Security
PDF signature errors explained: invalid, revoked, untrusted, self-signed and incomplete chain
Only two results mean something is actually wrong with a signed document: “invalid” (the signed content changed, or the signature is damaged) and “revoked” (the certificate was cancelled, usually because it was compromised). “Not trusted”, “unknown”, “self-signed”, “revocation not checked” and “no timestamp” are about how much you can rely on the signer's identity or time. Questions to consider, not proof of forgery.
Signature checkers tend to throw a wall of statuses at you: valid, invalid, trusted, not trusted, unknown, revoked, not checked, none. Some of these are serious. Most are not. This page goes through each one, in the order they appear in Verify PDF Signature, with the equivalents you are likely to see in Adobe, and tells you what to do.
First: the two results that really matter
| Result | Meaning | Seriousness |
|---|---|---|
| Signature: Invalid | The signed content changed, or the signature is damaged | Serious |
| Revocation: Revoked | The issuer cancelled the certificate | Serious |
| File changed after signing | Something was added that no signature covers | Depends what was added |
| Trust: Not trusted / Unknown | The issuer isn't on this checker's list | Question, not a failure |
| Self-signed certificate | Nobody else vouches for the identity | Identity unproven |
| Revocation: Not checked | No revocation service named, or unreachable | Informational |
| Timestamp: None | No independent proof of time | Informational |
Signature: Valid / Invalid
What it checks: whether the fingerprint of the signed bytes still matches the one locked in the signature.
- Valid: "The signed part of the document has not changed since it was signed." The most important line in any report.
- Invalid: "The document changed after signing, or the signature is damaged." The verdict reads: This signature is broken.
What to do with Invalid: do not rely on the contents. Ask the sender for the original file, sent directly. Innocent causes exist (a program "repairing" the PDF, an email gateway rewriting an attachment) so one fresh copy is worth trying. If that is also invalid, the document was changed.
Adobe equivalent: "The document has been altered or corrupted since the signature was applied" or "Signature is invalid".
The file has been changed after its last signature
What it means: the signed part is intact, but material was appended afterwards that no signature covers.
What to do: read the list under the signature. A later signature or a filled-in field is usually normal; a changed page or a new text box needs an explanation. Compare the pages and download the signed version. Full detail: Signature is valid but the document was modified.
Certificate: Valid / Invalid
What it checks: the signer's certificate itself. Its structure, its dates relative to the signing time, and whether it was meant for signing.
Invalid can mean the certificate was not valid at the signing time, is damaged, or its permitted uses (Key usage, Extended key usage in Certificate details) do not include signing. For example a certificate issued only for encryption or websites.
What to do: look at the dates and usages in Certificate details. A certificate "Not valid yet" at signing time is suspicious. One meant only for website identity is a sign the signer used the wrong credential. Ask them to re-sign properly.
Revocation: Not revoked / Revoked / Not checked
What it checks: whether the issuer has cancelled the certificate. The checker contacts the issuer's revocation service named in the certificate. OCSP or a CRL.
- Not revoked: the issuer confirms the certificate is in good standing.
- Revoked: the issuer cancelled it. The verdict reads "Signed by [name], but the certificate used has been revoked." Common reasons: the key was lost or stolen, or the certificate was issued in error.
- Not checked: "The certificate names no revocation service, or it could not be reached." Not a failure; common for self-signed and in-house certificates.
What to do with Revoked: treat the signature as unreliable. The only exception is where a trusted timestamp proves the signature was made before revocation, and even then, confirm with the signer.
Certificate chain: Valid / Invalid
What it checks: whether each certificate in the line from the signer up to a root correctly vouches for the one below it.
In Certificate details you will see the chain listed, with the root marked. You may also see: Incomplete: the certificates in the file do not reach a root certificate. That means the signer did not include the issuer's certificates in the signature, so the checker cannot complete the line.
What to do: an incomplete chain is often just a packaging problem (the signer exported their .pfx without "include all certificates in the certification path"). It does not affect integrity. It does mean identity cannot be traced. Ask the signer for a properly packaged signature if identity matters.
Trust: Trusted / Not trusted / Unknown
What it checks: whether the chain ends at a root authority this checker recognises.
- Trusted: "The certificate chains to a root this service recognises."
- Not trusted: "The certificate is intact, but was not issued by an authority this service recognises. That is normal for a company's own certificates."
Which roots a checker recognises is a choice made by whoever runs it. Several national government authorities, and many companies' in-house authorities, are not on general-purpose lists. So Not trusted says as much about the list as about the certificate. Decide based on who the issuer actually is (shown in Certificate details) and, for national schemes, use the official validator of that country as well.
Adobe equivalent: "Signature validity is UNKNOWN". See Why Adobe says “Signature validity is unknown”.
Adobe trust list (AATL)
Whether Adobe Acrobat and Reader will recognise the issuer depends on Adobe's own lists and the settings of the computer opening the file, so only Acrobat or Reader can say for certain whether they will show a green check. Our report explains this on the row itself rather than guessing.
Self-signed certificate
What it means: "[name]'s certificate is self-signed: no one else vouches for who it belongs to." The signer made their own digital ID.
What to do: integrity still holds, if the Signature row is Valid, the document has not changed. But the name is the signer's own claim. Acceptable between people who know each other and can confirm the certificate's SHA-256 fingerprint through another channel; not acceptable as proof of identity to strangers.
Timestamp: Valid / Invalid / None
- Valid: an independent timestamp authority confirmed when the signature was made.
- Invalid: the timestamp token is damaged or does not match. Treat the signing time as unproven.
- None: no timestamp; the only time is the signer's own clock. Common, and fine while the certificate is in date; more important for documents kept for years.
Details: What is LTV, and why does my signed PDF say the certificate expired?
Long-term validation: Present (not checked) / Not included
Whether the signature stores its own validation data for the future. We report its presence; we do not currently validate the stored data itself.
"No digital signature found in this file"
Not an error in the file. It simply has no certificate-based signature. What you see on the page is a picture, drawing or stamp. The checker points out which page such marks are on, and any signature field that was prepared but never signed. See What is a digital signature in a PDF.
"The signer's certificate could not be read from the signature"
The signature data is malformed or uses a structure the checker cannot parse. Try another validator; if it fails there too, the signature is damaged.
"We could not compare the signed version with the current file"
The signature check itself still stands, but the tool could not work out what changed afterwards, usually because of an unusual file structure. Download the signed version and compare the pages yourself.
Common questions
Which signature errors mean a document was tampered with?
“Signature: Invalid” means the signed content changed or the signature is damaged. A warning that the file was changed after its last signature means something was added afterwards. Everything else relates to the signer's identity or time, not to tampering.
What does “certificate revoked” mean?
The issuer cancelled the certificate, usually because its key was lost or stolen or it was issued in error. Treat signatures made with it as unreliable unless a trusted timestamp proves they were made before the revocation.
What does “certificate chain incomplete” mean?
The signature does not include the issuer's certificates, so the checker cannot trace the signer to a root authority. Integrity is unaffected; identity just cannot be traced. It is usually a packaging mistake when the certificate was exported.
Is a self-signed signature valid?
It can be mathematically valid (proving the document has not changed) but nobody else vouches for the signer's name. Confirm the certificate's fingerprint with the signer through another channel before relying on the identity.
Why is revocation “not checked”?
The certificate names no revocation service, or the service could not be reached. That is common and is not a failure.
Why does one checker say trusted and another say not trusted?
Each checker uses its own list of recognised root authorities. A national or company authority may be on one list and not another. Look at who actually issued the certificate and decide on that basis.