Why a PDF Signature Shows “Validity Unknown” and How to Fix It
When Adobe Acrobat Reader says a signature’s validity is unknown, it usually means the reader could not confirm that it trusts the certificate that made the signature. It does not by itself mean the document was changed.
The three results in Adobe Acrobat Reader
- Green tick — “Signed and all signatures are valid.” The document has not changed since signing, and the signer’s certificate chains to a certificate the reader trusts.
- Yellow warning — “At least one signature has problems.” Often shown as signature validity is unknown: the reader could not verify the signer’s identity with its trust settings.
- Red cross — “At least one signature is invalid.” For example the document was changed after signing, or the certificate is no longer valid.
Acrobat reports whether the document was modified after signing separately from whether it trusts the certificate. Open the signature panel or Signature Properties to see both.
Why “validity unknown” happens
- Acrobat and Reader keep their own list of trusted certificates, separate from Windows. Out of the box they trust certificates through Adobe’s programs, such as the Adobe Approved Trust List (AATL).
- If the root certificate of your certificate authority is not trusted in that reader, the signature cannot be verified there, even though it is correctly made. Whether your authority’s root is trusted depends on the authority, so check it in your reader.
- Every reader decides trust with its own settings, so the same file can be trusted on one computer and unknown on another.
Fix it on the computer that opens the PDF
Option 1 — trust your certificate authority’s root certificate
- Get the root certificate from your certificate authority (the company that issued your DSC). Only trust a certificate you obtained from its issuer.
- In Acrobat or Reader open Preferences → Signatures → Identities & Trusted Certificates → More and select Trusted Certificates.
- Import the root certificate and use Edit Trust to trust it for signatures.
- Close and reopen the PDF.
Option 2 — let Adobe use the Windows certificate store
- Open Preferences → Signatures, then under Verification click More.
- Under Windows Integration, tick Trust ALL root certificates in the Windows Certificate Store for: Validating Signatures.
- Click OK, then close and reopen Acrobat or Reader.
This is off by default, and Adobe’s own dialog warns: “Selecting either of these options may result in arbitrary material being treated as trusted content. Take care before enabling these features.” It only helps if your authority’s root is in the Windows Trusted Root Certification Authorities store. Option 1 trusts only the certificate you choose.
What the signer can do
- Dragdox includes the certificate chain from your token or PFX file in every signature, so readers can build the chain to your authority’s root.
- With Premium LTV, Dragdox also embeds certificate revocation lists (CRLs) when they can be downloaded, and adds a trusted timestamp.
- No signing software can change the trust settings on someone else’s computer. If recipients see “validity unknown”, share this page with them.
- The Green Tick option in Dragdox is part of the signature’s look. It is drawn on the page and is not the reader’s verification result.
