Skip to content
Validate a Digital Signature

How to Validate a Digital Signature: A Step-By-Step Guide

Mansi Rana

Receiving a digitally signed document is only half the picture. Before relying on it, you need to confirm that the signature is genuinely valid: that the document has not been altered since it was signed, that the signing certificate is authentic and was not expired or revoked at the time of signing, and that the signature was created by the identity it claims to represent. This process is called validation, and it is distinct from simply seeing a signature line on a PDF.

This guide covers exactly how to validate a digital signature, what a valid result actually confirms, how to interpret common warning and error messages, and what to do when validation fails.

What Validating a Digital Signature Actually Checks

When a PDF reader validates a digital signature, it is checking three distinct things simultaneously, and understanding what each one means helps you interpret the result correctly rather than just looking for a green checkmark.

Document integrity. The reader recalculates a cryptographic hash of the document’s content and compares it against the hash that was encrypted at the time of signing. If the document has been altered in any way since signing, even a single character, the hashes will not match, and the signature will be reported as invalid.

Certificate chain of trust. The reader checks the signer’s digital certificate against the certificate authority that issued it, tracing the chain up to a trusted root certificate. If the certificate chain cannot be validated, either because the certificate authority is not recognised as trusted by your system, or because a link in the chain is broken, the signature will show as valid but not trusted, or as unable to be validated.

Revocation status. The reader checks whether the signing certificate had been revoked by the certificate authority at the time the signature was applied, using either a Certificate Revocation List (CRL) or the Online Certificate Status Protocol (OCSP). This check requires an internet connection at the time of validation to reach the certificate authority’s servers.

A signature that passes all three checks is reported as valid, trusted, and unmodified. A signature that fails any one of these checks produces a different, specific warning, which is why reading the exact wording of the validation message matters more than just noting whether it says “valid” or not.

How to Validate a Digital Signature in Adobe Acrobat Reader

Adobe Acrobat Reader is the most widely used tool for validating digital signatures in PDF documents, and the process is largely automatic if your settings are configured correctly.

Step 1: Open the PDF in Adobe Acrobat Reader. Make sure you are using a recent version of the software, since certificate and revocation checks depend on up-to-date root certificate lists.

Step 2: Check the signature status bar. When you open a digitally signed PDF, Acrobat Reader typically displays a signature status message near the top of the document automatically, if the “verify signatures when the document is opened” preference is enabled.

Step 3: Open the Signatures panel. If the status bar is not visible or you want more detail, click the Signatures icon in the left-hand navigation pane (it looks like a fountain pen), or go to View > Show/Hide > Navigation Panes > Signatures.

Step 4: Expand the signature and review the details. Click on the signature entry to expand it, then click “Signature Properties” or the equivalent option to see the certificate details, the signing time, and the validity status.

Step 5: Ensure you are online. Revocation checking requires the reader to reach the certificate authority’s servers. If you validate a signature while offline, the reader may only be able to confirm the document’s integrity and the certificate’s format, not its current revocation status.

Step 6: Interpret the result. A fully valid signature will show a green checkmark with a message confirming the signature is valid, the document has not been modified, and the signer’s identity is confirmed. Any other result requires closer reading of the specific warning shown.

What a Valid Signature Result Looks Like

A properly validated signature in Adobe Acrobat Reader displays a message along the lines of “Signed and all signatures are valid,” accompanied by a green checkmark or ribbon icon in the signature panel. Clicking into the signature properties will show the signer’s name as it appears on the certificate, the time of signing (and whether this is a trusted timestamp from a timestamp authority or simply the time on the signer’s own computer at the moment of signing), and confirmation that the document has not been modified since that signature was applied.

For documents with multiple signatures, such as a contract executed by two or more parties, each signature is validated independently, and a document is only considered fully validly executed when every required signature passes validation.

Common Validation Warnings and What They Mean

“Signature is valid, but the signer’s identity is unknown.” This means the document integrity check passed, the signature was genuinely created with the claimed private key, but the certificate authority that issued the signer’s certificate is not in your system’s list of trusted root certificates. This is common with certificates issued by certificate authorities that are not pre-installed as trusted in your specific PDF reader, and does not necessarily mean the signature is fraudulent; it means your system has not yet been told to trust that specific certificate authority.

“The document has been altered or corrupted since it was signed.” This is the most serious warning. It means the cryptographic hash comparison failed, indicating that the document’s content has changed after the signature was applied. This could result from an intentional alteration, but can also occur from certain types of benign file conversion or repair processes that inadvertently modify the underlying file structure. Either way, this signature should not be relied upon without further investigation into what changed and why.

“Signature validity is unknown; the revocation status could not be checked.” This typically occurs when the validating device is offline, or when the certificate authority’s revocation servers are temporarily unreachable. It does not mean the signature is invalid; it means the reader could not complete the final check. Reconnecting to the internet and re-validating usually resolves this.

“The signer’s certificate has expired.” Certificates have a defined validity period, commonly one to three years for Digital Signature Certificates in India. If the certificate had already expired at the time the signature was applied, this is a genuine problem. If the certificate expired only after the signature was applied, most PDF readers, when properly configured, will still treat the signature as valid provided a trusted timestamp confirms the signature was made while the certificate was still valid.

How to Fix an Untrusted Certificate

If a signature shows as valid but the signer’s identity is reported as unknown or untrusted, and you have independently confirmed the certificate authority is legitimate, you can manually add that certificate authority to your trusted identities list.

Step 1: Open the signature properties and click “Show Signer’s Certificate” or “Show Certificate Details.”

Step 2: Navigate to the certification path and select the topmost root certificate in the chain.

Step 3: Go to the Trust tab and select “Add to Trusted Identities.”

Step 4: Confirm the checkboxes for how this certificate should be trusted (typically for validating signatures and, if relevant, certified documents), then click OK.

Step 5: Close all dialog boxes, close and reopen the document, and re-validate. The signature should now display as fully trusted.

This process should only be done when you can independently confirm the certificate authority is legitimate. Adding an untrusted or unverified certificate authority to your trusted identities list defeats the purpose of certificate validation entirely.

Validating Digital Signatures on Documents Signed with Aadhaar eSign or DSC in India

For documents signed using Aadhaar eSign or a Digital Signature Certificate issued by an Indian Certifying Authority licensed under the IT Act, 2000, the validation process in Adobe Acrobat Reader follows the same technical steps described above. The certificate chain for Indian CAs traces up through the Controller of Certifying Authorities (CCA) as the root of trust for the Indian PKI hierarchy.

If a document signed with an Indian DSC shows as valid but untrusted in your reader, this often means the CCA’s root certificate is not pre-installed as trusted on your specific device or software configuration, rather than indicating any problem with the signature itself. Indian government portals and several Indian e-signature platforms provide the CCA root certificate for manual installation specifically to address this common issue for users validating Indian-signed documents for the first time.

Why Validation Matters Beyond Just Checking a Box

For enterprise legal and compliance teams, validating a digital signature is not a one-time formality performed when a document first arrives. It is directly relevant to the document’s evidentiary value later. If a signed contract is ever challenged in a dispute, the ability to demonstrate, at the time the document was relied upon, that the signature was validated and confirmed the document’s integrity and the signer’s identity, strengthens the organisation’s position considerably compared to simply assuming a signature was valid because it looked correct on screen.

This is also directly relevant to the Section 65B / Section 63 BSA 2023 framework governing the admissibility of electronic records in Indian courts. A validated digital signature, with its confirmed chain of trust and integrity check, supports the certification process required to produce an electronic document as evidence, in a way that an unvalidated, merely visually inspected signature does not.

For organisations handling high volumes of digitally signed contracts, relying on manual, ad hoc validation checks by whichever employee happens to open the document is not a sustainable process. A contract management platform that automatically validates and logs signature status as part of the document intake and storage workflow removes this manual step and creates a permanent, auditable record of validation for every executed document in the repository.

Legistify’s contract management platform performs this validation automatically as documents are ingested, whether signed through Aadhaar eSign, DSC, or a third-party e-signature tool, and stores the validation result alongside the document’s own metadata, so legal teams have an instant, auditable answer on signature status without needing to manually open and check each file in Adobe Acrobat individually.

Conclusion

Validating a digital signature confirms three specific things: that the document has not been altered since signing, that the signer’s certificate traces to a trusted authority, and that the certificate had not been revoked at the time of signing. The process in Adobe Acrobat Reader is largely automatic, provided your settings enable verification on open and you are connected to the internet for revocation checking. Understanding the specific wording of validation warnings, rather than treating any non-green result as simply “broken,” is what allows you to correctly distinguish between a genuine problem and a routine trust configuration issue.

Frequently Asked Questions

How do I validate a digital signature in a PDF?

Open the PDF in Adobe Acrobat Reader or another signature-aware PDF viewer, ensure you are connected to the internet, and check the signature status displayed in the document message bar or the Signatures panel in the left-hand navigation. The reader automatically checks the document’s integrity, the signer’s certificate chain, and the certificate’s revocation status, and displays a validity result.

What does it mean if a signature is "valid" but the signer's identity is "unknown"?

This means the document has not been altered and the signature was genuinely created with the claimed private key, but the certificate authority that issued the signer’s certificate is not in your system’s list of trusted root certificates. This is a trust configuration issue on your device, not necessarily an indication of a fraudulent signature, and can usually be resolved by manually adding the certificate authority to your trusted identities list after independently confirming its legitimacy.

Why does validating a digital signature require an internet connection?

Checking whether a certificate has been revoked requires contacting the issuing certificate authority’s servers, either through a Certificate Revocation List (CRL) or the Online Certificate Status Protocol (OCSP). Without an internet connection, the reader can confirm document integrity and certificate format but cannot complete the revocation check, which is why full validation requires being online.

What should I do if a digital signature shows as invalid because the document was modified?

This is a serious warning indicating the document’s content has changed since the signature was applied. Do not rely on the document in its current state. Investigate what changed, when, and why, ideally by comparing it against a known-good copy or requesting the signer resend the original signed version, before treating the document as authoritative for any legal or commercial purpose.

Does validating a signature confirm the document is legally binding?

Validation confirms the technical integrity and authenticity of the digital signature itself, which is a necessary component of establishing legal enforceability but not the only one. Whether a signed document is legally binding also depends on the underlying contract law requirements (offer, acceptance, consideration, capacity) and, for documents that may need to be produced as evidence in India, compliance with the Section 65B / Section 63 BSA 2023 framework for electronic records.

About Author

Mansi Rana

Mansi Rana is a digital content marketer dedicated to helping brands communicate with confidence and consistency. With hands-on experience in content strategy, storytelling, and audience engagement, she enjoys turning ideas into clear, meaningful narratives that actually resonate.

Related Next