This helps ensure that Digital Signatures are valid when you open a PDF and verification details appear with the signature. See Set signature verification preferences for details. When Digital Signatures are validated, an icon appears in the document message bar to indicate the signature status. Additional status details appear in the Signatures panel and in the Signature Properties dialog box. Setting up digital signature validation When you receive a signed document, you may want to validate its signature s to verify the signer and the signed content. Depending on how you have configured your application, validation may occur automatically. It also confirms whether the signing certificate is valid based on the user's Acrobat or Reader configuration. Document integrity verification confirms whether the signed content changed after it was signed. If content changes, document integrity verification confirms whether the content changed in a manner permitted by the signer. Set signature verification preferences Open the Preferences dialog box. Under Categories, select Signatures. For Verification, click More. This option is selected by default. Select verification options as needed and click OK. Verification Behavior When Verifying These options specify methods that determine which plug-in to choose when verifying a signature. The appropriate plug-in is often selected automatically. Contact your system administrator about specific plug-in requirements for validating signatures. Checks certificates against a list of excluded certificates during validation. If you deselect this option, the revocation status for approval signatures is ignored. The revocation status is always checked for certifying signatures. Verification Time Verify Signatures Using Select an option to specify how to check the digital signature for validity. By default, you can check the time based on when the signature was created. Alternatively, check based on the current time or the time set by a timestamp server when the document was signed. Deselecting this option allows discarding of expired timestamps. Default is to alert user when verification information is too large. Windows Integration specify whether to trust all root certificates in the Windows Certificates feature when validating signatures and certified documents. Selecting these options can compromise security. It is not recommended to trust all root certificates in the Windows Certificate feature. Many certificates that are distributed with Windows are designed for purposes other than establishing trusted identities. Set the trust level of a certificate In Acrobat or Reader, the signature of a certified or signed document is valid if you and the signer have a trust relationship. The trust level of the certificate indicates the actions for which you trust the signer. You can change the trust settings of certificates to allow specific actions. For example, you can change the settings to enable the dynamic content and embedded JavaScript within the certified document. Open the Preferences dialog box. Select Trusted Certificates on the left. Select a certificate from the list, and click Edit Trust. In the Trust tab, select any of the following items to trust this certificate: Use This Certificate As A Trusted Root A root certificate is the originating authority in a chain of certificate authorities that issued the certificate. By trusting the root certificate, you trust all certificates issued by that certificate authority. Signed Documents Or Data Acknowledges the identity of the signer. Certified Documents Trusts documents in which the author has certified the document with a signature. You trust the signer for certifying documents, and you accept actions that the certified document takes. When this option is selected, the following options are available: Dynamic content Allows movies, sound, and other dynamic elements to play in a certified document. JavaScript files can be used in malicious ways. It is prudent to select this option only when necessary on certificates you trust. For example, use these options for your employer or service provider. For more information, see the Digital Signature Guide at www. Signatures panel for digital signatures The Signatures panel displays information about each digital signature in the current document and the change history of the document since the first digital signature. Each digital signature has an icon identifying its verification status. Verification details are listed beneath each signature and can be viewed by expanding the signature. The Signatures panel also provides information about the time the document was signed, and trust and signer details. You can right-click a signature field in the Signatures panel to do most signature-related tasks, including adding, clearing, and validating signatures. In some cases, however, the signature field becomes locked after you sign it. Sign in Preview Document mode When document integrity is critical for your signature workflow, use the Preview Document feature to sign documents. This feature analyzes the document for content that may alter the appearance of the document. It then suppresses that content, allowing you to view and sign the document in a static and secure state. The Preview Document feature lets you find out if the document contains any dynamic content or external dependencies. It also lets you find out if the document contains any constructs such as form fields, multimedia, or JavaScript that could affect its appearance. After reviewing the report, you can contact the author of the document about the problems listed in the report. You can also use Preview Document mode outside a signing workflow to check the integrity of a document. The document message bar appears with the compliance status and options. Optional Click View Report in the document message bar if available and select each item in the list to show details. Save the PDF using a different name than the original, and close the document without making any further changes. You also specify the types of changes that are permitted for the document to remain certified. For example, suppose that a government agency creates a form with signature fields. When the form is complete, the agency certifies the document, allowing users to change only form fields and sign the document. Users can fill the form and sign the document. Certifying signatures can be visible or invisible. A blue ribbon icon in the Signatures panel indicates a valid certifying signature. A digital ID is required to add the certifying digital signature. Remove content that may compromise document security, such as JavaScripts, actions, or embedded media. Click one of the following options: Certify Visible Signature Places a certified signature in either an exiting digital signature field if available or in the location you designate. Certify Invisible Signature Certifies the document, but your signature appears only in the Signatures panel. Follow the onscreen instructions to place the signature if applicable , specify a digital ID, and set an option for Permitted Actions After Certifying. If you enabled the When Signing: Save the PDF using a different filename than the original file, and then close the document without making additional changes. It is a good idea to save it as a different file so that you can retain the original unsigned document. Timestamp a document Acrobat provides users with the capability to add a document timestamp to a PDF without also requiring an identity-based signature. A timestamp server is required to timestamp a PDF. See Configure a timestamp server. A timestamp assures the authenticity and existence of a document at a particular time. Users of Reader X and later can also timestamp a document if the document includes appropriate Reader Enabling features. For more information on PAdES, see blogs. In the Choose Default Timestamp Server dialog box, select a default timestamp server from the list, or add a new default timestamp server. Click Next, and then save the document with the timestamp. Validate a digital signature If the signature status is unknown or unverified, validate the signature manually to determine the problem and possible solution. If the signature status is invalid, contact the signer about the problem. For more information about signature warnings and valid and invalid signatures, see the Digital Signature Guide at www. Set your signature verification preferences. For more information, see Set signature verification preferences. Open the PDF containing the signature, then click the signature. The Signature Validation Status dialog box describes the validity of the signature. For more information about the Signature and Timestamp, click Signature Properties. Review the Validity Summary in the Signature Properties dialog box. The summary might display one of the following messages: Signature is timestamped The signer used a Timestamp Server and your settings indicate that you have a trust relationship with that timestamp server. Signature is timestamped but the timestamp could not be verified Timestamp verification requires obtaining the timestamp server's certificate to your list of trusted identities. Validating a check

