How to digitally sign a PDF
A digital signature is not a picture of your name. It is a calculation over the whole file, made with a certificate only you hold, so anyone opening it can see who signed and whether anything changed afterwards. Making one takes two things: the PDF, and your digital ID.
Open Digital SignatureSign with your digital certificateStep by step
Upload the PDF
Drop the document onto Digital Signature. Up to 20 PDFs can be signed together with the same certificate and settings. A password-protected PDF has to be unlocked first with Unlock PDF.
Load your certificate
Under "Where is your certificate?", choose Certificate file and add your .pfx or .p12 with its password. A .cer or .crt will not work, because it carries no private key. For a USB token or smart card, choose that option instead; it needs the small KovaPDF Signer app on a Windows computer, and your token asks for its PIN when you sign.
Place the stamp
"Show a signature stamp on the page" is on by default, at the bottom right of the last page. Drag it where you want it and drag its corner to resize it, and add a reason or location if you like. If the PDF already has an empty signature field, you can choose that instead. Untick the box to sign invisibly. The signature is still in the file.
Decide what may change afterwards
Leave "Certify the document" on an ordinary approval signature unless you are the author sending out a final version; certifying fixes which later changes are allowed. "Lock the document after signing" stops the form fields being changed once you have signed.
Sign and read the check
Sign document builds the signature (with a trusted timestamp, which is on by default) and checks it the way a validator would before you receive the file. The result screen lists each check, from the signature itself to the certificate chain and the timestamp. Download signed PDF saves it.
If you do not have a certificate yet
"Create a free self-signed Digital ID" makes a password-protected .pfx file in your browser in about a minute, and nothing is sent to us while it is made. It signs properly and shows any later change, but readers see you as an unknown signer, because no issuing authority vouches for the name inside it. Keep the file and its password safe: it is the only copy, and neither can be recovered.
Why Acrobat may call the signer unknown
Acrobat shows a green tick only when the certificate comes from an authority on Adobe's trust list. Any other certificate (a company one, a self-signed one) still makes a valid signature that reveals later changes; Acrobat simply cannot vouch for who holds it. The check list on the result screen tells you which case you are in before you send the file anywhere.
Common questions
Is my certificate or its password kept?
No. Both are used once, in memory, to make this one signature and are then discarded. With a USB token the private key never leaves the token at all; only a hash of the document is signed on it.
What does the trusted timestamp add?
An independent timestamp authority certifies when you signed, so the signature stays checkable after your certificate expires. Only a hash is sent to it, never the document.
Can more than one person digitally sign the same PDF?
Yes. Each person signs in turn and the earlier signatures stay valid. The exception is a document certified with no changes allowed, which accepts no further signatures.
What is the difference from Sign PDF?
Sign PDF places a picture of your signature on the page and needs no certificate. Digital Signature uses your certificate to seal the file, so the signer can be identified and any change after signing shows up.