[{"data":1,"prerenderedAt":417},["ShallowReactive",2],{"github-releases":3,"app-docs-en":82},{"releases":4,"fetchedAt":80,"source":81},[5,26,43,61],{"tag":6,"name":7,"body":8,"publishedAt":9,"prerelease":10,"draft":10,"htmlUrl":11,"assets":12},"v1.3.1","Cachet v1.3.1","Standalone binaries (no Python required):\n- `cachet-…-linux-x86_64.tar.gz` — `cachet` (GUI) + `cachet-cli` (console)\n- `cachet-…-windows-x86_64.zip` — `cachet.exe` (GUI) + `cachet-cli.exe` (console)\n\nRuntime requirements (beid mode): Belgian eID middleware + reader.\nLevels ≥ b-t need network (TSA \u002F trust lists \u002F OCSP-CRL) — see BUILD.md.\n\n\n**Full Changelog**: https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fcompare\u002Fv1.3.0...v1.3.1","2026-09-02T00:23:19Z",false,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Ftag\u002Fv1.3.1",[13,20],{"name":14,"size":15,"downloadCount":16,"url":17,"digest":18,"platform":19},"cachet-1.3.1-linux-x86_64.tar.gz",117878510,0,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.3.1\u002Fcachet-1.3.1-linux-x86_64.tar.gz","sha256:2cd9800a127722d8a8a7fec4d09fe105978536d32effb29a2459f77578314bd6","linux",{"name":21,"size":22,"downloadCount":16,"url":23,"digest":24,"platform":25},"cachet-1.3.1-windows-x86_64.zip",76394236,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.3.1\u002Fcachet-1.3.1-windows-x86_64.zip","sha256:d5b70604770c06a10b241973a3d976f8e29c0708f1a1683dea3a94a247258cff","windows",{"tag":27,"name":28,"body":29,"publishedAt":30,"prerelease":10,"draft":10,"htmlUrl":31,"assets":32},"v1.3.0","Cachet v1.3.0","Standalone binaries (no Python required):\n- `cachet-…-linux-x86_64.tar.gz` — `cachet` (GUI) + `cachet-cli` (console)\n- `cachet-…-windows-x86_64.zip` — `cachet.exe` (GUI) + `cachet-cli.exe` (console)\n\nRuntime requirements (beid mode): Belgian eID middleware + reader.\nLevels ≥ b-t need network (TSA \u002F trust lists \u002F OCSP-CRL) — see BUILD.md.\n\n\n**Full Changelog**: https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fcompare\u002Fv1.2.0...v1.3.0","2026-09-01T23:21:31Z","https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Ftag\u002Fv1.3.0",[33,38],{"name":34,"size":35,"downloadCount":16,"url":36,"digest":37,"platform":19},"cachet-1.3.0-linux-x86_64.tar.gz",117877275,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.3.0\u002Fcachet-1.3.0-linux-x86_64.tar.gz","sha256:156cc1ea5df98a96d14bc0ef1fd97d156bfdc602ed3dbda0699bbc5a7416d350",{"name":39,"size":40,"downloadCount":16,"url":41,"digest":42,"platform":25},"cachet-1.3.0-windows-x86_64.zip",76399964,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.3.0\u002Fcachet-1.3.0-windows-x86_64.zip","sha256:4afcafe7b6080f38e93212128686d8e23ba30a084d0f7fa32f524592f43a2e2c",{"tag":44,"name":45,"body":46,"publishedAt":47,"prerelease":10,"draft":10,"htmlUrl":48,"assets":49},"v1.2.0","Cachet v1.2.0","Standalone binaries (no Python required):\n- `cachet-…-linux-x86_64.tar.gz` — `cachet` (GUI) + `cachet-cli` (console)\n- `cachet-…-windows-x86_64.zip` — `cachet.exe` (GUI) + `cachet-cli.exe` (console)\n\nRuntime requirements (beid mode): Belgian eID middleware + reader.\nLevels ≥ b-t need network (TSA \u002F trust lists \u002F OCSP-CRL) — see BUILD.md.\n\n\n## What's Changed\n* Feat\u002Fgui wizard i18n by @SebastienDenooz in https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fpull\u002F2\n\n\n**Full Changelog**: https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fcompare\u002Fv1.0.0...v1.2.0","2026-09-01T11:47:20Z","https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Ftag\u002Fv1.2.0",[50,55],{"name":51,"size":52,"downloadCount":16,"url":53,"digest":54,"platform":19},"cachet-1.2.0-linux-x86_64.tar.gz",115246124,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.2.0\u002Fcachet-1.2.0-linux-x86_64.tar.gz","sha256:2efcc7774be825da23f439ba6ad7161e7cd4c34e982fcf9003b9aec8cfb03dc4",{"name":56,"size":57,"downloadCount":58,"url":59,"digest":60,"platform":25},"cachet-1.2.0-windows-x86_64.zip",73765801,3,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.2.0\u002Fcachet-1.2.0-windows-x86_64.zip","sha256:c79f855f71b43185a1a643f93fe602bb0ed9779f4266d504f95a9296d29001c6",{"tag":62,"name":63,"body":64,"publishedAt":65,"prerelease":10,"draft":10,"htmlUrl":66,"assets":67},"v1.0.0","Cachet v1.0.0","Standalone binaries (no Python required):\n- `cachet-…-linux-x86_64.tar.gz` — `cachet` (GUI) + `cachet-cli` (console)\n- `cachet-…-windows-x86_64.zip` — `cachet.exe` (GUI) + `cachet-cli.exe` (console)\n\nRuntime requirements (beid mode): Belgian eID middleware + reader.\nLevels ≥ b-t need network (TSA \u002F trust lists \u002F OCSP-CRL) — see BUILD.md.\n\n\n## What's Changed\n* V0.9RC1 by @SebastienDenooz in https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fpull\u002F1\n\n## New Contributors\n* @SebastienDenooz made their first contribution in https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fpull\u002F1\n\n**Full Changelog**: https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Fcommits\u002Fv1.0.0","2026-06-04T23:29:36Z","https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Ftag\u002Fv1.0.0",[68,74],{"name":69,"size":70,"downloadCount":71,"url":72,"digest":73,"platform":19},"cachet-1.0.0-linux-x86_64.tar.gz",115132670,2,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.0.0\u002Fcachet-1.0.0-linux-x86_64.tar.gz","sha256:7680996ec90f3854f1738643cf7850b54208eecb9fd41f1da07a2ffa2e0447ed",{"name":75,"size":76,"downloadCount":77,"url":78,"digest":79,"platform":25},"cachet-1.0.0-windows-x86_64.zip",73729919,1,"https:\u002F\u002Fgithub.com\u002FAlchemicStudio\u002FCachet\u002Freleases\u002Fdownload\u002Fv1.0.0\u002Fcachet-1.0.0-windows-x86_64.zip","sha256:6de537a8b1537a334ab13bd27271cc6465f2e38388b22727134977a8bdca7694","2026-09-02T00:23:59.476Z","snapshot",{"_generated":83,"sections":84,"sources":371},"Ported from the Cachet app's i18n_docs.py by scripts\u002Fextract_app_docs.py — edit there, not here.",[85,131,155,205,347],{"id":86,"title":87,"blocks":88},"modes","THE THREE MODES",[89,92,129],{"type":90,"text":91},"p","Cachet signs a whole batch of PDFs the same way. Pick the mode that matches the legal weight you need.",{"type":93,"items":94},"list",[95,111,120],{"term":96,"text":97,"lines":98},"BEID — your Belgian eID card","",[99,102,105,108],{"label":100,"text":101,"bullet":10},"What it is","a qualified electronic signature (QES), the highest legal tier, equivalent to a handwritten signature.",{"label":103,"text":104,"bullet":10},"Requires","a card reader, your eID card, and one PIN entry per document. A visible vignette (your photo, name, and date) is added.",{"label":106,"text":107,"bullet":10},"Use it when","a document must be legally binding and provably signed by you in person.",{"label":109,"text":110,"bullet":10},"Note","your national register number (RRN) is embedded in every signature, so share signed files carefully.",{"term":112,"text":97,"lines":113},"AZURE — your personal certificate in Azure Key Vault",[114,116,118],{"label":100,"text":115,"bullet":10},"an advanced electronic signature (AES). Strong and verifiable, but one tier below QES.",{"label":103,"text":117,"bullet":10},"one Microsoft login per batch (not per document). Only the document digest leaves your machine; the private key never does. Trust is anchored on your organisation's internal CA.",{"label":106,"text":119,"bullet":10},"you need a real cryptographic signature for many files quickly, without your physical card.",{"term":121,"text":97,"lines":122},"IMAGE — paste a picture only",[123,125,127],{"label":100,"text":124,"bullet":10},"a visual stamp, NOT a cryptographic signature. No legal value.",{"label":103,"text":126,"bullet":10},"nothing; works fully offline.",{"label":106,"text":128,"bullet":10},"you only need a document to look signed, with no legal effect.",{"type":90,"text":130},"**Recommendation:** use BEID for legally binding documents, AZURE for large batches, and IMAGE only for appearance.",{"id":132,"title":133,"blocks":134},"levels","PAdES LEVELS",[135,137],{"type":90,"text":136},"PAdES levels (ETSI EN 319 142-1) describe how durable and verifiable your signature is. Each level builds on the one before it. Cachet uses b-lta by default and never silently drops to a lower level if the network fails.",{"type":93,"items":138},[139,143,147,151],{"term":140,"text":141,"lines":142},"B-B (basic)","The core signature: it proves who signed and that the document has not changed. Works fully offline. Pick it only for quick internal drafts where long-term proof and a trusted time do not matter.",[],{"term":144,"text":145,"lines":146},"B-T (+ timestamp)","Adds a trusted timestamp from a time-stamping authority (TSA), proving WHEN you signed. Needs network access. Pick it when the signing date must be provable but long-term archiving is not required.",[],{"term":148,"text":149,"lines":150},"B-LT (+ long-term validation)","Embeds the revocation data (OCSP\u002FCRL) and CA certificates inside the PDF (LTV). The signature stays verifiable even after the certificates expire. Needs network access. Pick it for documents you must keep and check years later.",[],{"term":152,"text":153,"lines":154},"B-LTA (+ archival, DEFAULT)","Adds an archival timestamp chain so the proof itself survives for decades (the chain is renewed every few years). Needs network access. This is the default because it gives the strongest, longest-lasting guarantee for official records.",[],{"id":156,"title":157,"blocks":158},"tiers","AES VS QES: WHICH SIGNATURE DO I NEED?",[159,161,175,185,192],{"type":90,"text":160},"Under EU law (eIDAS) there are three levels of electronic signature:",{"type":93,"items":162},[163,167,171],{"term":164,"text":165,"lines":166},"SES (simple)","any electronic mark, even a pasted picture. Easy, but weak proof of who signed. This is what \"image\" mode produces — no legal value.",[],{"term":168,"text":169,"lines":170},"AES (advanced)","uniquely tied to one signer and to the exact document; any later change is detectable. This is \"azure\" mode.",[],{"term":172,"text":173,"lines":174},"QES (qualified)","an AES made with a certified device and a face-to-face-verified identity. By law it is equal to a handwritten signature. This is \"beid\" (eID card) mode.",[],{"type":176,"term":177,"lines":178},"definition","QES — eID card (beid)",[179,182],{"label":180,"text":181,"bullet":10},"Pros","the strongest level; legally equal to a handwritten signature; accepted by any third party with no prior agreement.",{"label":183,"text":184,"bullet":10},"Cons","needs a card reader and your card; you type your PIN ONCE PER DOCUMENT (slow for big batches); your national register number (RRN) is embedded in every file.",{"type":176,"term":186,"lines":187},"AES — Azure Key Vault (azure)",[188,190],{"label":180,"text":189,"bullet":10},"ONE login per batch, so fast for many files; no card or reader; no RRN exposure.",{"label":183,"text":191,"bullet":10},"not \"qualified\"; trust relies on your organisation's internal CA, so outside parties may not recognise it automatically.",{"type":176,"term":193,"lines":194},"Which one should I choose?",[195,199,202],{"label":196,"text":197,"bullet":198},"Internal documents, or large batches","use azure (AES). One login signs the whole batch.",true,{"label":200,"text":201,"bullet":198},null,"Documents leaving the organisation, or where a handwritten-equivalent signature is required: use beid (QES), accepting one PIN per document.",{"label":203,"text":204,"bullet":198},"No card or reader available","azure is your only cryptographic option.",{"id":206,"title":207,"blocks":208},"glossary","GLOSSARY",[209,211,216,221,226,232,237,242,247,252,257,262,267,272,277,282,288,293,298,304,310,315,321,326,331,336,342],{"type":90,"text":210},"Cachet signs PDF documents in batches. It can apply three kinds of mark: a cryptographic signature made with your Belgian eID card (beid), a cryptographic signature made with your personal certificate held in Azure Key Vault (azure), or a simple pasted image with no legal value (image). For the two cryptographic modes it follows the European PAdES standard and, after signing, re-checks each file and tells you exactly what was achieved. The terms below explain what those checks and labels mean.",{"type":176,"term":212,"lines":213},"Electronic signature",[214],{"label":200,"text":215,"bullet":10},"A legally recognised way to sign a document electronically. Unlike a scanned handwritten signature, a cryptographic electronic signature also proves WHO signed and that the file has not changed since.",{"type":176,"term":217,"lines":218},"SES \u002F AES \u002F QES",[219],{"label":200,"text":220,"bullet":10},"The three eIDAS tiers, weakest to strongest. SES (simple) is just \"an electronic mark\". AES (advanced) is uniquely linked to the signer and detects any later change. QES (qualified) is an AES made with a qualified certificate and secure device, and is legally equal to a handwritten signature. eID = QES, Azure = AES, image = none.",{"type":176,"term":222,"lines":223},"eIDAS",[224],{"label":200,"text":225,"bullet":10},"The EU regulation that defines electronic signatures, trust services and the SES\u002FAES\u002FQES tiers, so a signature made in one EU country is recognised across the others.",{"type":176,"term":227,"lines":228},"PAdES",[229],{"label":230,"text":231,"bullet":10},"\"PDF Advanced Electronic Signatures\"","the ETSI standard (EN 319 142-1) for embedding signatures inside PDF files. Cachet writes PAdES signatures so any compliant reader (e.g. Adobe) can verify them.",{"type":176,"term":233,"lines":234},"CMS",[235],{"label":200,"text":236,"bullet":10},"The low-level container format (Cryptographic Message Syntax) that actually holds the signature bytes, certificates and timestamps inside the PDF. PAdES is a PDF-specific profile built on top of CMS.",{"type":176,"term":238,"lines":239},"Digest \u002F hash",[240],{"label":200,"text":241,"bullet":10},"A short fixed-length fingerprint computed from the document. Change one byte and the fingerprint changes completely. The signature is made over this fingerprint, which is why only the digest, never the full file, is sent to Azure.",{"type":176,"term":243,"lines":244},"Certificate",[245],{"label":200,"text":246,"bullet":10},"An electronic identity card for a cryptographic key: it binds a public key to a person or service and is itself signed by a Certificate Authority. Yours proves the signature really came from you.",{"type":176,"term":248,"lines":249},"CA \u002F certificate chain",[250],{"label":200,"text":251,"bullet":10},"A Certificate Authority (CA) issues certificates. Verifying a signature means following the chain from your certificate up through one or more CAs to a trusted root. If the whole chain checks out, the signature is trusted.",{"type":176,"term":253,"lines":254},"eID \u002F non-repudiation certificate",[255],{"label":200,"text":256,"bullet":10},"A Belgian eID card carries two certificates; Cachet uses the \"non-repudiation\" one, which is reserved for legally binding signatures (as opposed to the \"authentication\" certificate used only to log in).",{"type":176,"term":258,"lines":259},"RRN",[260],{"label":200,"text":261,"bullet":10},"The Belgian National Register Number. It is embedded in every eID signature. Anyone who receives a signed PDF can read it, so share signed files carefully.",{"type":176,"term":263,"lines":264},"PKCS#11",[265],{"label":200,"text":266,"bullet":10},"The standard software interface Cachet uses to talk to the eID card through the card-reader middleware. It lets the app use the card's key without the key ever leaving the card.",{"type":176,"term":268,"lines":269},"PIN",[270],{"label":200,"text":271,"bullet":10},"The secret code that unlocks your eID card's signing key. The card never reveals the key; it only signs when the PIN is correct. In beid mode Cachet asks for it once PER DOCUMENT.",{"type":176,"term":273,"lines":274},"Azure Key Vault",[275],{"label":200,"text":276,"bullet":10},"A Microsoft cloud service that stores your personal certificate and key so the key cannot be exported. Signing happens inside the vault: only the document digest is sent there, and the signed result comes back.",{"type":176,"term":278,"lines":279},"Microsoft Entra ID",[280],{"label":200,"text":281,"bullet":10},"Microsoft's identity and login service (formerly Azure Active Directory). In azure mode you log in once PER BATCH to prove you may use your key in the vault.",{"type":176,"term":283,"lines":284},"UPN",[285],{"label":286,"text":287,"bullet":10},"User Principal Name","your sign-in identity in Entra ID, usually in the form name@organisation. It is how the app knows which vault account is yours.",{"type":176,"term":289,"lines":290},"RFC 3161 timestamp \u002F TSA",[291],{"label":200,"text":292,"bullet":10},"A trusted, dated stamp proving the signature existed at a given moment. It comes from a Time-Stamping Authority (TSA) over the network and protects the signature even after the signing certificate later expires.",{"type":176,"term":294,"lines":295},"Qualified vs free timestamp",[296],{"label":200,"text":297,"bullet":10},"A free timestamp (Cachet's default, from DigiCert) is technically valid and widely trusted. A qualified timestamp comes from an eIDAS-qualified TSA and carries stronger legal weight. Both prove \"when\"; only the qualified one is \"qualified\".",{"type":176,"term":299,"lines":300},"LTV",[301],{"label":302,"text":303,"bullet":10},"Long-Term Validation","enough proof is stored inside the PDF that it can still be verified years later, even after the certificates have expired or the issuing CA has gone offline.",{"type":176,"term":305,"lines":306},"DSS",[307],{"label":308,"text":309,"bullet":10},"The Document Security Store","the area inside the PDF where LTV evidence (certificates and revocation data) is kept so the file is self-contained.",{"type":176,"term":311,"lines":312},"OCSP",[313],{"label":200,"text":314,"bullet":10},"A live online check asking the CA \"is this certificate still valid right now, or was it revoked?\". The answer is saved in the DSS for LTV.",{"type":176,"term":316,"lines":317},"CRL",[318],{"label":319,"text":320,"bullet":10},"Certificate Revocation List","a published list of certificates the CA has cancelled. An alternative to OCSP for proving a certificate was still good when used; also stored for LTV.",{"type":176,"term":322,"lines":323},"EU Trusted List (LOTL)",[324],{"label":200,"text":325,"bullet":10},"The official EU list of trusted qualified providers (the List of Trusted Lists). eID (QES) trust ultimately traces here. Azure (AES) does NOT: it is trusted via your organisation's internal CA instead.",{"type":176,"term":327,"lines":328},"Internal CA",[329],{"label":200,"text":330,"bullet":10},"Your organisation's own Certificate Authority. In azure mode, trust and LTV are anchored on this internal CA chain (a PEM file you provide), not on the EU Trusted List.",{"type":176,"term":332,"lines":333},"Vignette",[334],{"label":200,"text":335,"bullet":10},"The small visible stamp Cachet draws on the page in eID and Azure modes: the cardholder's photo (eID only), \"Signed by:\", the name and the date. It is the human-readable face of an otherwise invisible cryptographic signature. You choose its position by clicking on the page preview; without a click it goes bottom-right on the last page.",{"type":176,"term":337,"lines":338},"Template validation",[339],{"label":340,"text":341,"bullet":10},"A safety check","before signing, every input PDF is compared to a model (\"template\") and must have the same page count and identical page sizes. This guarantees the signature lands in the right spot on every file in the batch. When some files have a DIFFERENT page count (e.g. scanned annexes were added), a first\u002Flast-page selector appears at the validation step and at the top of the placement step: every such file is then signed on its own first or last page — that page must still have exactly the template's page size, so the position you pick is guaranteed to fit.",{"type":176,"term":343,"lines":344},"B-LTA renewal",[345],{"label":200,"text":346,"bullet":10},"B-LTA (the default level) adds an archival timestamp chain so the evidence stays provable for decades. \"Renewal\" means that, every few years, a fresh archive timestamp must be added before the previous one's protection weakens.",{"id":348,"title":349,"blocks":350},"glance","PAdES LEVELS, AT A GLANCE",[351,369],{"type":93,"items":352},[353,357,361,365],{"term":354,"text":355,"lines":356},"B-B","basic signature, fully offline.",[],{"term":358,"text":359,"lines":360},"B-T","adds a trusted timestamp (network needed).",[],{"term":362,"text":363,"lines":364},"B-LT","adds revocation info and CA certs (LTV).",[],{"term":366,"text":367,"lines":368},"B-LTA","adds the archival timestamp chain (default).",[],{"type":90,"text":370},"Cachet never silently downgrades these levels. If the network is unavailable and the requested level cannot be reached, it tells you rather than quietly producing a weaker signature.",{"heading":372,"intro":373,"items":374},"SOURCES AND FURTHER READING","The standards and services mentioned above. Click a title to open it in your browser (most of these documents are in English).",[375,378,381,384,387,390,393,396,399,402,405,408,411,414],{"title":376,"url":377},"eIDAS — Regulation (EU) No 910\u002F2014 on electronic identification and trust services (EUR-Lex)","https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2014\u002F910\u002Foj",{"title":379,"url":380},"ETSI EN 319 142-1 — PAdES digital signatures: building blocks and baseline signatures (B-B, B-T, B-LT, B-LTA)","https:\u002F\u002Fwww.etsi.org\u002Fdeliver\u002Fetsi_en\u002F319100_319199\u002F31914201\u002F01.01.01_60\u002Fen_31914201v010101p.pdf",{"title":382,"url":383},"ETSI TS 119 612 — Trusted Lists (format of the EU and national trusted lists)","https:\u002F\u002Fwww.etsi.org\u002Fdeliver\u002Fetsi_ts\u002F119600_119699\u002F119612\u002F02.02.01_60\u002Fts_119612v020201p.pdf",{"title":385,"url":386},"EU Trusted List Browser — the List of Trusted Lists (LOTL) and every national list","https:\u002F\u002Feidas.ec.europa.eu\u002Fefda\u002Ftl-browser\u002F",{"title":388,"url":389},"RFC 3161 — Time-Stamp Protocol (TSP): how trusted timestamps are requested and issued","https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc3161",{"title":391,"url":392},"DigiCert — the free RFC 3161 timestamp service Cachet uses by default","https:\u002F\u002Fknowledge.digicert.com\u002Fgeneral-information\u002Frfc3161-compliant-time-stamp-authority-server",{"title":394,"url":395},"RFC 5652 — Cryptographic Message Syntax (CMS): the signature container inside the PDF","https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc5652",{"title":397,"url":398},"RFC 6960 — Online Certificate Status Protocol (OCSP): live certificate revocation checks","https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc6960",{"title":400,"url":401},"RFC 5280 — X.509 certificates and Certificate Revocation Lists (CRL)","https:\u002F\u002Fwww.rfc-editor.org\u002Frfc\u002Frfc5280",{"title":403,"url":404},"Belgian eID — official site: the card, the middleware, the PIN and the card reader","https:\u002F\u002Feid.belgium.be\u002Fen",{"title":406,"url":407},"OASIS PKCS #11 — the cryptographic token interface used to talk to the eID card","https:\u002F\u002Fdocs.oasis-open.org\u002Fpkcs11\u002Fpkcs11-base\u002Fv2.40\u002Fpkcs11-base-v2.40.html",{"title":409,"url":410},"Azure Key Vault — about keys: how keys are protected and used for signing in the vault","https:\u002F\u002Flearn.microsoft.com\u002Fazure\u002Fkey-vault\u002Fkeys\u002Fabout-keys",{"title":412,"url":413},"Microsoft Entra ID — the identity service used for the azure-mode sign-in","https:\u002F\u002Flearn.microsoft.com\u002Fentra\u002Ffundamentals\u002Fwhatis",{"title":415,"url":416},"pyHanko — the open-source PDF signing and validation library Cachet is built on","https:\u002F\u002Fpyhanko.readthedocs.io\u002F",1788308639621]