Quick Answer
"The signer's identity is unknown" means Adobe Acrobat can't chain the signing certificate to a trusted root — the signature itself is usually intact, not tampered with. Fix it by adding the signer's certificate to your Trusted Certificates and enabling it as a trusted root, or by updating the AATL trust list under Preferences → Trust Manager → Update Now.
Symptom fingerprint
The exact strings, error codes, and UI surfaces that map to this issue:
| UI message | Surface | Code |
|---|---|---|
| The signer's identity is unknown because it has not been included in your list of trusted certificates | Signature Properties → Summary tab / yellow validation banner | — |
| Validity unknown | Signature panel badge (question-mark icon, not a red X) | — |
| Certificate details show a full chain but no trust anchor | Show Signer's Certificate → Trust tab | — |
What this message actually means
Adobe Acrobat checks two separate things when it opens a signed PDF: whether the signed bytes were altered (integrity) and whether the signing certificate chains to a root Acrobat trusts (trust). "The signer's identity is unknown" is purely the second check — trust — reporting that Acrobat reached the certificate but found no trusted anchor above it. It is not saying the document was tampered with.
That's the key thing to understand, because it means the fix is almost never re-signing the document. You either tell Acrobat to trust the certificate (or its issuer), or you refresh the Adobe Approved Trust List (AATL) so the issuer is recognized automatically. I see people panic at the yellow banner and ask the signer to redo everything — nine times out of ten that's wasted effort.
Why this happens
Three situations produce this exact banner:
- The signer used an internal, self-issued, or organizational certificate that was never meant to appear on a public trust list.
- The signer used a commercial certificate (Entrust, GlobalSign, DigiCert, IdenTrust) but your AATL is stale, so Acrobat doesn't recognize the issuer yet.
- A US Federal PIV/CAC or other government certificate that chains to the Federal PKI rather than the commercial AATL — Acrobat won't trust it until you add the Federal root.
Fix 1 — Trust the certificate directly
Use this when the signer used an internal, self-issued, or organizational certificate that will never be on the AATL.
[IMAGE: Signature Properties → Show Signer's Certificate → Trust tab with "Add to Trusted Certificates" highlighted — alt text: "Adobe Acrobat certificate viewer Trust tab with Add to Trusted Certificates button"]
- Open the signed PDF and click the signature, or open the Signatures panel on the left.
- Right-click the signature → Show Signature Properties → Show Signer's Certificate.
- Go to the Trust tab → Add to Trusted Certificates.
- Tick "Use this certificate as a trusted root" and, if appropriate, "Certified documents", then click OK.
- Right-click the signature again → Validate Signature. The banner should turn green.
Fix 2 — Update the AATL / EUTL trust list
Use this when the signer used a commercial certificate that should already be trusted — Acrobat's trust list is just stale.
[IMAGE: Preferences → Trust Manager with the "Update Now" button under Automatic Adobe Approved Trust List updates — alt text: "Adobe Acrobat Trust Manager preferences showing the AATL Update Now button"]
- Edit → Preferences → Trust Manager (Windows) or Acrobat → Preferences → Trust Manager (macOS).
- Under "Automatic Adobe Approved Trust List (AATL) updates", click Update Now.
- Confirm "Load trusted certificates from an Adobe AATL server" is enabled.
- Close and reopen the PDF, then re-validate the signature.
Fix 3 — Let Acrobat use the OS trust store (Windows)
If your organization distributes its root CA through Windows, tell Acrobat to honor it.
- Preferences → Signatures → Verification → More.
- Enable "Validating Signatures" and "Validating Certified Documents" against the Windows Certificate Store.
- This doesn't apply on macOS — Acrobat there doesn't read the login Keychain by default, so use Fix 1 or Fix 2 instead.
Still not working?
If you've trusted the certificate (or refreshed the AATL) and the banner still says the identity is unknown, the usual culprits are a broken or incomplete certificate chain — an intermediate CA is missing — or a revocation/timestamp check that can't reach the CA's servers. A government or bridge-CA certificate can also need the Federal root added by hand before anything else takes.
[IMAGE: the yellow "at least one signature has problems" validation banner above a signed PDF — alt text: "Adobe Acrobat yellow signature validation banner reading signer's identity is unknown"]
This is a common one to hand off — on a screen-shared session I can inspect the exact chain, import the missing intermediate or Federal root, and confirm the green tick sticks across your machines rather than just on this one.
Frequently asked questions
Is "the signer's identity is unknown" the same as an invalid signature in Adobe?
No. "Identity unknown" is a trust problem — Acrobat can't chain the certificate to a trusted root, but the signed content is usually intact. "Signature invalid" or "the document has been altered" is a separate, integrity problem. Open Signature Properties to see which one you actually have before doing anything.
How do I trust a certificate in Adobe Acrobat so the signer's identity shows as valid?
Right-click the signature → Show Signature Properties → Show Signer's Certificate → Trust tab → Add to Trusted Certificates. Tick "Use this certificate as a trusted root", click OK, then re-validate the signature. The banner should turn green.
I trusted the certificate but it still shows unknown on another computer — why?
Trust decisions are stored per user and per machine in Acrobat. Either repeat the trust step on each computer, or, better for organizations, deploy the root through AATL enrollment or Windows Group Policy so every install trusts it automatically.
Will Adobe's AATL cover a US government PIV or CAC certificate?
Not always. US Federal PKI roots (Federal Bridge / FCPCA) are trusted through the EUTL/Federal PKI rather than the commercial AATL. Import the FCPCA root and set it as a trusted root, or enable the Federal PKI trust anchor. We do this live for federal signers.
You might also need
More fix guides in Adobe Sign and related areas.
Adobe Sign Signature Invalid & Adobe Acrobat Certificate Not Trusted — Diagnostic Guide
Read Adobe SignAdobe Acrobat Certificate Not Trusted — Trust Store, AATL and Windows Integration Diagnostics
Read Adobe SignCertificate Chain Invalid in Adobe & DocuSign — Intermediate Rebuild and AIA Diagnostics
ReadStill seeing this error?
If these steps don't isolate the root cause inside your environment, an independent consultant can run a structured PKI diagnostic with you over a screen-shared session and deliver a written report identifying root cause, remediation, and — where relevant — the next responsible party (CA, internal IT, or software vendor).
Book a remote diagnostic →Includes a written diagnostic summary. Independent consulting engagement — not affiliated with DocuSign, Adobe, or Microsoft.
Comments
Loading comments…
