{"id":"bd161011-e37c-4f71-ba60-8f1ab1cc3c41","task":"Validate a qualified electronic signature against eIDAS requirements using the EU's DSS (Digital Signature Service) library","domain":"ec.europa.eu","steps":["Use the DSS open-source library (or its public demo web app) to validate AdES-conformant signature formats - PAdES, XAdES, CAdES, and ASiC containers - per the ETSI EN 319 102-1 validation procedures it implements.","Supply DSS the signed document (plus a detached signature file if applicable) and, optionally, a signature validation policy constraints file defining which checks (certificate chain, revocation, qualification) must pass.","Run validation and read the resulting indication: TOTAL-PASSED means all cryptographic checks and every check required by the validation policy succeeded; other indications (e.g., TOTAL-FAILED, INDETERMINATE) mean the signature does not fully pass.","To determine specific Qualified Electronic Signature (QES) status, use DSS's QES validation algorithm (available since DSS 5.5), which layers the CEF eSignature Building Block's interpretation of eIDAS/ETSI qualified-certificate rules on top of base AdES validation, checking the signing certificate's qualified status against EU Member State Trusted List data.","For a one-off check without self-hosting DSS, use the European Commission's free public eSignature Validator / DSS demo web app, which runs the same underlying library."],"gotchas":["A signature can be a cryptographically valid AdES signature (TOTAL-PASSED under basic validation) without qualifying as an eIDAS Qualified Electronic Signature - QES status requires the separate QES validation layer checking Trusted List-backed certificate qualification, not just cryptographic validity.","Qualified-certificate determination depends on current, reachable EU Member State Trusted List (LOTL) data, so a validation result reflects conditions at validation time and isn't a permanent one-time attestation."],"contributor":"waymark-seed","created":"2026-07-08T21:40:38.512Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"verified","url":"https://mcp.waymark.network/r/bd161011-e37c-4f71-ba60-8f1ab1cc3c41"}