Signing a PDF with your eID
In chapter 7.1 you signed a little sentence about the washing-up. You made the key pair for it on the spot in your browser, and when you closed the tab it was gone — it had never existed anywhere else. Here you do exactly the same thing, but with a key you didn't make and can't copy, because it sits in a piece of plastic in your wallet. And you're not signing a little sentence but a real document. What comes out is, in the eyes of the law, your signature.
Words you'll need in a moment
- PAdES
- Short for PDF Advanced Electronic Signatures. The agreement on how a digital signature is stored inside a PDF file, so that every reader finds it the same way. Laid down by ETSI, the European standards institute for telecoms, in the standard EN 319 142.
- Signing certificate
- The certificate on your eID that belongs to the
signkey, separate from the one for logging in. You only get it from the age of eighteen. - eIDAS
- The European regulation that says what an electronic signature is worth in law. Regulation (EU) No 910/2014, of 23 July 2014.
- Qualified electronic signature
- The heaviest of the three kinds eIDAS knows. Only this one is legally put on a par with a signature made with a pen. There are two conditions: a qualified certificate, and a device that doesn't let go of your private key. Your eID is both.
- Timestamp
- A signed statement from an independent service: "this document existed in this form at this hour on this day". Without a timestamp, a signature doesn't prove when it was put there.
- Validating
- Checking whether a signature is right: whether the seal matches the document, whether the certificate comes from a trusted issuer, and whether that certificate was still valid at the time.
What happens when you click "sign"
- The whole PDF file is hashed (chapter 2). A three-megabyte document comes down to a single number of 32 bytes. Change one comma in it and that number is completely different.
- Only that hash goes to the chip in your card. The document itself does not: the chip has neither the room nor the computing power for it, and it doesn't need to see it either.
- You enter your PIN. The chip signs the hash with the
signkey — the private half of a key pair (chapter 6) that never leaves the chip, as you saw in chapter 8.2. What comes out is only the signature. - That signature goes into the PDF file, together with your signing certificate and the certificates above it, all the way up to the Belgian State — the chain from chapter 7.2. Without that chain a reader knows that something was signed, but not by whom.
- A timestamp is fetched and enclosed with it, so that later on it's established when you signed, even if your certificate has expired in the meantime.
PAdES: the signature sits inside the document
A scanned scribble at the bottom of a page is a picture. It sits next to the text and knows nothing about the text. Someone can cut it out from underneath and paste it under another document, or change the amount above it, and there's nothing to see on the picture. So it only proves that a signature once existed somewhere.
A PAdES signature isn't a picture but a calculation over the bytes of the file. It's stored inside the PDF file itself, in a fixed place every PDF reader knows, along with which part of the file has been signed. Change one character in there and the hash from step 1 no longer matches, so the seal no longer matches, and every reader says so. There's no "nearly right" — exactly as in the demo in chapter 7.1.
| Scanned scribble or picture | PAdES signature | |
|---|---|---|
| Attached to | nothing — it's an image | the bytes of the document |
| Change afterwards | invisible | breaks the signature |
| Who signed | whoever can copy the scribble | whoever had the private key in hand |
| Forgeable with | cut and paste | nothing that exists today |
PAdES isn't a separate invention for PDF. Underneath it sits CMS, the same packaging format for signed data that also lies under signed email, in the ETSI version called CAdES. PAdES is the agreement on how you get such a package neatly into a PDF file.
auth or sign: here it's sign
Your card has two keys, and the difference is not a technical detail.
auth says "this is me" — that's a login attempt, and you can
simply do it again tomorrow or not do it. sign says "I agree
with what's written above". Signing a document is the second one, and so
this service uses sign.
Never sign anything you haven't read. This is the most
important sentence in this chapter. The chip doesn't read your document,
doesn't check whether it's reasonable and doesn't warn you about anything; it
works out a seal over the bytes it's given. That seal is legally just as
valid as your signature with a pen, and you can't deny it afterwards and
can't take it back. Whoever asks for your PIN for sign is asking
for your signature — not your password.
What the law says about it
eIDAS knows three levels of electronic signature: simple, advanced and qualified. Only the last one is put on a par with a signature made by hand. Article 25 of Regulation (EU) No 910/2014 says that a qualified electronic signature has the equivalent legal effect of a handwritten signature. A judge may not refuse the other two levels because they're electronic, but they don't get that equivalence.
Your eID is at that top level. The certificate belonging to the
sign key is literally called, in the official documents,
"Gekwalificeerd Certificaat voor Elektronische Handtekeningen" (qualified
certificate for electronic signatures), and the certificate for logging in
expressly is not — that distinction was made on purpose.
In 2024 eIDAS was revised by Regulation (EU) 2024/1183 of 11 April 2024, which you'll usually see called eIDAS 2. It adds the European framework for a digital identity wallet on your phone. It changes nothing about the three levels or about the equivalence of the qualified signature.
Two reasons why it might not work yet. The signing
certificate only goes onto your card from the age of eighteen; if you're
younger, only auth is on it and you can log in but not sign.
That isn't a technical limit but a legal one: a minor usually can't bind
themselves legally. And since 21 May 2026 the oldest cards are out
— the signing certificate on eIDs issued before 4 July 2016 lost
its qualification that day. Logging in with such a card still works, signing
doesn't; the government is setting up a separate service for that. See
the announcement from the Interior Ministry.
Sign a real PDF
Careful: here your document does go to a server. With every other demo on this site everything stays in your browser; not here. Your PDF is uploaded, because that's where the hash is calculated and that's where the signature is put back into the file. The service writes about this: "Your PDF is only processed temporarily and deleted after signing. Nothing is kept." You can't check that from the outside — you either trust it or you don't. Your PIN does stay put: you type that into the eID software on your own computer. If you add a visible stamp, then your name, your national register number and the date appear on screen in the document; they're already in the certificate that goes along anyway.
The service is called eID PDF-handtekening (eID PDF signature) and lives at pdfsign.hermesplatform.be. Free, no account. It comes from the same maker as this site and uses the same beID platform as the demo in chapter 8.2 — you ought to know that before you upload anything, because you can't see it from the outside. The site itself is in Dutch, so the button names below are given in English with the Dutch wording in brackets.
- Make sure you're set up as in chapter 8.2: card reader plugged in, the government's eID software and the helper installed, card and PIN to hand. This doesn't work on a phone.
- Drag your PDF into the box, or click to browse. PDF only, 10 MB maximum. The file name and the size appear; with Choose another file (Ander bestand kiezen) you start over.
- Click Sign with eID (Onderteken met eID). You get to see your document with a signature box on it. Drag that to the place where your stamp should go; with Previous page (Vorige pagina) and Next page (Volgende pagina) you pick the sheet.
- Click Continue to signing (Verder naar ondertekenen). If you don't want a stamp on screen but do want a valid signature, choose Sign without a visible stamp (Onderteken zonder zichtbare stempel) — the signature is still in the file afterwards, you just don't see it sitting there.
- Put your card in the reader and enter your PIN. Read what's in the
document first. This is
sign. - You get the signed PDF back to download. Keep that file the way you get it: don't save it again with another program, because then you write over the bytes the signature is about.
If the service refuses your file with a message that it uses a modern xref-stream format, that isn't your fault: not every PDF variant is accepted. Print the document to PDF or save it again, and try once more.
How you check whether it worked
Open the signed PDF in a reader that knows about signatures — Adobe Acrobat Reader does. A bar appears at the top saying the document has been signed. Open up the signature panel and you'll see who signed, when, and the sentence it's all about: that the document hasn't been changed since that signature. If you can't find that sentence, something is wrong.
If you'd rather not lean on Adobe alone, there's the European Commission's validation tool: the DSS demo. There you upload your PDF and get back a report from a party that has nothing to do with your document or with this service. That's the point of a standard like PAdES: everyone checks the same file in the same way, and you don't have to take anyone's word for it.
Want to see that it really works: make a copy, edit that copy, change one letter and save. Open it again. The reader now reports that the document has been changed after signing. That's the same Verify button from chapter 7.1, only built into your PDF reader.
This is math: one signature under two documents
Your chip never saw your document. It put a seal on 32 bytes. That the signature nevertheless covers the whole document isn't a law but an assumption — and there are two very different ways to knock it over.
The first: someone has your signed contract and afterwards looks for another document with exactly the same hash. That's hitting one particular value, and with SHA-256 that costs about 2256 attempts. That road is closed and stays closed.
The second: someone makes in advance two documents that have the same hash, has you sign the innocent one, and sticks your signature on the other. Now they don't have to hit a particular value but only make two things coincide — the birthday paradox from chapter 2 — and that costs the square root of it: 2128. The same hash, but 2128 times less work — purely because the question was put differently.
That's not a thought experiment. On 23 February 2017 the CWI in Amsterdam and Google published two PDF files with different contents and exactly the same SHA-1 hash. It cost them 9,223,372,036,854,775,808 calculations — precisely 263 — and some 110,000 dollars of rented computing time. SHA-1 was already on its way out by then; that day it was finished. What gets signed today uses SHA-256 or stronger. This is complexity theory: the field that doesn't ask whether something is possible, but how much work it costs — and that here decides how much a signature is worth.