Security

What is a digital certificate (.pfx / .p12), and do I need one to sign a PDF?

A digital certificate is a digital ID: a small file, usually ending in .pfx or .p12, that holds your verified name and a secret key. It is issued to you by an organisation that has checked who you are. You need one to make a digital signature, but not to simply put your signature on a PDF.

7 min read

The Digital Signature tool asks for a certificate and its password. If that made you stop and think "what certificate?", you are in the right place. Most people have never needed one, and the word is used for several different things online.

The short version

A digital certificate is a digital ID. It is a small file, usually ending in .pfx or .p12, that holds two things:

  1. Your verified identity: your name (and sometimes your organisation and email), checked by whoever issued it.
  2. A secret key that only you should have. This key is what actually creates the digital signature.

You use it the way you would use an official stamp that only you own: the stamp itself stays with you, and every document you seal with it can later be checked.

An everyday comparison

Think of a passport.

  • A government office checks who you are and then issues the passport. You cannot print a real one at home.
  • It has your name, an expiry date, and the name of the country that issued it.
  • Anyone who trusts that country trusts the passport.

A certificate works the same way. An organisation called a certification authority checks who you are and issues it. It has your name, an expiry date and the name of the issuer. Anyone who trusts that issuer can trust signatures made with it.

What is actually inside the file

If you opened a certificate, you would find:

  • Your name (and often your organisation, country and email).
  • The issuer: the authority that vouches for you.
  • Valid from / valid until dates. Most certificates last one to three years.
  • What it may be used for: for example "digital signature". A certificate made only for encrypting email cannot be used to sign documents.
  • A public key: the part others use to check your signatures.
  • The private (secret) key: only in the .pfx/.p12 file you keep. This is why the file has a password.

A good .pfx file also contains the certificates of the issuer (the "chain"). That lets a checker follow the line from your certificate up to an authority it recognises.

Where do people get a certificate?

A certificate is issued to you. The usual sources:

  • Your employer. Many companies, universities and hospitals give staff a digital ID for signing internal documents.
  • Your bank or a government service, where they issue digital IDs to customers or citizens.
  • A certification authority: a company that sells "document signing" certificates to individuals and businesses. They check your identity first (for example with an ID document or company registration), then issue the certificate. Prices and the checks they do vary by provider and country.

In many countries, a government body licenses certification authorities, and only their certificates carry legal weight for official filings. If you need a signature for a specific government or court process, ask that office which certificates they accept before buying one.

Can I make one myself?

Yes. Tools such as Adobe Acrobat can create a self-signed digital ID in a minute. It works for signing, and the signature will still show whether the document changed. But nobody has checked who you are, so other people's software will show the signer as not trusted or unknown. That is fine inside a small team that already knows each other; it is not suitable where identity must be proved.

.pfx, .p12, USB tokens and cloud signing

  • .pfx and .p12 are the same kind of file with two names. Both hold the certificate *and* the private key, protected by a password. This is what KovaPDF's Digital Signature tool accepts.
  • .cer, .crt or .pem files usually hold only the public part (no private key) so they cannot sign anything. If that is all you have, you need the .pfx version from whoever issued it.
  • USB tokens and smart cards keep the private key locked inside the hardware, where it cannot be copied into a file. Signing with those needs the token's own software, and a website cannot use them directly.
  • Cloud (remote) signing keeps the key with the provider, who signs on your behalf after you log in. That also happens in the provider's own app.

How to get a .pfx file from your computer

If your certificate is already installed on your computer (common when an employer set it up), you can export it:

On Windows

  1. Press the Windows key, type certmgr.msc and open it.
  2. Open Personal → Certificates and find the certificate with your name.
  3. Right-click it → All Tasks → Export.
  4. Choose "Yes, export the private key". If this option is greyed out, the key cannot be exported. Ask whoever issued the certificate.
  5. Select Personal Information Exchange (.PFX) and tick "Include all certificates in the certification path if possible".
  6. Set a password and save the file.

On a Mac

  1. Open Keychain Access.
  2. Find your certificate under My Certificates (the entry with a small arrow, which means the private key is included).
  3. Right-click → Export, choose the .p12 format, and set a password.

Ticking the "include all certificates" option matters: without the issuer's certificates inside the file, a checker cannot connect your certificate to the authority that issued it.

Keeping it safe

Your .pfx file plus its password is your signature. Treat it like the key to your house:

  • Never email it or share it in chat, and never share the password alongside it.
  • Keep a backup in a safe place: if you lose it, you cannot make new signatures with it.
  • If you think someone else has it, ask the issuer to revoke it at once. A revoked certificate is reported as revoked by signature checkers, including Verify PDF Signature.

On KovaPDF, the certificate and its password are used once, in memory, to make your signature, and are not stored.

What happens when it expires?

After the "valid until" date, you cannot make new signatures with it. Signatures you already made remain checkable, especially if they include a trusted timestamp, which proves they were made while the certificate was still valid. KovaPDF's Digital Signature tool adds one by default.

Do I actually need a certificate?

Ask yourself one question: does anyone need to prove later that this document has not been changed, and who signed it?

  • No: a leave request, a delivery note, a form a colleague asked you to sign, an agreement between people who trust each other. Use Sign PDF: draw, type or upload your signature and place it on the page. No certificate needed.
  • Yes: a contract that may be disputed, a tender, a bank or government submission that asks for a digital signature. Use Digital Signature with a certificate.

If you are still unsure, the organisation asking for your signature will usually say which one they need. The difference between the two is explained in plain language in What is a digital signature in a PDF.

Common questions

What is a .pfx or .p12 file?

It is a password-protected file that holds your digital certificate together with its private key. Everything needed to make a digital signature. The two extensions mean the same kind of file.

I have a .cer or .crt file. Can I sign with it?

No. Those files usually hold only the public part of the certificate, without the private key, so they cannot create a signature. Ask the issuer for the .pfx version, or export it from your computer with the private key included.

Where can I get a certificate for signing PDFs?

From your employer, bank or a government service if they issue digital IDs, or from a certification authority that sells document-signing certificates. If you need it for a particular official process, ask that office which certificates they accept first.

Can I create my own certificate for free?

Yes, programs such as Adobe Acrobat can create a self-signed digital ID. It still shows whether a document changed after signing, but because nobody verified your identity, other people will see the signer as not trusted or unknown.

The export option "Yes, export the private key" is greyed out. What now?

The certificate was installed in a way that does not allow the key to leave the computer or token. Only the issuer can help. Ask them for an exportable copy or a .pfx file.

Can I use a USB token or smart card?

Not on a website. The key on a token is locked inside the hardware and can only be used through the token's own software. KovaPDF's Digital Signature tool needs a .pfx or .p12 file.

Is it safe to upload my certificate?

Only upload it to a service you trust, over a secure connection. On KovaPDF, the certificate and its password are used once, in memory, to make your signature and are not stored. Never email your .pfx file or share its password.

Do I need a certificate just to sign a form?

Usually not. If nobody needs to prove later that the document was unchanged, draw, type or upload your signature with Sign PDF. No certificate required.