Digital signature workbench

DigitalSign

Home  /  Guides

Why Adobe shows ‘Validity Unknown’

A yellow warning triangle on a signature panics people into thinking the document is fake. Nine times out of ten it means something far less dramatic.

Adobe Reader answers two separate questions about every signature, and it reports them together in one badge. Confusing the two is why the yellow triangle causes so much unnecessary alarm.

QuestionWhat it checks
IntegrityHas a single byte of this document changed since it was signed?
IdentityDoes the signing certificate chain up to an authority Adobe trusts?

"Validity Unknown" means integrity passed and identity is unresolved. The document is intact. Adobe simply does not recognise who issued the certificate. It is a statement about Adobe's address book, not about your file.

The one to worry about is different. Tampering produces a red cross and text along the lines of "the document has been altered or corrupted since it was signed". A yellow triangle is not that.

Why it happens so often with Indian DSCs

Adobe maintains the Approved Trust List (AATL) — a set of root certificates it ships with and trusts automatically. Getting onto it requires an audit and an ongoing relationship with Adobe, and not every Certifying Authority licensed by the CCA in India is on it.

So you get an odd situation: a certificate can be entirely legitimate under Indian law, issued by a properly licensed CA, and still show yellow in Acrobat because that CA never joined Adobe's programme. Legal validity and Adobe's badge colour are separate things that happen to look related.

Other common causes:

How to fix it

Update Acrobat first

Help → Check for Updates. Then Edit → Preferences → Trust Manager, and confirm automatic updating of approved certificates is switched on. This alone resolves a good share of cases and costs nothing.

Add the issuer to Trusted Identities

If the CA is genuinely not in the AATL, you can tell your own copy of Acrobat to trust it:

  1. Open the signed PDF and click the signature.
  2. Signature PropertiesShow Signer's Certificate.
  3. Go to the Trust tab and click Add to Trusted Certificates.
  4. Tick "Use this certificate as a trusted root", then confirm.
  5. Close and reopen the document.
Understand what you just did. You have told your machine to trust that issuer for every document from now on, and only on your machine — recipients still see yellow. Do this for an authority you have independently verified, not for an unfamiliar certificate on a document you were not expecting.

Install the CA's root certificate

Most licensed CAs publish their root and intermediate certificates for download. Installing them into the Windows certificate store, and enabling Windows trust in Acrobat's Trust Manager preferences, fixes the problem for every document from that CA rather than one at a time.

What you cannot fix from your side

If you are the signer and you want recipients to see green without any of them configuring anything, the only real answer is to obtain a certificate from a CA that is already in the AATL. No tool or setting on the signing side can manufacture trust that Adobe has not extended.

In practice, many Indian organisations simply accept the yellow triangle internally, because everyone involved knows the issuer. It becomes a problem when documents go to people outside that circle — foreign counterparties especially — who read the warning as a red flag.

Common questions

Is a 'Validity Unknown' signature legally valid in India?
Adobe's badge has no bearing on legal status. Under the IT Act 2000, what matters is that the certificate was issued by a CCA-licensed Certifying Authority and was valid when the document was signed. Adobe's trust list is a commercial programme, not a legal register.
Should I trust a document showing a yellow triangle?
It tells you the document has not been altered since signing, which is genuinely useful. It tells you nothing about who signed. Verify the signer's identity another way before relying on it.
Why does the same file show green on one computer and yellow on another?
Trust settings are per-machine. One computer has the issuer's root installed or an up-to-date trust list; the other does not. The file is identical.
Can I make my own certificate show green?
Only on machines where you have explicitly added it as a trusted root. A self-signed certificate has no authority behind it, so no other computer has any reason to trust it.
Sign a document nowFree, no sign-up, and nothing is uploaded — the signing happens in your browser.
DigitalSign · digitalsign.buzz · Guidance only, not legal advice.