What Is a Digital Signature and How Does It Work?

A digital signature is a cryptographic value attached to a document that lets a recipient confirm two things: who signed it, and whether the file changed after signing. It is not the same as a typed or drawn electronic signature, and it is not the same as encryption. You need a digital certificate (a file holding your identity plus a public key) to create one, and the recipient needs software that can read the signature format to verify it. Tools such as Signature995 handle this by using Microsoft digital certificate technologies to create and validate signatures on PDF, Office, and Zip files.

Digital signature vs. electronic signature vs. encryption

These three terms get used interchangeably, but they solve different problems.

Term What it proves What it does not do
Electronic signature That someone indicated intent to sign (typed name, drawn mark, click-to-accept) Prove the file wasn't altered afterward
Digital signature Signer identity plus document integrity, via cryptography Hide the document contents
Encryption Confidentiality — only password/certificate holders can read it Prove who created or approved it

A digital signature can be combined with encryption. In Signature995, checking "SecureSign" signs the document and encrypts it, so the file is both tamper-evident and unreadable without the password.

The mechanism: certificates and public-key cryptography

A digital signature relies on a key pair. The signer holds a private key; the certificate carries the matching public key and identity information. Signing runs the document through a hash and encrypts that hash with the private key. Verification decrypts the hash with the public key and compares it to a fresh hash of the received file. If they match, the document is unchanged; if the certificate is trusted, the signer is who the certificate says.

Signature995 creates an unauthenticated digital certificate the first time it runs. That matters: an unauthenticated (self-issued) certificate can prove the document wasn't altered, but it does not carry the identity assurance of a certificate issued and validated by a trusted authority. For internal or low-stakes use that's often enough; for legal or financial transactions where the counterparty must trust the signer's identity, expect to need a certificate from a recognized issuer.

The practical workflow

The steps below follow how Signature995 describes its own operations. Other tools use different menus but the same underlying sequence.

Signing

  1. Select the document to sign (PDF, .doc, .xls, .ppt, or .zip).
  2. Choose the signing action. The tool applies your digital certificate to the file.
  3. If you want confidentiality as well, enable SecureSign so the signed file is also encrypted.
  4. The output lands in the same folder as the original, with a double extension: signed.995 or securesigned.995.

Verifying

  1. Open the signed or SecureSigned document in the tool.
  2. If it is SecureSigned, supply the document password.
  3. The tool verifies the signature and displays the certificate(s) attached to the document.

Co-signing

Co-signing adds your certificate to a document that already carries a signature. If the existing signature is a SecureSigned one, the tool requires that document's password before it will add yours. This is how you build a multi-party approval chain on a single file rather than passing around separate copies.

File types and formats

Signature995 supports PDF documents (*.pdf), Microsoft Office documents (*.doc, *.xls, *.ppt), Zip archives (*.zip), and UltraPdf documents (*.updf). The same file set applies to its encryption and decryption features. If your workflow lives entirely in PDF, that's the most common case; the Office and Zip support matters when you need to sign a spreadsheet or a packaged bundle rather than a single PDF.

Where verification fails

Verification is a pass/fail check, and most failures trace back to the certificate rather than the document:

  • Expired certificate — the signature may still be cryptographically valid, but the tool will flag the certificate as out of date.
  • Untrusted or unauthenticated certificate — a self-issued certificate verifies integrity but not identity, so a recipient expecting a trusted issuer will see it as unverified.
  • Modified document — any change after signing breaks the hash comparison. This is the feature working as intended.
  • Missing password on a SecureSigned file — verification can't proceed until the password is supplied.
  • Certificate not present on the verifying machine — the recipient may need the signer's certificate to complete the trust check.

What it costs and what to expect

Signature995 is available as a free download (Version 26.0, 35.4 MB) and is free to both sender and recipient. The free version displays a sponsor page in your browser each time you run it; a license key to remove those pages costs $9.95. If you deploy it on a Citrix or Terminal Server, the vendor's documented configuration is to add User Mode=1 to the Parameters section of ..pdf995\res\pdf995.ini.

The practical takeaway: use a digital signature when you need tamper-evidence and signer identity, add SecureSign when you also need confidentiality, and check the certificate's trust status before assuming a "verified" result means the signer's identity has been independently confirmed.

signature995.com
Signature995 uses native PDF encryption, offering a high level of protection for all your Internet communications, including legal documents and fina…