Part II — FES & Facsimile

Trigger S3/S4: An external contracting party requires an advanced electronic signature; the signature is to appear as a positioned graphic in the PDF layer (DocuSign-style).

Overview of the Articles (DS06–DS11)

Art. Title (DE) Core question
DS06 eIDAS basics: simple, advanced, qualified eS What levels are there, and when is which sufficient?
DS07 The Facsimile method: positioned graphic in the PDF layer How does the signature graphic get to the right place in the PDF?
DS08 Signature plate and hash anchoring How does the graphic become a provable signature declaration?
DS09 The FES envelope report How do we document a DocuSign-style process repo-natively?
DS10 The FES container package (gcpn.zip) How do you physically deliver the entire signature chain?
DS11 Connecting external partners: Gitea, GitCover.IdP, API/MCP How does the small entrepreneur scale access to permissions and evidence for partners (customers, clients, co-workers)?

The Levels of Electronic Signature

einfache eS ────► FES/ADES ────► QES
   │                 │             │
Grafik/E-Mail    Signaturplatte   Zertifikat der
(Facsimile)      + Kryptobindung  EU-Trust-Liste
   │                 │             │
"Textform"        "fortgeschritten" "qualifiziert"
(GCBoK Teil I)    (Teil II)        (extern, § 126a BGB)

Part I ended with text form — the graphic is a simple eS. Part II attaches the FES: The signature graphic (Facsimile) is positioned in a PDF layer and anchored with a signature plate (certificate hash, timestamp, signing role) — DocuSign-style, but documented repo-natively.

The Role of the Repo Remains

In Part II, too, the following applies: The repo is the evidence layer. The FES service (or your own PDF signature software) generates the signed PDF; the repo documents:

  1. The FES envelope report (who was prompted to sign, when it was signed, with which certificate hash) — DS09
  2. The physical version (signed PDF) in the container package — DS10
  3. The link to the text form container from Part I (same source document SHA, extended chain)

Reading Order

  1. DS06 — eIDAS levels and their evidentiary value (AdES, AdEE, QES).
  2. DS07 — The Facsimile method: PNG/SVG, positioning, height=40.
  3. DS08 — Signature plate: certificate, hash, timestamp, roles.
  4. DS09 — The envelope report: DocuSign-style process documentation in the repo.
  5. DS10 — The container package: *.gcpn.zip as a deliverable verification set.
  6. DS11 — Connecting external partners: the three scaling levels (offline package → Gitea via the internet → GitCover.IdP/API/MCP).

Next: Part III — GCPN container schema (research gain from the first process: JSON schema gcpn-container-1.0).


Created: 260913 | Part II of the digital-signage series