How to open a .sig file
A .sig file from a Polish signing program is a CAdES electronic signature. Drop it below to see the signed document and who signed it. Checked: that the document has not changed since signing and that the signature matches the certificate in the file. Not checked: the EU Trusted List and revocation. The file is not uploaded anywhere.
Nothing is uploaded. Only this page reads the file, in your browser. We count only that a file was opened (its format and the result), never its contents or name.
Where .sig files come from
Polish qualified-signature software, such as proCertum SmartSign and Szafir, writes the signature to a .sig file when the signer picks CAdES instead of XAdES. The file is a CMS structure (RFC 5652): the signature, the signer's certificate and often the document itself.
The document inside, or beside it
- Enveloping: the document is inside the .sig file. Drop just that file.
- Detached: the .sig file holds only the signature, and the document is a separate file. Drop both together; the page recognises the document by its digest, even under another name.
A .sig that is not a CAdES signature
Other programs use the .sig extension too: GnuPG (PGP signatures beside downloaded software) and mail programs (an e-mail footer). The page recognises such a file and says what it probably is.
Questions
Does this confirm the signature is valid?
No. It confirms that the document has not changed since it was signed and that the signature matches the certificate in the file. It does not check the EU Trusted List or revocation, so it does not judge legal validity.
Is my file sent anywhere?
No. The file is read only by this page in your browser. You can confirm it in your browser's developer tools, on the Network tab.