PDF Digital Signature

by Benjamín Alcalde G.
5
4
3
2
1
Score: 50/100

Description

Reviews

No reviews yet.

Stats

0
stars
215
downloads
0
forks
22
days
3
days
3
days
0
total PRs
0
open PRs
0
closed PRs
0
merged PRs
0
total issues
0
open issues
0
closed issues
18
commits

Latest Version

4 days ago

Changelog

French is now available throughout the plugin interface and documentation. This release also fixes PDF replacement safety, certificate status, HTML escaping in footers, delayed signing settings, dialog errors, and plugin cleanup.

  • Preserve the original PDF when replacement fails or the document changes while signing; reject re-signing that would invalidate an existing signature.
  • Read the certificate matching the RSA private key, handle expiry and future validity accurately, and back up certificates when renewing.
  • Keep export settings for delayed jobs, prevent duplicate jobs, and offer a vault PDF picker when the system dialog is unavailable.
  • Complete English, Spanish, Portuguese, Italian, and French translations; localize defaults and dates. New installations get a random certificate password; existing settings are preserved.
  • Clarify bundled dependencies, self-signed certificate trust, plaintext password storage, and the scope of the PKCS#7 signature implementation.

Validation: TypeScript check, production build, JavaScript syntax check, and 10 automated tests passed, including cryptographic signature verification and production bundle loading.

Headless export integration: five two-page Chromium PDFs cover all signing/footer combinations. Both signed PDFs passed CMS digest and RSA verification; extracted text, numbering and signature fields were checked on every page. The installed Obsidian 1.13.7 PDF modal and IPC export contracts were inspected for compatibility. The open Obsidian instance was not driven: its CLI is disabled.

README file from

Github

PDF Digital Signature for Obsidian

Languages / Idiomas / Lingue: 🇬🇧 English | 🇪🇸 Español | 🇧🇷 Português | 🇮🇹 Italiano | 🇫🇷 Français


License: MIT Obsidian Plugin No external tools: JavaScript / TypeScript Platform: Desktop Languages

PDF Digital Signature is a lightweight plugin with bundled JavaScript libraries for Obsidian that seamlessly integrates cryptographic digital signatures (PKCS#7 / X.509) and custom running footers into your exported PDF documents.

The signature allows a PDF reader to check whether the signed content has changed. Trust in the signer depends on the certificate and the reader’s trust settings. A self-signed certificate is not automatically trusted.


✨ Features

  • 🔏 True Cryptographic Signatures (PKCS#7): X.509 (.pfx / .p12). Detects changes to signed content; it does not prevent editing the PDF.
  • 📄 Running Footers on Every Page: Stamps your name (or custom text) on the bottom-left and running page numbers (page / total) on the bottom-right across all pages.
  • 🎛️ Independent Export Controls: Choose cryptographic signing, signer name, and page numbering separately for each PDF. Your choices are remembered as defaults.
  • ⚡ Portable with Bundled Libraries: Built entirely in pure TypeScript/JavaScript (node-forge + pdf-lib + @signpdf). No Python, no OpenSSL, no terminal commands required.
  • 🌐 Multi-Language Support (i18n): Full translations in English (en), Spanish (es), Portuguese (pt), Italian (it), and French (fr), automatically matching your Obsidian display language.
  • ⏳ Expiration Warnings & 1-Click Renewal: Monitors certificate validity and shows proactive alerts when your certificate has 30 days or less remaining, with an instant renewal button.
  • 🎛️ Native Integration: Hooks directly into Obsidian's built-in "Export to PDF" dialog with three independent controls that remember your preferences.
  • ⏱️ Automated Post-Processing: Optionally waits a customizable delay (default: 5 seconds) after export to ensure safe disk writes, applies the signature, and opens the signed PDF in your default viewer.
  • 🔑 Built-in Certificate Generator: Don't have a commercial certificate yet? Generate a self-signed 3-year certificate with 1 click directly in the plugin settings.
  • 🛡️ 100% Private & Offline: Everything runs locally on your machine. No telemetry, no network calls.

🚀 How It Works

  1. Open any note in Obsidian and trigger the native Export to PDF dialog (Ctrl + P / Cmd + P ➔ Export to PDF).
  2. Choose any combination of the three added options: cryptographic signing, signer name, and page numbering.
  3. Click Export to PDF and select your destination.
  4. The plugin automatically:
    • Prints the note with your name on the footer of every page.
    • Waits the configured delay (e.g. 5 seconds) and displays a progress notice.
    • Seals the document with your .pfx certificate.
    • Opens the signed PDF in your default viewer when enabled.

🛠️ Installation

  1. Open Obsidian Settings ➔ Community plugins.
  2. Search for PDF Digital Signature.
  3. Click Install, then Enable.

Method 2: Via BRAT (Beta Reviewer's Auto-update Tool)

  1. Install the BRAT community plugin in Obsidian.
  2. In BRAT settings, choose Add Beta plugin.
  3. Paste: https://github.com/Benhaman9/obsidian-pdf-digital-signature
  4. Click Add Plugin and enable it.

Method 3: Manual Installation

  1. Download main.js, manifest.json, and styles.css from the Latest Release.
  2. Create a folder named obsidian-pdf-digital-signature in your vault's .obsidian/plugins/ directory.
  3. Copy the 3 downloaded files into that folder.
  4. Reload Obsidian and enable the plugin under Community plugins.

⚙️ Configuration

In Obsidian's Settings ➔ PDF Digital Signature:

Setting Description Default
Cryptographically sign by default Applies the PKCS#7 signature independently from footer content. true
Show signer name by default Whether the signer name appears at the bottom-left. true
Signer name (Running footer) The text displayed when the signer-name option is enabled. Name of Signer
Display page number Displays page / total on the bottom-right. true
Delay before signing Seconds to wait before applying the signature. 5 seconds
Open PDF after signing Automatically opens your default PDF viewer once signed. true
Certificate file path Relative or absolute path to your .pfx or .p12 file. Scripts/certificado.pfx
Certificate password Password used to decrypt your certificate. Randomly generated on first load
Reason / Location Signature metadata displayed in Adobe Acrobat. Generic placeholders

Using an Official Certificate

If you own an accredited digital signature (such as a commercial X.509 certificate in .p12 or .pfx format), simply place it in your vault or enter its absolute path and password in the settings.


📄 License

This project is licensed under the MIT License.

Made with ❤️ by Benjamín Alcalde G.

Certificate and signature limitations

A random password is generated on first load. You can change it before creating a certificate. The plugin saves it in plain text in its local settings; protect the vault and its backups. Renewal preserves the previous certificate in a .bak file next to it. Existing signed PDFs are rejected because this plugin rewrites the PDF rather than adding an incremental signature. The signature uses adbe.pkcs7.detached; full PAdES profile conformance, trusted timestamps and long-term validation are not claimed.

Adobe: certificate trust · Signing library