Security

What is Adobe's Approved Trust List (AATL)?

The AATL is Adobe's own list of certificate authorities that Acrobat and Reader trust out of the box. If your certificate chains to one of them, Acrobat shows a green tick; if not, it shows the signature as valid but the signer as unknown.

4 min read

Every signature result includes a row called "Adobe trust list (AATL)", reading either *Trusted by Adobe (AATL)* or *Not on the list*.

Why it exists

Adobe Acrobat and Adobe Reader are how most of the world opens PDFs. When someone opens a signed document there, Acrobat has to decide what to show.

Adobe could have used the same root list your operating system uses, but PDF signing has its own requirements, so Adobe runs its own programme. Certificate authorities apply, are audited, and if accepted are added to the list. Adobe publishes it, and Acrobat carries it.

The practical effect: who issued your certificate decides what Acrobat shows. Not which website signed the document, not which app, not how careful you were.

The everyday version

Think of a club with a guest list at the door.

  • On the list: you walk in without being asked anything.
  • Not on the list: you are not thrown out, but you are asked who you are, and somebody inside has to vouch for you.

Being off the list does not make you an impostor. It means the door staff have not been told about you in advance.

What "Not on the list" really means

You will see it constantly, including for entirely legitimate signatures:

  • certificates a company issues to its own staff,
  • certificates from a national authority that never joined Adobe's programme,
  • [self-signed Digital IDs](/blog/what-a-self-signed-digital-id-proves), which by definition will never be on it.

In all three cases the signature can be perfectly intact and genuinely from the person named. Acrobat will typically say something like *signature valid, signer's identity unknown*, which is accurate: it cannot confirm the identity, and it does not pretend to.

Our verifier keeps the two apart for exactly this reason. The Signature row tells you whether the document changed. The AATL row tells you what Acrobat is likely to show. They are different questions and they get different lines.

If you need the green tick

Then you need a certificate from an authority in Adobe's programme. Ask before buying: *"Is your document-signing certificate on the Adobe Approved Trust List?"* Any authority in the programme will answer immediately.

No tool or setting can add this afterwards. It is decided entirely by the issuer.

If you are receiving a document

The recipient can also choose to trust a certificate, in Acrobat, or in our tool with "Trust your own certificate". That is the right answer when you know the issuer: your employer, a supplier, a partner. Add their root once, and their signatures show as trusted to you from then on.

Our result then states the basis plainly ("Trusted because you added it") so you never lose sight of where that trust came from.

How we read the list

Adobe publishes the AATL as a signed file. We use it only when its own signature verifies and chains to Adobe's own root, pinned by fingerprint, so a file that merely claims to come from Adobe is refused. Authorities Adobe has removed from the programme are never treated as trusted.

The result footer tells you how many entries were loaded and when.

AATL and the EU lists are different things

The AATL is a commercial trust programme run by one company for its own software. The EU trusted lists are government registers with legal meaning under European law.

A certificate can be on one, both or neither. A qualified European certificate that is not in Adobe's programme still carries full legal standing in Europe, while showing "signer unknown" in Acrobat. Both facts are true at once, which is exactly why they get separate rows.

Common questions

What is the Adobe Approved Trust List?

A list Adobe publishes of certificate authorities that Acrobat and Reader trust automatically for document signing. Certificates chaining to one of them show a green tick in Adobe software.

Why does Acrobat say my signature's validity is unknown?

Because your certificate does not chain to an authority on Adobe's list. The signature itself may be entirely valid; Acrobat simply cannot confirm the signer's identity on its own.

Can I add my certificate to the AATL?

Not as an individual. Certificate authorities apply and are audited. If you need the green tick, buy a certificate from an authority already in the programme.

Is a certificate that is not on the AATL unsafe?

No. Company-issued and many national certificates are not in Adobe's programme and are perfectly legitimate. The list is about automatic recognition in Adobe software, not about validity.

Is the AATL the same as the EU trusted lists?

No. The AATL is one company's trust programme for its own software. The EU trusted lists are government registers with legal meaning under European law. A certificate can appear on one and not the other.

How can I make a certificate show as trusted for me?

Add the issuer's root certificate yourself, in Acrobat or with 'Trust your own certificate' in the verification tool. The result will say the trust came from you.