> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/verificacion_firmas.md).

# Verification of received signatures

The process of verifying received signatures is automatic and is carried out as detailed below.

## Configuration

First, the *remote signers* of the *contact*will have been configured, who are the authors of the signatures that will be received and verified, and as many *file groups* for verification purposes as necessary. The *file groups* will be linked to *channels* reception with signature of the *contact*. These elements can be configured one by one or implemented in bulk by importing certain configuration that the signing endpoint has previously exported and sent (see [Export and import](/documentacion-editran/connect-v2.1-en/firma/administracionconnectfirma/grupoficheros/exportar_e_importar.md)).

## Reception

Once the configuration is complete, signature files are received by a *channel* reception directory that has the signature characteristic. Connect recognizes signature files only as files with the .xsig or .p7b extension. If the remote endpoint is not going to send them with that extension, a modifier must be applied to the reception directory using the **G Menu** of Editran to add it.

## Validation

Signature files received in a *channel* signature directory are verified immediately and automatically upon receipt. The verification of a signature is carried out on two levels:

**1)** It is checked that the signature is correct with respect to itself: integrity and structure, use of valid certificates that have been issued by recognized Certification Authorities and that are not expired or revoked. At this time the signers of the file are also obtained.

📌 **To keep in mind**

> This first validation phase is directly linked to the signing mode used in generating the signatures. Therefore, it is essential that all signature files received through the same *channel* have been created with the same signing mode. Consequently, all *file groups* to be verified associated with that *channel* must share the same value for that parameter.

Once these validations are passed, in the signing modes where this includes the signed file, it is extracted and the format is obtained. When the file corresponds to one of the banking standards covered, at this time the NIF, suffix, account and amounts are also recorded.

If there is a *file group* with verification purpose associated with that *channel* and in accordance with the obtained values, the file is assigned to it.

If there is no *file group* matching one, or there is ambiguity when assigning the file to a signing rule, the file extracted from the signature is not left in the output directory and the fact is reported.

**2)** Once the file has been assigned to a *file group* for verification purposes, the second stage of validation is carried out in which it is checked that the signers of the file obtained in the first stage of validation are those expected according to the signing rule, both in quantity and identity.

If this validation completes successfully, the file extracted from the signature remains in the output directory of the *file group*.

If this validation finishes with an error result (for example, the file is missing signatures), the file extracted from the signature is placed in: \`\[Output directory of the file group]\With Error\`

If there are users with signer, controller or administrator and signature controller roles associated with the *file group* to verify, they will be able to access Connect and consult the **Files**menu. Once in the view, it will be filtered by **Verify** and the list of received files will be displayed. From the list, as has already been seen in the files of *file groups* for signing purposes, it is possible to consult their signers, the verification status and view it. In this version this query can only be performed manually in this way

**Process summary**

1️⃣ **Receipt of the signature file (.p7b or .xsig)**\
2️⃣ **Validation with respect to itself**\
\- Structure\
\- Certificate expiration\
\- Integrity of the signed file\
3️⃣ **Obtaining signers**\
4️⃣ **Extraction of the signed document**\
5️⃣ **Assignment of the extracted document to a file group (or signing rule)**\
6️⃣ **Validation of signers according to&#x20;*****file group*****&#x20;assigned** 7️⃣ **Depending on the result, the extracted file remains in the output directory of the file group or in a subdirectory of it called `WithError`**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v2.1-en/firma/verificacion_firmas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
