PDFFileElement: trust property

Works in all major browsers
Since July 2026

WebPDF works in Chrome and Edge 125, Firefox 153 and Safari 18, on desktop and mobile, and in every later version: the oldest versions its PDF.js build supports, which already have every platform feature WebPDF needs. Since July 2026, that is every major browser.

The trust read-only property of the PDFFileElement interface returns an object with the trust anchors a <pdf-file> verifies its signatures against. Its properties reflect the trust:srcdoc, trust:src and trust:stores HTML attributes.

Value

An object with three properties. Nothing is trusted by default:

srcdoc

A string of certificates, inline: PEM CERTIFICATE or PKCS7 blocks, or bare base64 DER.

src

A string: the URL of a certificate file (PEM, DER or a PKCS #7 bundle), fetched directly by the browser. Relative, data: and blob: URLs work.

stores

A live DOMTokenList of well-known root stores, fetched fresh from their publishers through the built-in proxy and cached for five minutes:

aatl

The Adobe Approved Trust List: the authorities Acrobat trusts for signed PDFs (about 180 roots).

eutl

The EU trusted lists: the qualified certificate authorities of every EU and EEA country, status granted (about 880).

ms

The roots Microsoft trusts for document signing, from the CCADB (about 80).

moz

The roots Mozilla trusts for signed email, from the CCADB (about 90).

The file's anchors add up with the WebPDF <script>'s: a value of - drops the script's, -name drops one inherited store, and "- name" replaces them. Changing an anchor verifies the signatures again without loading the file again. A source that fails adds a TRUST_SOURCE_FAILED warning to every row.

Examples

Trusting your own root and the EU lists

html
<pdf-file id=s src=//new.webpdf.pro/signed.pdf trust:src=//new.webpdf.pro/demo-root.pem trust:stores=eutl></pdf-file>
js
const file = document.querySelector("#s");
file.trust.stores.add("aatl"); // + the Adobe list
file.trust.stores.add("-moz"); // - the <script>'s Mozilla roots

Specifications

Not part of any specification. <pdf-file> and <pdf-page> are autonomous custom elements defined by WebPDF.pro. It implements:

Specification
ISO 32000-2:2020 (PDF 2.0)
# 12.8 Digital signatures
RFC 5280: X.509 certificates and CRLs

Browser compatibility

desktopmobile
Chrome
Edge
Firefox
Opera
Safari
Chrome Android
Firefox for Android
Opera Android
Safari on iOS
Samsung Internet
WebView Android
WebView on iOS
trust
1251251531111812515383182712518
  • trust · Chrome, Edge, Firefox, Opera, Safari, Chrome Android, Firefox for Android, Opera Android, Safari on iOS, Samsung Internet, WebView Android, WebView on iOS: Secure contexts (HTTPS) only; elsewhere every signature verifies as unknown.

Legend

Full support
See implementation notes.

See also