<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Adobe on Michael’s Domain</title><link>https://jeltsch.org/en/tags/adobe/</link><description>Recent content in Adobe on Michael’s Domain</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright © 2002 - 2026 Michael Jeltsch.</copyright><lastBuildDate>Fri, 24 Jul 2026 00:18:18 +0300</lastBuildDate><atom:link href="https://jeltsch.org/en/tags/adobe/index.xml" rel="self" type="application/rss+xml"/><item><title>Free digital signing of documents under Linux - an impossibility?</title><link>https://jeltsch.org/en/free_digital_signing_of_documents_under_linux_an_impossibility/</link><pubDate>Sun, 01 Dec 2019 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/free_digital_signing_of_documents_under_linux_an_impossibility/</guid><description>&lt;p&gt;The whole story started when I tried to sign a LibreOffice document. When you belive the internet, document signing is inbuilt into LibreOffice. I still have to find the person that managed to digitally sign a LibreOffice document. This experience shows, that despite 
 &lt;a href="https://en.wikipedia.org/wiki/Edward_Snowden" target="_blank" rel="noopener noreferrer nofollow"&gt;Edward Snowden&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 most people do not proactively care about security and privacy. Debian removed scdaemon from the gnupg2 package and as usual, one needs to be a command line ninja to fix this. The scdaemon gives smartcard support (which I do not have, but without the scdaemon the Kleopatra key manager refuses to run). I am using the default Ubuntu 18.04 installation and it was quite an odyssey to get a document signed. In fact, I still do not have a satisfactory way to do this. However one does it, something&amp;rsquo;s not right. Ubuntu 19.10 has fixed at least the invokation of the key manager from LibreOffice and I can invoke SeaHorse from the document signing dialog, but I still have no clue how to make my gpg keys visible to LibreOffice. Anybody figured this out? Until somebody shows me how to sign with LibreOffice, I use the very good, but proprietary software 
 &lt;a href="https://www.qoppa.com/pdfstudio/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDFStudio&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 to import my GPG keys and sign my PDF files.&lt;strong&gt;Signing services (DocuSign, HelloSign)&lt;/strong&gt; So what do you do if you need to sign e.g. a PDF and you have no means or do not want to subscribe to one of the document-signing certificate service like 
 &lt;a href="https://www.docusign.com/products-and-pricing" target="_blank" rel="noopener noreferrer nofollow"&gt;DocuSign&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
? Even with DocuSign&amp;rsquo;s budget plan a single digital signing costs $2. DocuSign has a 30-day free trial, but I do not know whether the certificats that you generate during the trial with continue to be valid after the end of the trial. HelloSign (
 &lt;a href="https://www.hellosign.com" target="_blank" rel="noopener noreferrer nofollow"&gt;https://www.hellosign.com&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
, now owned by DropBox ) has also a free tier (allowing to sign 3 documents/month) and when signing, it embeds an invisible signature (which was invalid for some strange reason when I tested it even though HelloSign is in Adobe&amp;rsquo;s approved trust list).&lt;strong&gt;Self-signing, cacert and StartSSL&lt;/strong&gt;Technically you can created your own signatures (self-signed certificates), but if such PDFs are viewed with Acrobat Reader, the signature will be flagged as invalid and the fact of self-signing is displayed. There used to be 
 &lt;a href="http://www.cacert.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;http://www.cacert.org/&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
, but to my knowledge, all browsers have removed the CAcert certificates and the same is likely true for Acrobat. StartSSL used to give out free certificates, but they do not exist anymore (they were seriously challenged with their own security).&lt;strong&gt;PDF Viewer support&lt;/strong&gt;Interestingly many PDF Viewers do anyway ignore the signing (e.g. the inbuilt PDF viewer from Firefox does not display anything). Other PDF viewers will display the signature, but NOT indicate, that it is not trusted (e.g. the Chrome Browser&amp;rsquo;s PDF viewer and Ubuntu&amp;rsquo;s default PDF viewer Evince). Since you have no idea what viewer your target will use to display your signed PDF, you are anyway in a bad situation (even if you subscribe to a document signing service). &lt;strong&gt;Letsencrypt&lt;/strong&gt;To increase the trust in the signing, one can use a 
 &lt;a href="https://letsencrypt.org/" target="_blank" rel="noopener noreferrer nofollow"&gt;Letsencrypt&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 certificate for signing. This signature certifies that the author of the document controls a specific website (in my case jeltsch.org). That is more than a self-signed certificate (and if the website is trusted, this is arguably also more than buying a subscription from DocuSign), but the re-purposed Letsencrypt certificate is not being trusted by Adobe since obviously the Letsencrypt endeavor was never meant for document signing (&amp;ldquo;Signer&amp;rsquo;s identity is unknown because it has not been included in your list oif trusted certificates and none of its parent certificates are trusted certificats&amp;rdquo;). However, the maximum lifetime of such a certificate is 3 months, after which it becomes invalid. It can still be used, but it will display that it is not valid because it has expired (or is not valid yet).&lt;strong&gt;How to misuse the Letsencrypt certificate&lt;/strong&gt;First, you need a web server, that uses Letsencrypt certificates to verify the web site identity. This is out-of-scope for this blog post, but there are several good tutorials (e.g. from the 
 &lt;a href="https://letsencrypt.org/getting-started/" target="_blank" rel="noopener noreferrer nofollow"&gt;Let’s Encrypt people themselves&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 or from 
 &lt;a href="https://www.digitalocean.com/community/tutorials/how-to-secure-apache-with-let-s-encrypt-on-ubuntu-18-04" target="_blank" rel="noopener noreferrer nofollow"&gt;Digital Ocean&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
). Once you have your Let&amp;rsquo;s Encrypt certificates, this is the process to &amp;ldquo;misuse&amp;rdquo; them for signing documents:Since Letsencrypt requires certificate renewal every three months, there will be lots of fullchain.pem and privkey.pem files in the same directory and they are numbered. You obviously want to use the newest (the only valid) certificate and perhaps you want to renew the Let&amp;rsquo;s Encrypt certificate immediately before exporting it for document signing:&lt;code&gt;certbot --apache --force-renewal -n -d jeltsch.org&lt;/code&gt; or if you want to renew all certificates: &lt;code&gt;certbot --apache --force-renewal&lt;/code&gt; If you choose to renew all certificates, certbot will try to issue a single certificate for all domains that exist on your server (this possibility did not exist in the beginning of the Letsencrypt ecosystem, but was introduced later). If your server serves more than one domain, you need to manually specify the domain name, for which you want the certificate.For more details about how to use the certbot script, see 
 &lt;a href="https://certbot.eff.org/docs/using.html#certbot-commandsThis" target="_blank" rel="noopener noreferrer nofollow"&gt;https://certbot.eff.org/docs/using.html#certbot-commandsThis&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 is the command, that converts the certs into a PKCS#12 file:&lt;code&gt;openssl pkcs12 -export -out signing_certificat.p12 -in /etc/letsencrypt/archive/website-name/fullchain1.pem -inkey /etc/letsencrypt/archive/website-name/privkey1.pem&lt;/code&gt;The PKCS#12 file stores the certificate and the private key in one encrypted file (with the file extension .p12). Therefore, the command will ask from you a keyphrase, which you absolutely need to remember to be able to use the certificate. Then you can transfer the p12 file to your desktop computer and use it to sign PDF files.&lt;strong&gt;Time stamping servers&lt;/strong&gt;If your PDF application asks for a time stamping server, you can use one of the free services, e.g. ca.signFiles.com/TSAServer.aspx or 
 &lt;a href="http://zeitstempel.dfn.de" target="_blank" rel="noopener noreferrer nofollow"&gt;http://zeitstempel.dfn.de&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. However, also these time stamping services are not trusted by Adobe Acrobat.Here the commands to generate a self-signed certificate (it asks for a (temporary) passphrase, just make up something and remember it, you need it in the second step):&lt;code&gt;openssl req -x509 -newkey rsa:4096 -keyout key.pem -out cert.pem -days 3650&lt;/code&gt;Conversion into a signing certificate (it first asks you for the temporary passphrase from above and then for the final passphrase, which you need to remember in order to use the certificate:&lt;code&gt;openssl pkcs12 -export -out signing_certificat.p12 -in cert.pem -inkey key.pem&lt;/code&gt;&lt;/p&gt;</description></item><item><title>Ḿanuscript reviewing by annotating PDFs</title><link>https://jeltsch.org/en/manuscript_reviewing_by_annotating_pdfs/</link><pubDate>Fri, 28 Jun 2019 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/manuscript_reviewing_by_annotating_pdfs/</guid><description>&lt;p&gt;Manuscripts for scientific peer-review are delivered as PDF files. Thus it appears most natural to comment the PDF file itself instead of submitting the comments as a separate text (file). However, many submission systems do not allow to submit comments in form of an annotated PDF file.In addition, there is no easy-to-use free/Open Source PDF editor for Linux (my platform of choice). Yes, there is PDFEdit (
 &lt;a href="http://pdfedit.cz/en/index.html%29" target="_blank" rel="noopener noreferrer nofollow"&gt;http://pdfedit.cz/en/index.html)&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
, but it requires substantial learning and its last release dates back to 2012. There are free online PDF editors (e.g. 
 &lt;a href="https://www.pdfescape.com/%29" target="_blank" rel="noopener noreferrer nofollow"&gt;https://www.pdfescape.com/)&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
, but sometimes I need a local tool. Although not Open Source and not free, the tool of my choice has been 
 &lt;a href="https://www.qoppa.com/pdfstudio/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDF Studio Pro&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. It has all the features I need (actually much more than I need), it is truly cross-platform (Windows, Mac, Linux), easy to use and very affordable for what it offers ($129 single permanent license). Unfortunately, Quoppa software - the maker of PDF Studio - does not offer academic discounts.&lt;strong&gt;PDF Studio Viewer&lt;/strong&gt;A while ago, the makers of PDF Studio started to offer a free version called 
 &lt;a href="https://www.qoppa.com/pdfstudioviewer/download/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDF Studio Viewer&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. This free version has gotten more useful over time. Since last year, it also supports PDF annotation, which is very important for my work, mostly when I am peer-reviewing scientific manuscripts. For many academic users, the PDF Studio Viewer might be fully sufficient.&lt;strong&gt;Libre Office and Inkscape&lt;/strong&gt;Of course Libre Office Draw and Inkscape can edit PDFs, but they are not specialized for annotating. If you need to do extensive annotations, the process becomes soon very painful. In addition, Inkscape editing can be destructive (i.e. when you modify text), but I have used it e.g. to fill out forms.Apart from the lack of dedicated annotation and reviewing tools (&amp;ldquo;markups&amp;rdquo; like &amp;ldquo;replace text&amp;rdquo;, &amp;ldquo;crossout text&amp;rdquo;, &amp;ldquo;delete text&amp;rdquo;, &amp;ldquo;insert text&amp;rdquo; or callouts), Libre Office Draw is actually a quite capable PDF editor, but fails still sometimes to correctly open very complex PDF documents (I have had problems with background images/patterns). Strangely, the only reviewing tool (comments) are not exported by default. You need to check the &amp;ldquo;Export comments&amp;rdquo; box when you export your edited PDF file as PDF (the &amp;ldquo;Save&amp;rdquo; operation creates an ODG file, which you probably don&amp;rsquo;t want).&lt;strong&gt;PDFsam&lt;/strong&gt;If you do not have the need to annotate, then you might get away with the Open Source tool 
 &lt;a href="https://sourceforge.net/projects/pdfsam/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDFsam&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. Unlike PDFEdit, PDFsam is available from the Ubuntu repositories. PDFsam also has two non-free versions (
 &lt;a href="https://pdfsam.org/pdfsam-enhanced/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDFsam Enhanced&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 and 
 &lt;a href="https://pdfsam.org/download-pdfsam-visual/" target="_blank" rel="noopener noreferrer nofollow"&gt;PDFsam Visual&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
). PDFsam Basic (the Open Source version) is just a simple GUI on top of some command line utilities, whereas the PDF Studio Viewer offers a true visual editing experience. I canot talk about the non-free versions of PDFsam as they are not available as free trials. In fact, all of the operations of PDFsam can be achieved via the command line (see here for my blog post about how to perform common PDF editing tasks using mostly the command line tool 
 &lt;a href="https://jeltsch.org/en/pdf/"&gt;pdftk&lt;/a&gt;
).&lt;strong&gt;Reducing file size&lt;/strong&gt;PDFsam Basic and PDF Studio Viewer do not offer any functionality to reduce file size. The LibreOffice Draw PDF export dialog let&amp;rsquo;s you reduce image resolution and JPEG compression, which you can use to reduce file size. But at the Open Source front, the only capable tools to reduce PDF size seem to be command line tools. I use 
 &lt;a href="https://www.ghostscript.com/" target="_blank" rel="noopener noreferrer nofollow"&gt;ghostscript&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
 for this task, but the command is not easy to remember:&lt;code&gt;gs -sDEVICE=pdfwrite -dCompatibilityLevel=1.4 -dPDFSETTINGS=/screen -dNOPAUSE -dQUIET -dBATCH -sOutputFile=output.pdf input.pdf&lt;/code&gt;With PDF Studio Pro, you obviously do not need to remember the different keywords for the different output quality option (screen, ebook, printer, prepress) as you just choose from the drop down menu between the available options. If you are looking for an Open Source graphical wrapper for ghostscript, perhaps try 
 &lt;a href="https://sourceforge.net/projects/workerpdf/" target="_blank" rel="noopener noreferrer nofollow"&gt;workerPdf&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. &lt;strong&gt;Signing documents and adding signatures&lt;/strong&gt;PDF Studio Viewer let&amp;rsquo;s you sign documents if you have a 
 &lt;a href="https://www.docusign.com/products-and-pricing" target="_blank" rel="noopener noreferrer nofollow"&gt;DocuSign subscription&amp;nbsp;






 
 
 
 &lt;svg class="svg-inline--fa fas fa-up-right-from-square fa-2xs" fill="currentColor" aria-hidden="true" role="img" viewBox="0 0 512 512" overflow="visible"&gt;&lt;use href="#fas-up-right-from-square"&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/a&gt;
. However, I am mostly concerned about being able to prove myself that I created a certain document (&amp;ldquo;self-signed signature&amp;rdquo;) and not that others are able to verify my authorship. For this scenario you are out of luck with PDF Studio Viewer. And apparently, PDFSam does not offer any possibility for signing (neither self-signing nor 3rd party signing). However, Libre Office Draw allows documents signing! I have been looking for an affordable solution (not self-signed, but trusted by other PDF readers) to sign PDF documents, but there seems to be no appropriate solution if you need to sign only rarely. The basic plan by DocuSign ($10/month) appears too expensive when signing only one document per month.&lt;strong&gt;Take-home message&lt;/strong&gt;If you want to stay with free or Open Source solutions, you probably need to combine several tools in order to cover all typical PDF editing tasks without pain: PDFsam Basic, LibreOffice Draw, PDF Studio Viewer and ghostscript. But if you edit PDFs often (as I do), buying PDF Studio Pro is clearly the way to go.&lt;/p&gt;</description></item><item><title>Adobe Acrobat 5.0.5 under wine</title><link>https://jeltsch.org/en/adobe_acrobat_5_0_5_under_wine/</link><pubDate>Wed, 23 May 2007 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/adobe_acrobat_5_0_5_under_wine/</guid><description>&lt;p&gt;I reinstalled Acrobat 5 to run it under wine. It didn&amp;rsquo;t work. The reason appeared to be again a plugin: DocBox.api. After removing it everything went smoothly. Already before (using RedHat 9) I have had trouble with a Acrobat plugin (it was WebPDF.api at that time). Most manipulation of pdf files can be easily done with Linux tools, but one thing is tricky: cropping already existing pdf files. That&amp;rsquo;s why I need Acrobat.&lt;/p&gt;</description></item><item><title>Wine and Adobe Illustrator (can't find AIRes.dll)</title><link>https://jeltsch.org/en/wine_and_adobe_illustrator_can_t_find_aires_dll/</link><pubDate>Mon, 21 May 2007 00:00:00 +0000</pubDate><guid>https://jeltsch.org/en/wine_and_adobe_illustrator_can_t_find_aires_dll/</guid><description>&lt;p&gt;Adobe Illustrator didn&amp;rsquo;t want to start up under wine, because it couldn&amp;rsquo;t find the file AI90Res.dll. This file is located after the Illustrator install in:&lt;code&gt;~/.cxoffice/dotwine/fake_windows/Program Files/Adobe/Illustrator 10/Support Files/Contents/Windows/System&lt;/code&gt;I just moved it up one directory and everything started working.&lt;/p&gt;</description></item></channel></rss>