Open a .p7m file: the document inside and who signed it
A .p7m is a document wrapped in a digital signature: an e-invoice from the Italian exchange system, a contract signed with a smart card, a document sent by certified e-mail (PEC). Drop it here to get the PDF, XML or Word file out, see who signed it and when, and check that the content still matches what was signed.
The file is read on your device. It is not uploaded, and no server is asked about it.
What it shows
- The document inside, saved under the .p7m's name without the .p7m (
contratto.pdf.p7mgivescontratto.pdf), or opened right here in viewhack's matching viewer: PDF, Word, Excel, pictures, ZIP and the rest. Its real type is read from its bytes, so a file named only.p7mstill gets the right extension. - Who signed it. For each signature: the signer's name, organisation, and the tax code or ID number from the certificate (Italian signing certificates carry the codice fiscale as
TINIT-followed by the 16 characters), who issued the certificate and the dates it is valid, the signing time the signer's software wrote, and the digest algorithm. - Whether the content still matches. The document's hash is computed again on your device and compared with the hash inside the signature, in a plain sentence: it matches, or it does NOT. The signature over that hash is checked with the public key in the signer's certificate, and so is the attribute that names that certificate.
- The signature level. CAdES-BES (a basic signature with the signing certificate bound into it), CAdES-T (with a timestamp from a timestamp authority, whose time and name are shown and whose hash is checked against the signature), or a plain PKCS#7 signature without CAdES attributes. Later levels (CAdES-C, -X-L, -A) are named when their attributes are there.
- Signed twice or more. A
.p7m.p7m(a signed file signed again, for example by a second person) is unwrapped layer by layer, up to 8 layers, and each layer's signers are listed, outermost first. - An Italian e-invoice inside (FatturaPA XML) is laid out as an invoice: supplier and customer with VAT number, tax code and address, document type, number and date, every line with quantity, unit price, VAT rate and total, the VAT summary, the total, payment terms with due date and IBAN, and the attachments (Allegati) to save or open. "Save as text" writes the same summary as a plain .txt file.
What a .p7m is, and why it will not open
A .p7m file is a CMS (PKCS#7) "SignedData" structure in which the signed file itself is stored. Its first bytes are always 30 80 or 30 82 (an ASN.1 sequence) followed by the object identifier 1.2.840.113549.1.7.2, "signed data". Inside come the hash algorithm, the document, the signer's certificate and one signer block per signature. Programs that open PDFs or XML see none of that: to them the file is unknown binary, which is why double-clicking it does nothing useful.
In Italy the format is everywhere. Electronic invoices between businesses, and to the public administration, go through the Agenzia delle Entrate's exchange system (SdI) as FatturaPA XML files, and a signed one arrives as IT01234567890_00001.xml.p7m. Contracts, tenders and documents for the land registry or the chamber of commerce are signed with a smart card or a remote-signature service in the CAdES format (ETSI EN 319 122), which is a .p7m. The PEC system delivers them as attachments, and some mail programs save them as base64 text instead of binary; that opens here too.
A worked example, from viewhack's own test: a 599-byte one-page PDF signed with a throwaway 2,048-bit RSA certificate and SHA-256 becomes a 2,453-byte .p7m. Besides the PDF it holds the signer's certificate (1,102 bytes), the signed attributes (content type, signing time, the PDF's 32-byte SHA-256 hash and the certificate's own hash) and the 256-byte signature over those attributes. Change one byte of the PDF inside and its SHA-256 no longer equals the one in the signed attributes: this page then says the content does NOT match, although the signature over the attributes still verifies, because the attributes themselves were not touched.
Files it opens
- .p7m (binary)
- DER or BER CMS signed data with the document inside, including documents stored in many pieces (a constructed OCTET STRING, as some signing tools write large files).
- .p7m (text)
- The same as base64 text (starting
MII), as several mail programs save it, or between-----BEGIN PKCS7-----lines. - .p7m.p7m
- Nested signatures: a signed file signed again. Each layer is listed.
- Not here
- A .p7s is a detached signature: it holds the signer and the certificates but not the document, which travels as a separate file. It opens in the certificate viewer, as do .p7b certificate bundles.
What this cannot do
- No trust-list check. Whether the certificate was issued by a qualified provider on the EU trusted lists (for Italy, those AgID supervises) needs those lists from the network. This page does not fetch them, so a certificate someone made at home passes every check here. The issuer's name is shown so you can judge it.
- No revocation check. Whether the certificate was revoked or suspended before the signing time is answered by the issuer's OCSP service or CRL, which this page does not contact.
- The signing time is a claim. Without a timestamp, the signing time is what the signer's computer said. With one (CAdES-T), the timestamp authority's time is shown, but its own certificate is not checked against a trust list either.
- It does not sign anything, and it does not remove or add signatures: the document you download is the original bytes, without a signature.
- Hashes WebCrypto lacks (SHA-224, SHA-3, MD5) are named but not computed; SHA-1, SHA-256, SHA-384 and SHA-512 are. RSA, RSA-PSS and ECDSA on P-256, P-384 and P-521 signatures are checked; other algorithms are named.
- Not .p7s, .m7m or .tsd. A detached .p7s goes to the certificate viewer. An .m7m (a .p7m and its timestamp packed together in a MIME file) and a .tsd (RFC 5544 time-stamped data) are not unpacked here.
- Invoices are read, not validated. The FatturaPA layout shows what the XML says; it does not check the file against the schema or recompute the arithmetic, and the simplified invoice (FSM10) gets the parties, number, date and lines only.