> For the complete documentation index, see [llms.txt](https://docs.editran.onesait.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/firma/verificacion_firmas.md).

# Verification of received signatures

The process of verifying received signatures is automatic and is carried out in the manner detailed below.

## Configuration

First, the *remote signers* of the *contact*, who are the authors of the signatures that are going to be received and verified, and as many *file groups* verification-purpose groups as necessary. The *file groups* will be linked to *channels* signature reception with signature from the *contact*. These elements can be configured one by one or implemented in batch by importing certain configuration that the signing endpoint has previously exported and sent (see [Export and import](/documentacion-editran/connect-v3.1-en/firma/administracionconnectfirma/grupoficheros/exportar_e_importar.md)).

## Reception

Once the configuration has been completed, the signature files are received by a *channel* reception directory that has the signature feature. Connect recognizes as signature files only files with the .xsig or .p7b extension. If the remote endpoint is not going to send them with that extension, a modifier must be applied to the reception directory using the **G Menu** of Editran to add it.

## Validation

The signature files received in a *channel* signature group are verified immediately and automatically after receipt. Verification of a signature is carried out in two levels:

**1)** It is checked that the signature is correct in relation to itself: integrity and structure, use of valid certificates that have been issued by recognized Certification Authorities and are neither expired nor revoked. At this point, the file signers are also obtained.

📌 **Things to keep in mind**

> This first validation phase is directly linked to the signing mode used in generating the signatures. Therefore, it is essential that all signature files received through the same *channel* have been created with the same signing mode. Consequently, all the *file groups* to be verified associated with that *channel* must share the same value for that parameter.

Once these validations have been passed, in signing modes in which this includes the signed file, it is extracted and the format is obtained. When the file corresponds to one of the banking standards handled, at this point the NIF, suffix, account and amounts are also recorded.

If there is a *file group* verification-purpose group associated with that *channel* and according to the values obtained, the file is assigned to it.

If there is no *file group* that matches, or there is ambiguity when assigning the file to a signing rule, the file extracted from the signature is not left in the output directory and the fact is reported.

**2)** Once the file has been assigned to a *file group* verification-purpose group, the second stage of validation is performed, in which it is checked that the signers of the file obtained in the first stage of validation are the expected ones according to the signing rule, both in number and identity.

If this validation ends successfully, the file extracted from the signature remains in the output directory of the *file group*.

If this validation ends with an error result (for example, the file is missing signatures), the file extracted from the signature remains in: \`\[File group output directory]\\\With Error

If there were users with signer, controller, or admin and signature controller roles associated with the *file group* to verify, they will be able to access Connect and consult the menu **Files**. Once in the view, it will be filtered by **Verify** and the list of received files will be displayed. From the list, as has already been seen in the *file groups* of purpose sign files, it is possible to consult their signers, the verification status, and view it. In this version this query can only be made manually in this way

**Process summary**

1️⃣ **Receipt of the signature file (.p7b or .xsig)**\
2️⃣ **Validation against itself**\
\- Structure\
\- Certificate expiration\
\- Integrity of the signed file\
3️⃣ **Obtaining signers**\
4️⃣ **Extraction of the signed document**\
5️⃣ **Assignment of the extracted document to a file group (or signing rule)**\
6️⃣ **Validation of signers according to&#x20;*****file group*****&#x20;assigned** 7️⃣ **Depending on the result, the extracted file remains in the output directory of the file group or in a subdirectory of this called `With Error`**


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.editran.onesait.com/documentacion-editran/connect-v3.1-en/firma/verificacion_firmas.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
