> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/verificacion_firmas.md).

# Verification of received signatures

The signature verification process for received files is automatic and is carried out as detailed below.

## Configuration

First, the *remote signers* of the *contact*, who are the authors of the signatures to be received and verified, and as many *file groups* verification-purpose ones as necessary. The *file groups* will be linked to *channels* receiving directories with signature from the *contact*. These elements can be configured one by one or deployed in bulk by importing certain configuration that the signing endpoint has previously exported and sent (see [Export and import](/documentacion-editran/connect-3.2-en/firma/administracionconnectfirma/grupoficheros/exportar_e_importar.md)).

## Incoming

Once the configuration has been made, the signature files are received by a *channel* receiving directory that has the signature feature. Connect only recognizes signature files with .xsig or .p7b extension. If the remote endpoint is not going to send them with that extension, a modifier must be applied to the receiving directory using the **Menu G** of Editran to add it.

## Validation

The signature files received in a *channel* signature directory are verified immediately and automatically upon receipt. The verification of a signature is carried out at two levels:

**1)** It is checked that the signature is correct with respect to itself: integrity and structure, use of valid certificates that have been issued by recognized Certification Authorities and that are neither expired nor revoked. At this point the file signers are also obtained.

📌 **Note**

> This first validation phase is directly linked to the signature mode used in generating the signatures. Therefore, it is essential that all signature files received through the same *channel* have been made with the same signature mode. Consequently, all the *file groups* to be verified associated with that *channel* must share the same value for that parameter.

Once these validations have been passed, in the signature modes in which this includes the signed file, it is extracted and the format is obtained. When the file corresponds to one of the bank standards handled, the NIF, suffix, account and amounts are also recorded at this point.

If there is a *file group* with verification purpose associated with that *channel* and according to the values obtained, the file is assigned to it.

If there is no *file group* that matches, or there is ambiguity when assigning the file to a signing rule, the file extracted from the signature is not left in the output directory and this is reported.

**2)** Once the file has been assigned to a *file group* verification-purpose one, the second stage of validation is carried out, in which it is checked that the signers of the file obtained in the first stage of validation are the expected ones according to the signing rule, both in number and identity.

If this validation ends successfully, the file extracted from the signature remains in the output directory of the *file group*.

If this validation ends with an error result (for example, the file is missing signatures), the file extracted from the signature remains in: \`\[File group output directory]\With Error

If there are users with signer, controller or administrator and signature controller roles associated with the *file group* to verify, they will be able to access Connect and consult the **Files**. Once in the view, it will be filtered by **Verify** and the list of received files will be shown. From the list, as has already been seen in the files of *file groups* to sign purposes, it is possible to consult their signers, the verification status and view it. In this version this query can only be performed manually in this way

**Process summary**

1️⃣ **Receipt of the signature file (.p7b or .xsig)**\
2️⃣ **Validation with respect to itself**\
\- Structure\
\- Certificate expiration\
\- Integrity of the signed file\
3️⃣ **Obtaining signers**\
4️⃣ **Extraction of the signed document**\
5️⃣ **Assignment of the extracted document to a file group (or signing rule)**\
6️⃣ **Validation of signers according to&#x20;*****file group*****&#x20;assigned** 7️⃣ **According to the result, the extracted file remains in the output directory of the file group or in a subdirectory of it called `WithError`**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-3.2-en/firma/verificacion_firmas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
