Keys & signatures

PGP key & signed PDFs

I sign my PDFs (quotes, invoices, CVs) with my own certificate. Your PDF viewer will say the signer’s identity is “unknown”, because I don’t pay a commercial certificate authority. This page gives you everything you need to check that a PDF really comes from me and hasn’t been altered.

Verify a PDF

Drop the PDF below. Every step of the chain of trust is checked in your browser.

How the trust works

  1. My PGP key is the anchor. It’s published independently on keys.openpgp.org and GitHub, so you can check its fingerprint somewhere other than this site.
  2. The PGP key signs the fingerprint of my root certificate (x509.cert.sha512.asc).
  3. The root certificate stays offline. It issues my signing certificate and publishes a revocation list (CRL), so a stolen signing key can be revoked.
  4. The signing certificate signs my PDFs, together with a timestamp from an independent authority that proves when each one was signed.

PGP key

Fingerprint

7526 0AC4 B55D 0A91 A079 760C BE7E 6798 D983 5EA6

Download the public key

Same key, published elsewhere:

X.509 certificates

Root certificate (CA)

Eymeric CHAUCHAT Root CA · Valid until September 25, 2036

SHA-256
82:29:9B:C3:08:9B:58:24:C7:B2:0D:20:D4:57:A2:7F:9B:F9:76:E3:66:04:B6:C4:6D:A0:4A:1B:C2:10:A8:45
SHA-512
90b1bec4c4ff9649b527b3a291e540b4ae8e80ff72eca7a0777b92a3e81e15a87c87b50a2eddc5a9127eaec04972e727d45be85ae65f3a0c82be0b0b4fb69348

root.cert.pemroot.cert.der

Current signing certificate

Eymeric CHAUCHAT <eymeric.chauchat@gmail.com> · Valid until November 2, 2027

SHA-256
D5:17:D6:88:A1:4C:A1:20:63:D4:D2:63:74:BF:D6:AE:79:20:53:8E:4F:A2:16:AC:69:9F:E4:E2:20:A9:73:A9
SHA-512
902ab42441d4053e40748a80bcbf05446d7d9ef0a2c5274b531f329078131893f2800a10c9a2eeb4d73723122ca653715bb221e424e463b4822279f28b61c392

signing.cert.pemsigning.cert.der

Revocation list (CRL)

Next update November 2, 2027

root.crl

Certificate fingerprints signed with my PGP key

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

90b1bec4c4ff9649b527b3a291e540b4ae8e80ff72eca7a0777b92a3e81e15a87c87b50a2eddc5a9127eaec04972e727d45be85ae65f3a0c82be0b0b4fb69348  root.cert.der
5bf1cde666c0be6530d7e68c5dd84d11d331589b6ce7b07fd64467b88e1296da99133b177812715c238bcd5a7b8bb51a526f83b726056db65c6bae7684bc73db  root.cert.pem
902ab42441d4053e40748a80bcbf05446d7d9ef0a2c5274b531f329078131893f2800a10c9a2eeb4d73723122ca653715bb221e424e463b4822279f28b61c392  signing.cert.der
887e76f7dddb6b624e8fa6ed57a991ef7221b9c348428e11abbeb3b924e414bc0b87900b9444ecaedc2adf044c1a2b6114733e4fb4e180e6c62e2fc150c93afa  signing.cert.pem
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQBs3Qb0toM6HaKl3wOzyTdmxKvZgUCarrMvQAKCRAOzyTdmxKv
ZjUmAP9c1IwpxkHJyOuO+7jhtAIJnTaoFBySfT44ervryvzW8wEAtzh9bIn40wQQ
Z8jg37srC+2ZUJ8Bd/fHRGHJI9zEZws=
=0GV9
-----END PGP SIGNATURE-----

x509.cert.sha512.asc

Don’t trust this page? Check by hand

The same checks with standard command-line tools:

curl -sO 'https://eymeric.me/gpg/{eymeric.asc,x509.cert.sha512.asc,root.cert.der,root.cert.pem,signing.cert.der,signing.cert.pem,root.crl}'
gpg --keyserver hkps://keys.openpgp.org --recv-keys 75260AC4B55D0A91A079760CBE7E6798D9835EA6
gpg --verify x509.cert.sha512.asc
gpg --decrypt x509.cert.sha512.asc | sha512sum -c
openssl crl -inform der -in root.crl -out root.crl.pem
openssl verify -CAfile root.cert.pem -CRLfile root.crl.pem -crl_check signing.cert.pem
pyhanko sign validate --pretty-print --trust root.cert.pem document.pdf

Offline verifier

A single self-contained HTML file with the same verifier and my keys built in. Save it, audit it, and use it without an internet connection.

Download verify.html