|
|
5.7 Validation of VERS signatures
When validating a digital signature the complete chain of certificates must be validated. These certificates will be found in the Signature Block which contains the signature, or as Certificates found in records referenced by the Certificate Reference (M141) element. The root certificate of the certificate chain will be self-signed and must be validated by one of the following two mechanisms:
- By means of a copy of the certificate stored in a secure place on the recordkeeping system.
- By comparing the root certificate in the signature block with those from other instances of signatures signed by the same user at roughly the same time.
back to top
printer friendly
|