Security

How to verify a DSC-signed PDF in India (GST, MCA, income-tax documents and e-Aadhaar)

Indian DSCs chain up to the Root Certifying Authority of India run by the Controller of Certifying Authorities (CCA). Many computers do not trust that root by default, so Adobe often shows “validity unknown” even when the signature is intact. Check that the signature is valid and nothing changed after signing, confirm the certificate chains to a licensed Indian CA and the CCA root, and only then add the root to your trusted certificates.

6 min read

India uses digital signatures on a very large scale. Company filings, audit reports, income-tax documents, tender bids, GST returns, e-stamped agreements, Form 16 certificates and the e-Aadhaar all rely on them. So "how do I verify this signature?" is one of the most common PDF questions in the country, usually asked by someone looking at a yellow question mark in Adobe Reader.

The short answer

  • A Digital Signature Certificate (DSC) in India is issued by a Certifying Authority (CA) licensed by the Controller of Certifying Authorities (CCA) under the Information Technology Act, 2000.
  • Every licensed CA's certificate chains up to the Root Certifying Authority of India (RCAI), operated by the CCA.
  • If your computer does not trust that root, Adobe shows "Signature validity is unknown": even when the document is intact and the signature is genuine.
  • Verify in this order: integrity first, then the chain, then trust.

Step 1: check the signature is intact

Upload the PDF, exactly as downloaded, to Verify PDF Signature. Look for:

  • Signature: Valid and a verdict of Unchanged since [name] signed it.
  • No changes after signing: or, if there are, what they are. For filings and certificates, a page-content change after signing is a serious warning sign.

This part does not depend on trust settings at all: if the signature is valid, the signed content has not changed since the DSC holder signed it.

Step 2: check who issued the certificate

Open Certificate details and look at the Certificate chain. For a genuine Indian DSC you should see:

  • At the bottom: the signer. An individual, or for organisational signatures the organisation's authorised signatory.
  • In the middle: one or more certificates of a licensed Indian CA.
  • At the top: a CCA India root certificate. The CCA has issued new roots over the years, so the name includes a year.

If the chain does not reach a CCA India root, or the certificate is self-signed, it is not a DSC issued under the IT Act. Whatever name it carries.

Also useful:

  • Issued to: name, organisation, and sometimes state or a partial identifier.
  • Key usage: should include digital signature and usually non-repudiation.
  • Valid from / until: DSCs typically last one to three years. An expired certificate does not invalidate a signature made while it was valid, especially with a trusted timestamp. See What is LTV, and why does my signed PDF say the certificate expired?

Our Trust row may say Not trusted. That describes this service's list of roots, not the validity of Indian DSCs.

Step 3: make Adobe recognise it (safely)

To make the question mark turn green in Adobe Reader, you tell Adobe to trust the Indian root:

  1. Right-click the signature and choose Show Signature Properties.
  2. Click Show Signer's Certificate.
  3. Select the top certificate in the chain. The CCA India root.
  4. Open the Trust tab and click Add to Trusted Certificates.
  5. Tick Use this certificate as a trusted root and click OK.
  6. Close the windows and click Validate Signature.

Safety first: trust the root only after confirming it really is the CCA India root. The CCA publishes its root certificates on its official website; compare the SHA-256 fingerprint of the root in your chain with the published one. Never trust a certificate just because a PDF told you to.

e-Aadhaar: the most common case

The e-Aadhaar PDF downloaded from UIDAI is digitally signed by UIDAI and is password-protected (the password format is explained on the download page). It is meant to be as valid as the physical Aadhaar letter.

When you open it in Adobe Reader, the signature typically shows validity unknown, and many banks and offices ask for it to be "validated". The steps are the same as above: open the signature properties, show the signer's certificate, trust the root, validate. After that, Adobe shows a green tick on your computer.

Do not remove the password to check it. Unlocking tools rewrite the file, and a rewritten file loses its digital signature. If a checker cannot open a password-protected file, check it in Adobe Reader instead.

Form 16, TDS certificates and other income-tax documents

Form 16 and other TDS certificates downloaded through TRACES are usually signed by the deductor with their DSC. The same approach applies: integrity, chain to a licensed CA and the CCA root, then trust if needed. The verdict should be Unchanged since [deductor's signatory] signed it. A Form 16 that has been edited (a salary figure changed, a PAN corrected in an editor) will show as changed after signing, or the signature will be broken.

GST: returns, certificates and e-invoices

  • GST registration certificates and other documents downloaded from the GST portal may be digitally signed; check them the same way.
  • GST e-invoices are different: the legally relevant signature is on the QR code, signed by the Invoice Registration Portal. Verify it with the official e-Invoice QR Code Verifier app listed on the GST portal, not with a PDF checker. See How to verify a signed e-invoice.

MCA filings and company documents

Company forms and attachments filed with the Ministry of Corporate Affairs are signed with the DSCs of directors and professionals, and the portal checks those signatures when you file. Certified copies and approval letters downloaded from the portal may carry a digital signature too. For due diligence on a company document someone sends you, check the signature and changes as above, and confirm the underlying record on the MCA portal yourself.

Class 2, Class 3 and DGFT certificates

Since 1 January 2021, CAs have issued Class 3 certificates for individuals in place of the old Class 2, following CCA guidelines. You may still see older Class 2 certificates on documents signed before their expiry; they were valid when used. Some certificates also serve particular uses (signing, encryption, or both) and the key usage fields show which.

Aadhaar eSign

Documents signed with Aadhaar eSign (the online signing service where you authenticate with an OTP) carry a signature from a certificate issued on the fly by an eSign service provider, which is itself a licensed CA. They are verified the same way: integrity first, then the chain to the CCA root.

Common questions

Why does my e-Aadhaar show “validity unknown”?

Because Adobe Reader on your computer does not trust the Indian root authority by default. The signature can still be intact. Open the signature properties, show the signer's certificate, select the root, add it to trusted certificates, tick “Use this certificate as a trusted root”, and validate again.

How do I verify a DSC on a PDF?

Check that the signature is valid and nothing was added after signing, then confirm the certificate chain ends at a CCA India root through a licensed Indian CA. Verify PDF Signature shows all of this, including the full chain and SHA-256 fingerprints.

Is it safe to add the CCA India root to trusted certificates?

Yes, if you have confirmed it is the genuine CCA root. Compare its SHA-256 fingerprint with the one the CCA publishes on its official website. Never trust a root just because a document told you to.

Can I remove the e-Aadhaar password and then verify it?

No. Unlocking rewrites the file and removes the digital signature. Verify the password-protected original in Adobe Reader.

How do I verify a GST e-invoice?

Scan the QR code with the official e-Invoice QR Code Verifier app listed on the GST portal. The QR code is signed by the Invoice Registration Portal; the PDF itself is only a copy.

My Form 16 signature shows as invalid. What does it mean?

The document was changed after the deductor signed it, or the signature is damaged. Download a fresh copy from the source or ask your employer; do not rely on the edited one.

Is a Class 2 DSC signature still valid?

Signatures made with Class 2 certificates while they were valid remain valid. New Class 2 certificates stopped being issued from 1 January 2021 under CCA guidelines, with Class 3 issued instead.