viewhack

Open a .p7m file: the document inside and who signed it

A .p7m is a document wrapped in a digital signature: an e-invoice from the Italian exchange system, a contract signed with a smart card, a document sent by certified e-mail (PEC). Drop it here to get the PDF, XML or Word file out, see who signed it and when, and check that the content still matches what was signed.

The file is read on your device. It is not uploaded, and no server is asked about it.

What it shows

What a .p7m is, and why it will not open

A .p7m file is a CMS (PKCS#7) "SignedData" structure in which the signed file itself is stored. Its first bytes are always 30 80 or 30 82 (an ASN.1 sequence) followed by the object identifier 1.2.840.113549.1.7.2, "signed data". Inside come the hash algorithm, the document, the signer's certificate and one signer block per signature. Programs that open PDFs or XML see none of that: to them the file is unknown binary, which is why double-clicking it does nothing useful.

In Italy the format is everywhere. Electronic invoices between businesses, and to the public administration, go through the Agenzia delle Entrate's exchange system (SdI) as FatturaPA XML files, and a signed one arrives as IT01234567890_00001.xml.p7m. Contracts, tenders and documents for the land registry or the chamber of commerce are signed with a smart card or a remote-signature service in the CAdES format (ETSI EN 319 122), which is a .p7m. The PEC system delivers them as attachments, and some mail programs save them as base64 text instead of binary; that opens here too.

A worked example, from viewhack's own test: a 599-byte one-page PDF signed with a throwaway 2,048-bit RSA certificate and SHA-256 becomes a 2,453-byte .p7m. Besides the PDF it holds the signer's certificate (1,102 bytes), the signed attributes (content type, signing time, the PDF's 32-byte SHA-256 hash and the certificate's own hash) and the 256-byte signature over those attributes. Change one byte of the PDF inside and its SHA-256 no longer equals the one in the signed attributes: this page then says the content does NOT match, although the signature over the attributes still verifies, because the attributes themselves were not touched.

Files it opens

.p7m (binary)
DER or BER CMS signed data with the document inside, including documents stored in many pieces (a constructed OCTET STRING, as some signing tools write large files).
.p7m (text)
The same as base64 text (starting MII), as several mail programs save it, or between -----BEGIN PKCS7----- lines.
.p7m.p7m
Nested signatures: a signed file signed again. Each layer is listed.
Not here
A .p7s is a detached signature: it holds the signer and the certificates but not the document, which travels as a separate file. It opens in the certificate viewer, as do .p7b certificate bundles.

What this cannot do