Adobe Acrobat and Acrobat Reader show this message in the blue document message bar when a PDF contains one or more certificate-based digital signatures that they could not fully validate:
At least one signature has problems.
It is a summary, not a diagnosis. The cause is in the signature details, and in most cases the document has not been tampered with: Acrobat simply cannot confirm who signed it. Here is how to find out which of the four usual causes you have, and how to fix each one.
First, read the actual reason
- Click Signature Panel at the right of the blue message bar (or open the Signatures panel from the left-hand pane).
- Expand each signature. Look at the icon and the first line of text:
- Green check: valid.
- Yellow warning triangle: validity unknown, or valid with changes made after signing.
- Red X: invalid.
- Right-click the signature with the warning and choose Show Signature Properties. The Validity Summary at the top says what could not be confirmed.
Match what you see to one of the sections below.
Cause 1: The signer's certificate is not trusted (most common)
The details read:
Signature validity is UNKNOWN.
The signer's identity is unknown because it has not been included in your list
of trusted certificates and none of its parent certificates are trusted certificates.
The signature is mathematically intact, but the certificate that made it does not chain to a root that Acrobat trusts. This happens with company-internal certificate authorities, self-signed certificates, many national ID-card and government PKIs, and some smaller commercial issuers.
Fix A: update Acrobat's trust lists. Certificates from issuers on the Adobe Approved Trust List (AATL) or the EU Trusted Lists (EUTL) validate automatically, but only if Acrobat has downloaded current lists.
- Go to Edit > Preferences (Windows) or Acrobat > Settings/Preferences (Mac).
- Select Trust Manager.
- Under the Adobe Approved Trust List and EU Trusted Lists settings, make sure automatic updates are enabled and click Update Now.
- Close and reopen the PDF.
Fix B: trust the signer's certificate yourself. Do this only when you know the certificate belongs to the person or organisation that sent the document. If in doubt, ask the signer to confirm the certificate's fingerprint (shown on the certificate viewer's Details tab) by phone, not by replying to the same email.
- In the Signatures panel, right-click the signature and choose Show Signature Properties.
- Click Show Signer's Certificate.
- Select the certificate (or its issuing CA, higher in the chain on the left, if you trust everything that CA issues).
- On the Trust tab, click Add To Trusted Certificates and confirm.
- Tick Use this certificate as a trusted root if it is a root or you want to trust certificates under it, then click OK.
- Right-click the signature and choose Validate Signature.
Trust is stored per computer, which is why the same file can show a green check for the sender and a warning for you.
Fix C (Windows, optional): trust the Windows certificate store. In Preferences > Signatures > Verification > More, the Windows Integration options let Acrobat trust root certificates in the Windows store. In a company that deploys its internal CA through Group Policy, this is how internal signatures go green. Adobe cautions that many certificates shipped with Windows exist for other purposes, so enabling it widens what Acrobat trusts.
Cause 2: The document changed after it was signed
Two different messages, with very different meanings:
- Yellow warning, valid but with changes after signing: something was saved into the file after the signature, such as a filled-in form field, a comment, or another person's signature. A signer can allow some of these changes, and a multi-signer workflow routinely produces them.
- Red X,
Document has been altered or corrupted since it was signed.: the signed bytes no longer match. Either the file was edited in a way the signature does not allow, or it was damaged in transit.
Fix: right-click the signature and choose View Signed Version. Acrobat opens the document exactly as it was when that signature was applied, so you can compare it with the current version and see what changed.
If the changes are legitimate (later signers, form fields the signer left open), the yellow warning is expected. If the file shows a red X, do not rely on it. Ask the sender for a fresh copy, sent directly rather than forwarded through tools that might rewrite it.
A common self-inflicted version of this: opening a signed PDF in another editor, an online "sign PDF" or "compress PDF" service, or a print-to-PDF driver, and saving it. Those tools rewrite the whole file, which invalidates every existing certificate signature. Acrobat appends changes as incremental updates instead, which is why it can keep earlier signatures valid.
Cause 3: The revocation check failed
Acrobat checks whether the signer's certificate has been revoked by contacting the issuer's OCSP responder or downloading its certificate revocation list (CRL). If it cannot reach them, because you are offline, behind a proxy or firewall that blocks those addresses, or the issuer's server is down, the signature may show as unknown with a note that revocation checking did not complete. The Revocation tab of the certificate viewer shows the result.
Fix:
- Connect to the internet (or leave the restricted network) and right-click the signature, then choose Validate Signature again.
- If you are on a corporate network, ask IT to allow outbound HTTP to the OCSP and CRL addresses listed on the certificate's Details tab.
- Senders can avoid this for recipients by signing with long-term validation (LTV) enabled, which embeds the revocation responses in the PDF so it can be validated later without a network connection.
Do not "fix" this by turning off revocation checking in Preferences > Signatures > Verification > More. If the certificate really has been revoked, that check is what tells you.
Cause 4: Timestamp problems
A signature records the time it was made. If it was timestamped by a timestamp authority (TSA), Acrobat validates the signature as of that trusted time. Problems appear when:
- There is no trusted timestamp and the certificate has since expired. The time came from the signer's own computer clock, so Acrobat cannot prove the certificate was valid at the moment of signing.
- The timestamp authority's certificate is not trusted. The signature itself may be fine; the timestamp cannot be verified.
- The timestamp's own certificate has expired.
Fix:
- In Show Signature Properties, open the Date/Time tab to see whether the signature has a timestamp and whether it verified.
- If the TSA is the only untrusted part, trust its certificate the same way as in Cause 1, Fix B, after confirming it is the TSA your organisation or the sender uses.
- In Preferences > Signatures > Verification > More, the Verification Time setting controls whether Acrobat validates as of the signing time, the secure timestamp time, or the current time, and Use expired timestamps controls whether an expired timestamp is still accepted. Adobe enables the latter by default; check it has not been switched off by policy.
Check that it worked
Reopen the PDF. The blue bar should read Signed and all signatures are valid, and each signature in the panel should have a green check. If one still shows a warning, its properties will now name a narrower reason; work through the matching section again.
If you only need a visual signature
Much of the time this error arrives in the middle of an everyday task: someone sent a form, you need to sign it and send it back, and you do not have, or need, a certificate. For that, a visual electronic signature is usually what the recipient expects, and our Sign PDF tool adds one in your browser without uploading the file. It is not a certificate-based signature, and like any tool that rewrites the file it will invalidate digital signatures already in the PDF. Do not use it on a document whose existing signatures must stay valid.
Preventing it when you are the signer
- Sign with a certificate from an issuer on the AATL or EUTL so recipients' copies of Acrobat trust it automatically.
- Add a timestamp from a timestamp authority and enable LTV, so the signature still validates after your certificate expires or if the recipient is offline.
- Make signing the last step. Finish filling, merging and compressing first; do not run the signed file through other tools afterwards.