We’re happy to announce the release of GroupDocs.Signature for .NET v26.9, available as of September 2026. This release is a security‑focused update that introduces .NET 10 support, discontinues .NET Standard 2.1, and enforces stricter defaults for loading external resources, hashing algorithms, and certificate validation. It also adds support for signing Word documents with post‑quantum (ML‑DSA) certificates and resolves several critical bugs related to verification, logging, and platform‑specific behavior.
Що нового у цьому випуску
- [Feature] .NET 10 support and .NET Standard 2.1 discontinued (SIGNATURENET-5938)
- [Enhancement] External resources are no longer loaded by default (SIGNATURENET-5950)
- [Enhancement] PDF digital signatures use SHA-256 by default and honour HashAlgorithm (SIGNATURENET-5976)
- [Enhancement] SignatureFont no longer exposes System.Drawing types on .NET 6 and later (SIGNATURENET-5943)
- [Enhancement] Signing with an expired or not‑yet‑valid certificate is rejected by default (SIGNATURENET-5995)
- [Enhancement] Sign Word documents with post‑quantum (ML‑DSA) certificates (SIGNATURENET-5996)
- [Bug] Verify did not check PDF digital signatures cryptographically (SIGNATURENET-5978)
- [Bug] SubjectName and IssuerName were ignored when verifying PDF documents (SIGNATURENET-5997)
- [Bug] Time‑stamp server credentials were sent only when both user name and password were set (SIGNATURENET-5998)
- [Bug] Saving presentations and Word documents as images failed on Linux and macOS (SIGNATURENET-5999)
- [Bug] LoadExternalResources was ignored for documents inside archives (SIGNATURENET-6000)
- [Bug] External images and style sheets of SVG images were always loaded (SIGNATURENET-6001)
- [Bug] Search and verification of a spreadsheet with a linked picture threw ArgumentNullException (SIGNATURENET-6002)
- [Bug] CertificateVerifyOptions.Expired was wrong by the local UTC offset (SIGNATURENET-6003)
- [Bug] SignatureSettings.LogLevel had no effect (SIGNATURENET-6004)
- [Bug] A reused VerifyOptions reported signatures of documents verified earlier (SIGNATURENET-6005)
- [Bug] A reused DigitalSignOptions signed later presentations with its first certificate and comment (SIGNATURENET-6006)
- [Enhancement] Internal improvements (SIGNATURENET-5979)
Зміни публічного API
| Член | Зміна |
|---|---|
LoadOptions.SkipExternalResources |
New. bool, default true. When true, external resources are not loaded, except those that match WhitelistedResources. |
LoadOptions.WhitelistedResources |
New. List<string>, default empty. Parts of addresses that may be loaded while SkipExternalResources is true. An address is loaded when it contains one of them, ignoring case. Setting null clears the list. |
LoadOptions.LoadExternalResources |
Obsolete. Still works, with the opposite meaning of SkipExternalResources. Its default changed from true to false. Using it produces compiler warning CS0618. |
SignatureFont implicit conversion from System.Drawing.Font |
Removed from the .NET 6, .NET 8 and .NET 10 builds. Obsolete in the .NET Framework build. Assign the SignatureFont properties instead. |
SignOptions.HashAlgorithm |
No signature change. It now takes effect for PDF digital signatures; before, it was ignored. |
DigitalVerifyOptions.SubjectName, DigitalVerifyOptions.IssuerName |
No signature change. They now take effect for PDF documents; before, they were ignored there. |
SignatureSettings.LogLevel |
No signature change. It now takes effect: only messages of the levels it contains reach the logger, and LogLevel.None logs nothing. Before, every message was logged whatever the value. The descriptions of the LogLevel values were corrected. |
VerificationResult.Succeeded, VerificationResult.TotalSignatures |
No signature change. When one VerifyOptions object is used for several Verify calls, they now list only the signatures of the document just verified. |
DigitalSignOptions.AllowExpired |
New. bool, default false. When false, signing with a certificate whose validity period has ended throws GroupDocsSignatureException. When true, the document is signed and a warning is logged. |
DigitalSignOptions.AllowNotYetValid |
New. bool, default false. The same, for a certificate whose validity period has not started yet. |
Нові функції
No new features beyond those listed in Що нового у цьому випуску and Зміни публічного API.
Приклад коду
Allow only trusted external resources:
LoadOptions loadOptions = new LoadOptions
{
WhitelistedResources = new List<string> { "https://cdn.example.com/images/" }
};
using (Signature signature = new Signature("sample.docx", loadOptions))
{
// Only images from https://cdn.example.com/images/ are loaded.
}
Sign with SHA-384 and use an expired certificate (with warning):
using (Signature signature = new Signature("sample.pdf"))
{
DigitalSignOptions options = new DigitalSignOptions("certificate.pfx")
{
Password = "1234567890",
HashAlgorithm = HashAlgorithm.Sha384 // honoured from this release; the default is SHA-256
};
signature.Sign("signed.pdf", options);
}
Sign with an expired certificate explicitly allowed:
SignatureSettings settings = new SignatureSettings(new ConsoleLogger());
using (Signature signature = new Signature("sample.pdf", settings))
{
DigitalSignOptions options = new DigitalSignOptions("certificate.pfx")
{
Password = "1234567890",
AllowExpired = true
};
signature.Sign("signed.pdf", options);
// If certificate.pfx has expired, the document is signed and the console shows a warning such as:
// The signing certificate expired on 2019-05-01 12:00 UTC (subject "CN=...", thumbprint ...).
}
Sign a Word document with a post‑quantum ML‑DSA certificate:
using (Signature signature = new Signature("sample.docx"))
{
DigitalSignOptions options = new DigitalSignOptions("ml-dsa-65.pfx")
{
Password = "1234567890"
};
signature.Sign("signed.docx", options);
}
Configure logging to show only errors and warnings:
SignatureSettings settings = new SignatureSettings(new ConsoleLogger())
{
// Errors and warnings, without the step-by-step traces.
LogLevel = LogLevel.Error | LogLevel.Warning
};
Як отримати оновлення
NuGet
Upgrade to the latest GroupDocs.Signature package via NuGet: GroupDocs.Signature 26.9.0
Install command:
dotnet add package GroupDocs.Signature --version 26.9.0
Пряме завантаження
Download assemblies from the GroupDocs.Signature for .NET 26.9 page