Skip to main content
FAQ Question

Why am I receiving an "At least one signature is invalid" warning message when I open a digitally signed PDF document?

FAQ Answer

This message showing as warning upon opening digitally signed PDF documents usually means that the policy asserted in at least one of the digital certificates present in the PDF, is not in Adobe’s Approved Trusted List, referred as AATL Enabled certificate.

This message DOES NOT mean that the certificate is invalid, unless it is truly expired, suspended or revoked. The real status of the certificate is confirmed by double-clicking on each digital signature present in the opened PDF document.

A temporary way to resolve this issue is to ‘trust’ the certificate in the device used to open the PDF document. See “Trust Manager” in the ‘Preferences“ section of Adobe Acrobat or Adobe Reader. This temporary solution has to be repeated once on each device where a signed PDF is opened.

A permanent way to avoid that warning message is purchasing an IdenTrust AATL Enabled Digital Certificate

AATL Enabled certificates are issued directly on Smart  Cards or USB tokens compliant with FIPS 140-2 L2+ standard like HID Global USB tokens or HID Global Smart Cards. This requirement facilitates two-factor authentication (2FA) and also provides additional security, as the certificate private key cannot be exported from the hardware device, thereby eliminating the potential of key compromise by bad actors.

If the certificate used to sign the PDF document is AATL enabled and the “invalid signature”  message is present, the AATL list in that device has to be updated: Adobe Reader/Adobe Acrobat: Preferences, Trust Manager, click on [Update Now] in the “Automatic Adobe Approved Trusted List (AATL) section.“