Skip to content

Pass explicit empty trust roots to pyHanko signature validation - #1

Merged
overjoyde merged 1 commit into
overjoyde:mainfrom
pepo72:fix/pyhanko-trust-roots
Sep 26, 2026
Merged

overjoyde merged 1 commit into
overjoyde:mainfrom
pepo72:fix/pyhanko-trust-roots

Conversation

@pepo72

@pepo72 pepo72 commented Sep 26, 2026

Copy link
Copy Markdown

Summary

Every signature validation emitted a DeprecationWarning from pyhanko-certvalidator 0.32:

Relying on the operating system's trust list is deprecated and will stop working in a future release; pass 'trust_roots' explicitly

The signatures analyser only uses pyHanko for integrity and post-signing modification checks. The signature.intact finding already states that trust roots are not configured by default, and the OS TLS trust list is not a meaningful source for document-signing trust anyway. This change passes ValidationContext(trust_roots=[]) so that intent is explicit, and the code keeps working when pyHanko removes the fall-back.

Certificate trust is still reported by the pdfsig cross-check, as before.

Changes

  • analyzers/signatures.py: pass an explicit empty trust-root list to validate_pdf_signature.
  • tests/test_analysis.py: new test that fails if the trust-list deprecation warning returns, and checks that trusted is reported as False.

Testing

  • pytest: 104 passed, also with -W error::DeprecationWarning.
  • Ran the five bank-statement example PDFs before and after the change. Verdicts, finding IDs and the pyHanko fields (intact, valid, trusted, modification_level, docmdp_ok) are identical.

Tested with pyHanko 0.37.0 and pyhanko-certvalidator 0.32.1 on Python 3.13.

pyhanko-certvalidator 0.32 deprecated the implicit fall-back to the
operating system's TLS trust list when no trust roots are given, and
warns that it will stop working in a future release. Every signature
validation triggered that DeprecationWarning.

The signatures analyser checks integrity and post-signing modifications,
not signer trust (the finding text already says trust roots are not
configured by default), and OS TLS roots are not a document-signing
trust source in any case. Passing a ValidationContext with an empty
trust_roots list makes that explicit and silences the warning.
Certificate trust continues to be reported by the pdfsig cross-check.

Findings for the bank-statement examples are unchanged. Adds a test
that fails if the deprecation warning returns.
@overjoyde
overjoyde merged commit f7c3a82 into overjoyde:main Sep 26, 2026
6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants