Verify ASiC

ASiC container signature verification

Validate the digital signatures bundled inside your .asice and .asics containers. Drop in a signed ASiC file and Chaindoc unpacks it, then checks each inner XAdES or CAdES signature, the certificate chain, container timestamps, and eIDAS compliance with the EU DSS library.

VERIFY .asice

Verify ASiC Container

Upload a signed .asice or .asics container to validate the ASiC-S / ASiC-E signatures packed inside it using EU DSS verification standards.

We'll send a verification code to confirm your identity.

What the container check includes

  • Free ASiC & eIDAS container validation
  • Every inner signature checked, one by one
  • Detailed report ready in seconds
  • Your file is never stored
Validate in Chaindoc

The container you upload is never stored. Its verification report is kept privately for 7 days, then deleted, and after that only a minimal record (result, signature count, date) stays in your account.

EU DSS compliant

What ASiC verification checks

An ASiC container is a ZIP package defined by ETSI EN 319 162 that carries your signed files together with their signatures. Chaindoc runs the whole container through the EU Digital Signature Service (DSS) library and checks it against these rules.

Unzips the ASiC package and reads the META-INF manifest that ties each signature to the file it covers. Swap a file or tamper with the manifest and the check catches it.

One container can hold several signatures over several files, and the report returns a separate verdict for each. Every inner signature is a XAdES or CAdES signature and is validated as such.

Traces each signer's certificate back to a trusted root and checks whether it was revoked, using CRL and OCSP responders. See how trust is established under eIDAS across all signature formats.

Reads container and signature timestamps, then confirms whether the signature meets eIDAS rules and the ETSI EN 319 162 profile for ASiC containers.

Beyond verification

Signed containers auditors trust

Create signatures as rigorous as the ones you verify. Chaindoc signs, timestamps and anchors every agreement on chain, and a free esignature account covers your first documents — no card required.

Container types

ASiC-S and ASiC-E containers

ASiC (Associated Signature Containers) is defined by ETSI EN 319 162. It's a ZIP-based package that carries the signed files together with their signatures, so everything you need to validate travels in one file.

ASiC-S (Simple)

One data file plus one signature or timestamp token. Extensions are .asics and .scs. Handy when you're timestamping or signing a single document and want a tidy, self-contained package.

ASiC-E (Extended)

Several data files, several signatures, and a META-INF manifest. Extensions are .asice and .sce. This is the eIDAS e-delivery container and the format behind most national ID-card signing.

XAdES or CAdES inside

ASiC is only the wrapper. The signatures within are either XAdES over XML or CAdES over binary CMS, and Chaindoc validates whichever it finds.

BDOC and DigiDoc files

Estonia's .bdoc is an ASiC-E container under the hood. Rename it to .asice or .zip if the upload refuses the extension, and the DSS engine validates it the same way, along with the DigiDoc4 packages used across the Baltic eID ecosystem.

FAQ

Common questions about ASiC container verification

What ASiC is, how the check runs, and what the result means. More on our support page.

ASiC stands for Associated Signature Containers, an ETSI standard (EN 319 162). It's a ZIP file with a specific layout: your signed documents sit next to their signatures and, for ASiC-E, a META-INF manifest that maps one to the other. Because the originals live inside the zip, an ASiC container validates on its own, with no separate file needed.

Size of the job, basically. ASiC-S (Simple) wraps a single data object with one signature or timestamp and uses the .asics or .scs extension. ASiC-E (Extended) can hold many files, many signatures, and a manifest tying them together, and uses .asice or .sce. ASiC-E is the one you meet in eIDAS e-delivery and government portals.

Yes. The .asice files from Estonia's ID-card, e-Residency, Smart-ID, and DigiDoc4 apps are ASiC-E containers, and this tool reads them directly. A .bdoc file is the same thing under an older name, so the validator handles it identically once it arrives, but the upload filter matches on extension: rename a .bdoc to .asice or .zip if the form refuses it. Latvian and Lithuanian eID signatures built on the DigiDoc stack work the same way.

Either. ASiC is just the container. Inside, the actual signatures are XAdES (XML-based) or CAdES (binary CMS), and one container can even mix them. Chaindoc opens the package and validates whatever it finds. Signing a plain PDF instead? That's PAdES, and the PDF signature verification tool handles those.

The usual reasons plus a container-specific one. A file inside was edited after signing so its digest no longer matches, a signer's certificate expired or was revoked, or the chain doesn't reach a trusted root. The container-specific case is a broken or missing META-INF manifest, which severs the link between a signature and the file it should cover. The report points at the exact signature and check that failed. Validating containers at scale? See pricing and our API integration.

Guides and resources

ASiC containers and digital signature guides

How ASiC-E, ASiC-S, and the XAdES and CAdES signatures inside them keep signed files verifiable and eIDAS-ready.