|
Developer
Downloads
Tutorial
Licensing
Mac
OS X
Success Stories
|

|
Legal Digital
Signature,
About new
XML software solutions papers and latest secure electronic
articles.
|
To
sign a Legal Digital Signature file, a publisher obtains public and private keys from
an independent 'Certificate Authority' (Microsoft does not provide such
keys.) The public key is a kind of certificate that identifies a
specific publisher. The publisher uses a 'signing tool' to sign each
file using their private key. Publishers will only need to obtain one
set of keys from a Certificate Authority. These can be used to sign any
file they produce, since a signature identifies a publisher not a
specific Legal Digital Signature file.
Legal Digital
Signature,
how publishers sign
their files?
|
We have released a
font signing tool that publishers can use to sign
True-Type and Open-Type fonts. In addition to actually adding the digital
signature to the font file, the tool will perform tests to help
publishers ensure their fonts conform to the published font
specifications and do not contain serious bugs. The signatures
themselves are formed using industry standards (standard hashing
algorithms and standard signature formats). -Legal Digital Signature
|
Legal Digital
Signature,
How operating systems
validate signatures?
|
In most circumstances Legal Digital Signature signed files will
be treated differently than unsigned files by operating systems and
applications. Current versions of Microsoft Internet Explorer, for
example, provide a different set of warnings when downloading unsigned
files from the Internet than when downloading files that have been
signed. The way in which future Microsoft operating systems will
deal with
signed and unsigned fonts, is still being decided. However, it is
important for publishers to start signing their fonts as soon as
possible. It is possible that many corporations will adopt a policy of
only allowing signed files on their networks. In the future it will be
possible for system administrators to implement company wide policies to
prevent employees from installing unsigned software, including Legal
Digital Signature unsigned fonts.
|
|