Security
What is a .pfx or .p12 file, and where do people get one?
A .pfx or .p12 file is your digital ID in a single password-protected file: your checked name plus the secret key that actually makes the signature. It is issued to you by an organisation that verified who you are, and it is the only certificate format that can sign anything.
The Digital Signature tool asks for two things: "Certificate (.pfx or .p12)" and "Certificate password". If you have never been given either, this page explains what is being asked for and why.
Why a signature needs a file at all
A signature you draw with a mouse is a picture. Anyone can copy it. A digital signature is different: it is made with a secret key, and it can only be made by whoever holds that key. The .pfx file is where that key lives.
So the file is not a picture of your signature, and it does not contain one. It is the thing that does the signing.
What is inside
Open one up and you would find:
- Your name, and often your organisation, country and email. Checked by whoever issued it.
- The issuer's name: who vouches for you.
- Valid from and valid until dates. Usually one to three years.
- What it may be used for. A certificate issued only for encrypting email cannot sign documents.
- The public part, which other people use to check your signatures.
- The private key: the secret. This is the part that must never be shared, and the reason the whole file has a password.
A good .pfx also carries the issuer's own certificates, so a checker can follow the line from you up to an authority it recognises.
.pfx and .p12 are the same thing
Two names, one format. Windows tends to say .pfx, Apple and Linux tools tend to say .p12. Either will work.
Files that will not work
This trips up a lot of people, so it is worth stating clearly:
| File ending | Contains the secret key? | Can it sign? |
|---|---|---|
| .pfx / .p12 | Yes | Yes |
| .cer / .crt / .der | No | No |
| .pem | Usually no | Only if it also holds the key |
| .p7b / .p7c | No | No |
A .cer or .crt file holds only the public half. The part you hand to other people. It proves nothing on its own and cannot create a signature. If that is all you have, go back to whoever issued the certificate and ask for the .pfx version, or export it yourself.
The password
The password protects the private key inside the file. You will have either chosen it when the certificate was created, or been given it by whoever issued the certificate.
Nobody can recover it for you. Not us, and usually not the issuer either. The password is applied to the file itself, not stored anywhere. If it is lost, a new certificate is the only route.
In the tool, your file and its password are used once, in memory, to make the signature, and are never stored.
Where do people get one?
A certificate is issued to you, the way a passport is issued. The usual sources:
- Your employer. Many companies, universities and hospitals give staff a digital ID.
- Your bank or a government service, where digital IDs are issued to customers or citizens.
- A certification authority: a company that sells document-signing certificates. They check your identity first, then issue the certificate.
In many countries, a government body licenses these authorities, and only their certificates carry weight for official filings. If you need a signature for a particular office or court, ask them which certificates they accept before buying one.
There is a longer guide on all of this: what is a digital certificate, and a country-by-country one at how to get a digital signature certificate in your country.
If you do not have one
You have two honest options.
Make one yourself. The tool offers "Create a free self-signed Digital ID", made right in your browser. It produces a genuine .pfx you can sign with. What it cannot do is prove your identity to a stranger. See what a self-signed Digital ID proves.
Do not use a certificate at all. For a great many everyday documents (a leave form, a delivery note, an internal approval) a drawn or typed signature is what people actually expect. Sign PDF does that in a few seconds, with no certificate.
Keeping it safe
Treat the .pfx like a house key:
- Keep it somewhere only you can reach, and keep a backup somewhere safe.
- Never email it, and never put it in shared storage.
- Never send it together with its password.
- If you think someone else has a copy, tell the issuer so the certificate can be cancelled.
A stolen .pfx plus its password lets someone sign as you.
If your key is on a USB token instead
Some certificates never come as a file at all. The key lives inside a USB token or smart card and cannot be exported. That is a stronger arrangement, and the tool supports it: see signing with a USB token or smart card.
Common questions
What is a .pfx file used for?
It holds a digital ID: your verified name together with the private key that creates digital signatures. It is the file a signing tool needs in order to sign on your behalf.
Is .p12 the same as .pfx?
Yes. They are the same format under two names. Either works.
I have a .cer file. Why can't I sign with it?
A .cer holds only the public half of the certificate. The part you give other people. The private key is missing, and without it nothing can be signed. Ask the issuer for the .pfx version.
I lost my certificate password. Can it be recovered?
No. The password protects the file itself and is not stored anywhere. You will need a new certificate from the issuer.
Where can I get a certificate for signing PDFs?
From your employer, your bank or a government service if they issue digital IDs, or by buying one from a certification authority. If a specific office must accept it, ask them first which issuers they recognise.
Is my certificate stored when I sign?
No. The file and its password are used once, in memory, to make the signature, and are never kept.