Leadership updated [GDPR-related office procedures] and the legal team insists on dated acknowledgments from every emp…
Open Adobe Acrobat and sign in with your administrator account.
Go to the application preferences by selecting Edit > Preferences.
Select Signatures from the list on the left.
In the Identities & Trusted Certificates section, click More.
In the Digital ID and Trusted Certificate Settings dialog, add or import your organization's trusted root certificates under Trusted Certificates.
CautionOnly import certificates from verified and authorized sources to avoid trust issues.
Set trust levels for each imported certificate by selecting it and configuring the appropriate trust options for your organization's requirements.
Close the dialog and return to the Signatures preferences pane.
Under Verification, configure the signature validation settings to enable certificate revocation checking and signature validation policies.
Configure signature validation policies by selecting options such as requiring certificate revocation checking, verifying signatures using OCSP or CRL, and validating all signatures in the document when certifying.
RecommendationEnable revocation checking to ensure signatures are still valid at the time of verification.
Click OK to save your validation policy settings.
Deploy these settings organization-wide using the Acrobat Customization Wizard or via Group Policy Objects (GPO) for managed environments.
Best practiceBLOGS suggest exporting your configured registry settings and distributing them via GPO for consistent enforcement across all user devices.
You can centrally manage trusted certificates and validation policies to ensure all users in your organization validate signatures according to your security requirements.
This runs in the Acrobat app - there is no separate API for this task.
A 'trusted identity' is a digital certificate from a person or organization that you have told Acrobat you trust. It matters because Acrobat uses this trust to decide if a digital signature is valid. If a signature comes from an identity you don't trust, Acrobat will warn you, even if the signature itself is technically correct. You can manage these trusted identities in Acrobat's settings.
If a digital signature shows 'unknown validity', it means Acrobat cannot confirm if it's real or trusted. You should first check your internet connection, as Acrobat might need to contact a server to verify the certificate. You may also need to manually add the signer's certificate to your list of trusted identities. This often happens if the signer is new to you or their certificate authority is not automatically trusted by your system.
Adding Long Term Validation (LTV) information to a digital signature is important because it makes the signature self-validating over time. Without LTV, a signature's validity might expire or become unconfirmable if the original certificate authority or timestamp server goes offline. LTV embeds all necessary verification data directly into the PDF at the time of signing, ensuring the signature can be validated far into the future, even if external resources are no longer available. This is crucial for documents that need to remain legally binding for many years.
| Feature | Scanned Image of Signature | Verified Digital Signature |
|---|---|---|
| Purpose | Visual representation of a signature | Proof of identity and document integrity |
| Security | Can be easily copied or faked | Uses encryption to prevent tampering and verify signer |
| Verification | Requires manual comparison | Automatically checked by software for validity and trust |