Quick Answer
"Signature validity is unknown" in Adobe means the signed content is intact but Acrobat can't chain the signing certificate to a trusted root, so it won't confirm the signer's identity. Fix it by adding the certificate (or its issuer) to Trusted Certificates, or by updating the Adobe Approved Trust List: Preferences → Trust Manager → Update Now, then re-validate the signature.
Symptom fingerprint
The exact strings, error codes, and UI surfaces that map to this issue:
| UI message | Surface | Code |
|---|---|---|
| Signature validity is unknown | Signature panel / yellow banner at top of the PDF | — |
| Yellow triangle or question-mark badge (not a red X) | Signatures panel icon | — |
| The signer's identity has not yet been verified | Signature Properties → Summary | — |
Unknown is not the same as invalid
This one panics people more than it should. A yellow question mark or triangle means "validity unknown" — Acrobat checked that the document wasn't changed after signing, but it can't verify the signer because their certificate doesn't chain to a root Acrobat trusts. A red X is different: that's a genuinely broken or altered signature. If you've got yellow, the content is fine.
Because it's a trust problem, the fix is on your side — you establish trust in the certificate — not the signer's. You almost never need the document re-signed.
Why this happens
- The signer used an internal, self-signed, or organizational certificate that isn't on any public trust list.
- The signer used a commercial CA, but your Acrobat's Adobe Approved Trust List (AATL) is out of date.
- The certificate's revocation status (CRL/OCSP) couldn't be checked — often an offline machine or a blocked network.
- The document is time-stamped by an authority Acrobat doesn't yet trust.
- You opened it in a viewer that doesn't do trust checking, then Acrobat flagged what the other app ignored.
Fix 1 — Trust the certificate directly
Best when the signer used an internal or self-issued certificate that will never be on the AATL.
- Open the Signatures panel (left side) or click the signature.
- Right-click the signature → Show Signature Properties → Show Signer's Certificate.
- Trust tab → Add to Trusted Certificates.
- Tick "Use this certificate as a trusted root", then OK.
- Right-click the signature → Validate Signature. It should turn green.
Fix 2 — Update the trust list (commercial certificates)
Best when the signer used a known CA (DigiCert, GlobalSign, Entrust, IdenTrust) and the badge should already be green.
- Edit → Preferences → Trust Manager (Windows) or Acrobat → Preferences → Trust Manager (macOS).
- Under "Automatic Adobe Approved Trust List (AATL) updates", click Update Now.
- Also enable "Load trusted certificates from an Adobe AATL server" if it isn't already.
- Close and reopen the PDF, then re-validate.
Fix 3 — Let Acrobat use the Windows store
- Preferences → Signatures → Verification → More.
- Enable validating signatures and certified documents against the Windows Certificate Store.
- Useful when your organization pushes its root CA through Windows. On macOS, use Fix 1 or Fix 2 — Acrobat there doesn't read the login Keychain by default.
Still not working?
- If it goes green on your PC but stays unknown elsewhere, remember trust is stored per user/per machine — deploy the root via Group Policy or AATL enrolment for everyone.
- If revocation checking is the blocker, connect the machine to the internet or, for a one-off, adjust revocation-checking behaviour in Preferences → Signatures → Verification.
- US federal (PIV/CAC) signers: import the FCPCA / Federal PKI root and set it as a trusted root — the commercial AATL may not cover it.
Frequently asked questions
What does signature validity is unknown mean in Adobe?
It means the document wasn't altered after signing, but Acrobat can't verify who signed it because the certificate doesn't chain to a trusted root. It's a trust problem, not a broken signature — a red X would mean the signature itself failed.
How do I make an unknown signature valid (green) in Acrobat?
Either add the signer's certificate to your Trusted Certificates and mark it a trusted root, or update the Adobe Approved Trust List via Preferences → Trust Manager → Update Now. Then right-click the signature and choose Validate Signature.
Why is the signature unknown on one computer but valid on another?
Trust decisions in Acrobat are stored per user and per machine. A certificate you trusted on one PC isn't automatically trusted on another. For organizations, deploy the root certificate through Group Policy or AATL enrolment so every install trusts it.
You might also need
More fix guides in PDF and related areas.
Still seeing this error?
If these steps don't isolate the root cause inside your environment, an independent consultant can run a structured PKI diagnostic with you over a screen-shared session and deliver a written report identifying root cause, remediation, and — where relevant — the next responsible party (CA, internal IT, or software vendor).
Book a remote diagnostic →Includes a written diagnostic summary. Independent consulting engagement — not affiliated with DocuSign, Adobe, or Microsoft.
Comments
Loading comments…
