 (was SHA-1) for signing that relies on the implicit default. An explicit or saved hash.algorithm is untouched, and SHA-1 stays selectable for the OpenPDF engine.
  • CLI signatures now append by default, matching the GUI. Use the new --overwrite flag to replace existing signatures; the legacy --append / -a flag is kept as a no-op.
  • Signed Windows installers — the Windows MSI installers are Authenticode-signed via SignPath, so they install without an unknown-publisher warning. Pre-release builds ship unsigned.
  • Configurable default output suffix — the _signed marker appended to the output file name can now be changed with the new output.suffix key in advanced.properties, so non-English users can localize it (e.g. _firmado). It feeds both GUIs and the default for the CLI -os / --out-suffix option.
  • Checksums for every artifact — a jsignpdf-<version>-SHA256SUMS.txt file now covers all published release assets.

JSignPdf_3_1_0-RC-2

JSignPdf_3_1_0-RC-2 Pre-release
Pre-release

Choose a tag to compare

Version 3.1.0

Packaging-focused release: the fat jar is gone and every supported platform ships a native installer with its own bundled Java runtime. Also introduces a pluggable signing-engine architecture with a new EU DSS (PAdES) engine.

  • Per-platform native installers built with jpackage and a bundled Zulu+FX 21 runtime, so no system Java is required: Windows MSI, Linux DEB and RPM, and macOS DMG, each alongside a portable ZIP. Flatpak bundles are published for Linux x64 and aarch64.
  • Two cross-platform ZIPs for users who already have Java 21: a full ZIP carrying JavaFX natives for all platforms (with a Swing fallback when none match) and a minimal ZIP without JavaFX for headless/CLI signing and downstream packagers.
  • Fat jar dropped — the shaded all-in-one jar is no longer produced; the cross-platform ZIPs use bin/jsignpdf.sh and bin\jsignpdf.cmd launchers instead. The library jar published to Maven Central is unchanged.
  • Pluggable signing engines selectable with the new --list-engines and -eng / --engine options or the Engine selector in Preferences. JSignPdf ships OpenPDF as the default engine.
  • New EU DSS (PAdES) engine (id dss) producing PAdES signatures at the ETSI baseline levels B, T, LT, and LTA, which the OpenPDF engine cannot create.
  • Default hash algorithm is now SHA-256 (was SHA-1) for signing that relies on the implicit default. An explicit or saved hash.algorithm is untouched, and SHA-1 stays selectable for the OpenPDF engine.
  • CLI signatures now append by default, matching the GUI. Use the new --overwrite flag to replace existing signatures; the legacy --append / -a flag is kept as a no-op.
  • Signed Windows installers — the Windows MSI installers are Authenticode-signed via SignPath, so they install without an unknown-publisher warning. Pre-release builds ship unsigned.
  • Checksums for every artifact — a jsignpdf-<version>-SHA256SUMS.txt file now covers all published release assets.