Notice

rFirma is not an official product of the Public Administration. It's an independent open-source project under the EUPL 1.2 licence.

Alternative to AutoFirma

Native electronic signature.
No Java, no waiting.

Desktop application in Rust and React that replaces AutoFirma's Swing interface and local servers, with the Administration's official cryptography.

  • Open source, EUPL 1.2
  • The private key never leaves your computer
  • CAdES, PAdES, XAdES and FacturaE
  • In five languages
rFirma — Solicitud-subvencion.pdf
rFirma main window: document viewer, visible signature placement and side signature panel
CertificateADA LOVELACE BYRONAC FNMT Usuarios
StageAssembling
Visible signaturePlaced on page 3
PAdES · 2 signatures
CAdESPAdESXAdESFacturaEPKCS#11
Step by step

How a document gets signed

01

Document loaded

rFirma opens the PDF and shows what it contains: pages, size and the signatures it already carries. If there's an earlier one, yours will be a co-signature.

02

Choose certificate

The list is built from the system stores, the browser profiles and the PKCS#11 modules. Expired and revoked ones are shown, but can't be used.

03

Enter the PIN

The PIN is requested in a native dialogue, not a web window, and is wiped from memory as soon as the signature is done.

04

Signature complete

The signed PDF is saved next to the original, and the summary shows its format.

rFirma with a PDF open that already carries a valid signature
Why rFirma

Four design decisions

It replaces AutoFirma's Swing interface and local servers; the cryptographic engine is the same one, from clienteafirma.

Native performance

Desktop app in Tauri v2, Rust and React. No JVM and no local servers listening.

The private key never leaves the system

Signing happens on your computer, through the system stores and the PKCS#11 modules. Java never sees it.

Official cryptography

CAdES, PAdES, XAdES and FacturaE come from the clienteafirma code, compiled to a native binary with GraalVM.

Draggable visible signature

Place and size the rubric on the page, with a faithful preview. No blind coordinates.

Comparison

AutoFirma versus rFirma

AspectAutoFirma (official)rFirma
ArchitectureJava Swing on the JVMTauri v2 (Rust + React) with the clienteafirma engine on GraalVM Native Image
Where the private key is processedIn the Java processIn the system store or the PKCS#11 module; it never leaves it
PIN protection in memoryOnly partly wiped, and it can end up on diskProtected in memory, never written to disk and wiped after use
Signing with a Spanish DNIeYes, via jMulticardIn development
Certificates in a file (.p12)The file's path is registered in a store dialogue with six optionsIts own encrypted store, unlocked with your session
Certificate lookupOnly searches the store you pickAll in one searchable list, one certificate per row
Visible signature placementCoordinates or a box with no contextDrag it onto the page, with text templates and a faithful preview
Browser trust in the local serverThe installer registers the CA on the system, with privilegesThe application registers its CA in the person's NSS stores, without root
LanguagesSpanish only, with the Swing dialogue stringsSpanish, Catalan, Basque, Galician and English, with its own catalogue and switching from Preferences
Document manager—Remembers recent documents and the last certificate used
Operating systemsWindows, macOS, Linux, Android and iOSLinux and Windows; macOS, in development
Update channelManual download of a .deb or .rpmNative repositories: APT, DNF and Flatpak; on Windows, from the app itself
Desktop integrationSwing's own lookFollows the desktop's style, with light and dark themes
Installation

One repository for your operating system

rFirma's channels are native repositories. Once your system's is added, security patches install through the package manager.

For Debian, Ubuntu and derived distributions. Sets up the repository using the modern deb822 format with the GPG key verified in /usr/share/keyrings/.

curl -fsSL https://rfirma.sgomez.me/rfirma.asc | sudo tee /usr/share/keyrings/rfirma.asc >/dev/null
sudo tee /etc/apt/sources.list.d/rfirma.sources <<'EOF'
Types: deb
URIs: https://rfirma.sgomez.me/apt/
Suites: stable
Components: main
Signed-By: /usr/share/keyrings/rfirma.asc
EOF
sudo apt update && sudo apt install rfirma
Transparency

All the code, in the open

rFirma is free, auditable software under the EUPL 1.2 licence. The code and the cryptographic engine live in two public repositories.

Application and FFI bridge

sgomez/rfirma holds the Tauri interface (Rust + React), the FFI bridge (rfirma-native-bridge) and the packaging.

Original cryptographic engine

The signing logic consumes the artefacts from ctt-gob-es/clienteafirma, compiled into a native library with GraalVM Native Image.

Package signing key

Public key at rfirma.asc. Check its fingerprint after downloading it with gpg --show-keys rfirma.asc:

C8D6 A81C 1ED4 3A28 D426  8112 A6E0 EE02 2344 6A16