trust_lists library

Opt-in trust anchors for signature validation: the EU trusted lists (LOTL + Member State lists, fetched and signature-verified through a host transport) and a loader for an Adobe Approved Trust List file the host supplies.

The core library ships no roots. This library ships the mechanism - XML-signature verification of the lists, the pinned LOTL signers, and the parsers - so a host can build a PdfTrustStore from the official sources at run time or from a snapshot it refreshed with tool/trust_lists/refresh_trust_lists.dart. Pure Dart, no I/O.

Classes

PdfAatl
Where Adobe publishes the AATL for Acrobat, and the root its signature chains to.
PdfAatlSnapshot
The trust anchors read from an AATL file.
PdfEuLotl
The EU LOTL location and the certificates allowed to sign it.
PdfEuTrustListSnapshot
A verified set of EU trust anchors, with the per-list problems met while building it.
PdfTrustListEntry
One qualified CA service certificate from a Member State list.
PdfTrustListPointer
A pointer in the LOTL to one Member State's list.
PdfTrustLists
Builders for trust stores from the supported public lists.
XmlLiteDocument
A parsed document: top-level comments/PIs around the single root.
XmlLiteElement
An element: its qualified name, attributes (namespace declarations included, as written) and children.
XmlSignatureVerification
The outcome of verifyEnvelopedXmlSignature.

Enums

XmlC14nMethod
Canonical XML flavours used by XML signatures.

Constants

pdfTrustListExpiryGrace → const Duration
How long past its NextUpdate a trusted list is still accepted. A list that is not reissued by its NextUpdate is expired (ETSI TS 119 612 §5.3.14) and may still carry trust anchors that have since been withdrawn; the grace only absorbs clock skew and publication lag.

Functions

canonicalizeDocument(XmlLiteDocument document, {required XmlC14nMethod method, XmlLiteElement? omit, List<String> inclusivePrefixes = const []}) → Uint8List
Canonicalizes the whole document (comments dropped), leaving out the subtree omit - the enveloped-signature transform.
canonicalizeElement(XmlLiteElement element, {required XmlC14nMethod method, XmlLiteElement? omit, List<String> inclusivePrefixes = const []}) → Uint8List
Canonicalizes the subtree rooted at element as a document subset: the namespaces it inherits from its ancestors are rendered on it as needed.
fetchAatl({required Future<Uint8List> fetch(Uri url), DateTime? now, Duration maxAge = PdfAatl.maxAge, String rootFingerprint = PdfAatl.adobeRootFingerprint}) → Future<PdfAatlSnapshot>
Downloads the AATL from PdfAatl.url through the host's fetch (the library performs no I/O), verifies that its signature chains to Adobe Root CA G2 and that it was signed within maxAge of now, and returns its trusted roots. Throws FormatException when verification fails.
fetchEuTrustedLists({required PdfTrustListFetch fetch, Set<String> pinnedSigners = PdfEuLotl.signerFingerprints, DateTime? now}) → Future<PdfEuTrustListSnapshot>
Fetches the LOTL and every Member State list through fetch, verifies each signature (the LOTL against pinnedSigners, each national list against the certificates the LOTL names for it) and collects the qualified CA anchors. A list that fails to download or verify is skipped and reported in PdfEuTrustListSnapshot.problems - including one that is expired at now; a LOTL that fails or is expired is fatal (thrown). The snapshot's PdfEuTrustListSnapshot.expires is the earliest NextUpdate of the lists it was built from.
parseAatlSecuritySettings(Uint8List file, {bool verifySignature = true, String rootFingerprint = PdfAatl.adobeRootFingerprint, Duration? maxAge, DateTime? now}) → PdfAatlSnapshot
Reads the trusted roots out of an AATL .acrobatsecuritysettings file.
parseEuLotl(Uint8List bytes, {Set<String> pinnedSigners = PdfEuLotl.signerFingerprints, DateTime? now}) → ({DateTime? issued, DateTime? nextUpdate, List<PdfTrustListPointer> pointers, int? sequence})
Parses and verifies the LOTL: its signature must verify, its signing certificate must be one of pinnedSigners (SHA-256 fingerprints), and it must not be expired at now (NextUpdate + pdfTrustListExpiryGrace). Returns the pointers to the Member State XML lists.
parseEuTrustedList(Uint8List bytes, PdfTrustListPointer pointer, {DateTime? now}) → ({List<PdfTrustListEntry> entries, DateTime nextUpdate})
Parses and verifies one Member State list against its LOTL pointer: the list's signature must verify with one of the pointer's certificates, and it must not be expired at now. Returns the active qualified CA service certificates and the list's NextUpdate.
verifyEnvelopedXmlSignature(XmlLiteDocument document) → XmlSignatureVerification
Verifies the enveloped signature (a ds:Signature child of the root) of document. At least one reference must cover the whole document (URI="" or the root element's Id, with the enveloped-signature transform), so a signature over only its own properties is refused.

Typedefs

PdfTrustListFetch = Future<Uint8List> Function(Uri url)
Downloads url and returns the body; throws on failure. The host's transport (the library performs no I/O).