Security

Why Adobe says “Signature validity is unknown”, and how to fix it

“Signature validity is unknown” almost always means Adobe could confirm the document has not changed, but could not confirm who signed it, because the signer's certificate does not lead to an authority on Adobe's trust list. It is a question about the signer's identity, not proof of tampering, and the fix is to establish trust in the issuer deliberately, not to click anything that makes the warning go away.

7 min read

You open a signed PDF in Adobe Acrobat or Reader and, instead of a reassuring green tick, a yellow bar says "At least one signature has problems." Click the signature and it says "Signature validity is UNKNOWN." The signature itself may show a yellow warning triangle or a question mark.

It looks alarming. Most of the time it is not.

The short answer

When Adobe validates a signature, it checks several things. The two that matter here are:

  1. Has the document changed since it was signed?
  2. Can the signer's identity be traced to an authority Adobe trusts?

"Validity unknown" usually means the first answer is no, it has not changed: but the second answer is Adobe doesn't know. The signer's certificate was issued by an authority that is not on Adobe's trust lists and that you have not told Adobe to trust yourself.

It is Adobe saying "I can't vouch for who this is", not "this is fake".

Why Adobe doesn't recognise the issuer

Adobe trusts certificates that lead back to authorities on the lists it is set up to use: mainly its own Adobe Approved Trust List (AATL) and, for European signatures, the EU Trusted Lists. Many perfectly legitimate certificates are on neither:

  • National government PKIs. Several countries run their own root authority for official signatures, and not all of those roots are on Adobe's lists. Government-signed documents from those countries routinely show "validity unknown" in a fresh install of Reader.
  • Company certificates. Many organisations issue certificates to their own staff from an in-house authority.
  • Self-signed certificates. Made by the signer themselves in a minute. Nobody else vouches for them.
  • Signatures made by e-signature services and apps whose certificate authority is not one Adobe includes.

There is one more cause worth knowing: if the certificate has expired or been revoked, and the signature carries no trusted timestamp, Adobe may also be unable to reach a firm answer.

Step 1: confirm the document has not changed

Before touching any settings, make sure you are dealing with an identity question and not an integrity one.

  • In Adobe, open the Signature Panel and expand the signature. Look for a line saying the document has not been modified since the signature was applied. If instead it says the document has been altered or corrupted since the signature was applied, stop. That is a different, more serious problem.
  • Or check it independently in Verify PDF Signature. The Signature row reports Valid or Invalid on its own, separate from trust, and the result lists anything added to the file after signing.

If the signature is intact, you only have an identity question left.

Step 2: find out who issued the certificate

Your decision to trust a signature should rest on who issued the signer's certificate, not on the fact that a warning is annoying.

  • In Adobe: open the signature's properties and choose Show Signer's Certificate. The chain on the left shows the signer at the bottom and the issuing authorities above.
  • In Verify PDF Signature: open Certificate details. It shows who the certificate was issued to, who issued it, the validity dates, what it may be used for, its SHA-256 fingerprint and the full Certificate chain up to the root.

Ask yourself: is this the authority I would expect? A government letter should chain to that country's official root. A bank's statement should chain to a recognised commercial authority or the bank's own. A contract from a colleague signed with a self-signed certificate called "John Smith" proves nothing about John Smith.

Step 3: establish trust: the right way

If the issuing authority is genuinely one you should trust, you can tell Adobe so. The usual route in Acrobat or Reader:

  1. Right-click the signature (or open it in the Signature Panel) and choose Show Signature Properties.
  2. Click Show Signer's Certificate.
  3. In the certificate viewer, select the root certificate at the top of the chain: not the signer's own certificate at the bottom.
  4. Open the Trust tab and click Add to Trusted Certificates.
  5. Tick Use this certificate as a trusted root, confirm with OK, and close the windows.
  6. Back in the signature properties, click Validate Signature.

Adobe's menus shift a little between versions, so the exact wording may differ slightly on your screen.

A big caution about this step

Trusting the root means trusting every certificate it has ever issued, on this computer, from now on. So:

  • Only trust a root you have identified independently. The ideal is to obtain the official root certificate from the issuing authority itself and compare its fingerprint with the one in the chain. If they match, trust it.
  • Never trust a self-signed signer certificate just to turn a warning green. You would be telling Adobe to accept that person's own word for who they are, which is precisely what the warning is protecting you from.
  • Remember it is local. Adding trust fixes the display on your computer only. Anyone else who opens the file sees the original warning.

Step 4: check Adobe's own trust-list settings

Adobe updates its trust lists from the internet. If they are switched off or out of date, signatures that *should* validate may not. In Preferences → Trust Manager, check that automatic updates of the Adobe Approved Trust List and the European Union Trusted Lists are enabled, and use the update option to refresh them. In managed workplaces, IT may control these settings.

What if the warning is about time?

Sometimes validity is unknown because the certificate has since expired, and Adobe is checking at today's date. A signature with a trusted timestamp can be validated at the time it was made instead. That is a separate subject with its own fix. See What is LTV, and why does my signed PDF say the certificate expired?

The fix is not always on your side

If you are the sender, and your recipients keep seeing "validity unknown", the lasting fix is to sign with a certificate from an authority your recipients' software already trusts. For Adobe users, a member of the AATL; for European recipients, a provider on the EU Trusted Lists. No setting on the recipient's side can make an unknown self-signed certificate trustworthy for everyone.

What our checker reports alongside Adobe

Verify PDF Signature deliberately never collapses its answer into one tick. Integrity (Signature), the certificate's own validity, the Certificate chain, Revocation, Trust and Timestamp are separate rows, because "the document is intact" and "someone you rely on vouches for the signer" are different facts. A result of Signature: Valid with Trust: Not trusted is the same situation as Adobe's "validity unknown", and it is common and often perfectly fine, for example with a company's own certificates.

Whether Adobe itself shows a green tick depends on Adobe's own lists and settings on the computer opening the file, so only Acrobat or Reader can say for certain what it will display.

Common questions

Does “Signature validity is unknown” mean the PDF is fake?

Usually not. It normally means Adobe confirmed the document has not changed but could not trace the signer's certificate to an authority it trusts. Check the Signature Panel: if it says the document has not been modified since signing, the only open question is the signer's identity.

How do I make Adobe show a green tick?

Either the signer's certificate must come from an authority on Adobe's trust lists, or you must add the issuing root to your trusted certificates (Show Signer's Certificate → select the root → Trust → Add to Trusted Certificates → Use this certificate as a trusted root) and then validate again. Only do the second if you have independently confirmed that root is genuine.

Why does a government PDF from my own country show validity unknown?

Some national government root authorities are not on Adobe's trust lists, so a fresh installation of Reader does not recognise them. The signature can still be valid. Obtain the official root certificate from the issuing authority, compare its fingerprint and trust it, or use the official validator that country provides.

If I trust the certificate, will other people see a green tick too?

No. Trust settings are stored on your computer only. Everyone else sees whatever their own Adobe settings produce.

What is the difference between “validity unknown” and “invalid”?

Unknown means the identity could not be confirmed. Invalid means something is actually wrong. Most often the document changed after signing, or the certificate was revoked. Invalid is the one to take seriously.

Is it safe to trust a self-signed certificate?

Only if you personally know it belongs to the signer. For example they told you its fingerprint through another channel. A self-signed certificate is the signer vouching for themselves, so trusting it blindly defeats the purpose of the check.

Can KovaPDF tell me whether Adobe will show a green tick?

Not with certainty. That depends on Adobe's own trust lists and on the settings of the computer opening the file. KovaPDF reports the facts it can check itself (integrity, certificate, chain, revocation, timestamp) each on its own line.