Security

How to verify an ICP-Brasil or gov.br signature on a PDF

Use the official ITI validator for the legal answer: it checks ICP-Brasil (qualified) signatures and gov.br (advanced) signatures and reports each as approved (aprovado), failed (reprovado) or indeterminate (indeterminado). Check integrity and what changed after signing with a PDF signature checker as well. An ICP-Brasil signature may show as “not trusted” in general-purpose tools because the Brazilian root is not on every trust list. That alone does not make it invalid.

5 min read

Brazil has one of the most developed digital-signature systems in the world. The ICP-Brasil public-key infrastructure has underpinned legally valid digital signatures since 2001, and millions of citizens now sign documents for free through the gov.br platform. If you receive a signed PDF in Brazil (a contract, a university diploma, a public document, a medical prescription) here is how to check it.

The short answer

  1. Check the legal validity with the official validator run by the ITI (Instituto Nacional de Tecnologia da Informação). It validates ICP-Brasil and gov.br signatures and reports a result per signature.
  2. Check integrity and later changes with Verify PDF Signature, which lists anything added after signing and shows the signed version side by side with the current one.
  3. Do not panic at "not trusted" in general-purpose tools. The ICP-Brasil root is a national root, and not every trust list includes it.
  • Medida Provisória 2.200-2/2001 created ICP-Brasil and gave documents signed with ICP-Brasil certificates a presumption of truthfulness in relation to the signers. It also allows other means of proving authorship and integrity where the parties accept them.
  • Lei 14.063/2020 classified electronic signatures in dealings with public bodies into three types:
  • Simples (simple): identifies the signer, e.g. a login;
  • Avançada (advanced): uses certificates not issued by ICP-Brasil or other means that link the signature uniquely to the signer and detect changes; the gov.br signature is in this category;
  • Qualificada (qualified): uses an ICP-Brasil certificate.
  • Which type a given act requires depends on the act and the public body. Some acts require a qualified signature; many accept advanced.

Step 1: use the official validator

The ITI's validation service is called VALIDAR. It is free, and it validates only two kinds of signature: those made with certificates from ICP-Brasil certification authorities, and advanced signatures made through the gov.br portal. For ICP-Brasil signatures it recommends .pdf, .p7s or .xml files (the PAdES, CAdES and XAdES formats); gov.br signatures must be checked as PDF.

How to use it:

  1. Open the validator through the ITI's official government site, found by searching yourself.
  2. Upload the signed file exactly as you received it.
  3. Read the result for each signature, not just the first.
  4. If a signature is failed or indeterminate, open the conformity report (relatório de conformidade), which lists what did not pass.

For each signature it reports one of these results, along with details of the signer and the certificate:

  • Aprovado (approved): the signature conforms to the ICP-Brasil rules, or to the gov.br rules for advanced signatures.
  • Reprovado (failed): the signature does not conform. Treat it as unreliable until you know why.
  • Indeterminado (indeterminate): the available information is not enough to say either way. The ITI's own FAQ lists causes such as a PDF signed by software that did not set the modification-detection entries (DocMDP or FieldMDP) that the PDF standard provides, a document that was changed after signing, and an expired certificate. Since the older conformity checker was merged into VALIDAR, a change after signing makes a signature indeterminate as a rule.
  • Assinatura desconhecida (unknown signature). A signature the validator does not recognise. A PDF signed with a foreign certificate will often land here. It may still be a perfectly good signature under another country's rules.

Never follow a validation link printed inside the document you are checking. A forger controls that link.

Step 2: check integrity and changes after signing

The official validator gives the legal verdict. Verify PDF Signature adds detail that helps when the answer is "indeterminate":

  • Signature: Valid means the signed content is unchanged.
  • If something was added afterwards, the verdict says so and lists it in plain words. "Page 2: a comment was added", "Page 1: the page content was changed", "A later signature by [name] was added".
  • Compare the changed pages shows each affected page as signed and as it is now.
  • Download the version that was signed gives you the file exactly as signed, which you can then submit to the official validator on its own.

That last step often resolves an "indeterminate" result caused by an addition after signing. For example, a stamp or annotation someone put on the PDF after the signatures.

What an ICP-Brasil signature looks like in the certificate

In Certificate details, an ICP-Brasil certificate chains up through an ICP-Brasil certification authority to the Autoridade Certificadora Raiz Brasileira (the Brazilian root). The certificate type appears in the policy and name fields. For example, A1 certificates (stored as a file) and A3 certificates (on a token, smart card or in the cloud) are both common.

A gov.br signature chains to the gov.br signing infrastructure rather than to the ICP-Brasil root.

Our Trust row may say Not trusted for both. That means the root is not on this service's list, not that the signature is invalid. Legal validity in Brazil is determined by the Brazilian rules and the ITI validator.

Common real-life situations

A gov.br signature shows a question mark in Adobe

Adobe does not automatically trust the gov.br signing chain on every installation, so you may see validity unknown. The document can still be intact and valid. Check it with the ITI validator, and see Why Adobe says “Signature validity is unknown”.

A contract with several signatures where only some are approved

Look at each signature separately. Common causes: one signer used a certificate from outside Brazil; someone added a signature by a method the others' signatures do not allow; or a stamp was added after the first signatures. The changes-after-signing list shows which.

A diploma or public document with a validation code

Many Brazilian institutions print an authentication code or QR code on signed documents, with a page on their own site to retrieve the original. Use it: but through the institution's official site, found by you.

"I printed and scanned it, and now it isn't signed"

A scan or print-to-PDF produces a new file with no digital signature. Always keep and send the original signed PDF.

Common questions

How do I verify an ICP-Brasil signature?

Submit the signed file to VALIDAR, the ITI's official validation service, which reports each signature as aprovado (approved), reprovado (failed) or indeterminado (indeterminate), and flags signatures it does not recognise as unknown. Check integrity and any changes after signing with a PDF signature checker as well.

Is a gov.br signature legally valid?

Under Lei 14.063/2020, the gov.br signature is an advanced electronic signature, accepted in many interactions with public bodies. Some acts require a qualified signature, which means an ICP-Brasil certificate. The requirement depends on the act and the body.

Why does the ITI validator say “indeterminado”?

The available information was not enough for a firm result. The ITI lists causes such as a document changed after signing, a PDF signed without the standard modification-detection settings, and an expired certificate. A checker that lists changes after signing can show what was added.

Why does my ICP-Brasil signature show “not trusted” in other tools?

Because the Brazilian root authority is not on every general-purpose trust list. That is a limitation of the list, not proof the signature is invalid.

Can I verify a gov.br-signed PDF in Adobe?

Adobe can show whether the document changed, but may display validity unknown because it does not recognise the signing chain by default. Use the ITI validator for the legal result.