Adobe 22002484 User Guide - Page 252

Establish long-term signature validation, Add verification information at signing - air

Page 252 highlights

USING ACROBAT 9 STANDARD 247 Digital signatures Establish long-term signature validation Long-term signature validation allows you to check the validity of a signature long after the document was signed. To achieve long-term validation, all the required elements for signature validation must be embedded in the signed PDF. Embedding these elements can occur when the document is signed, or after signature creation. Without certain information added to the PDF, a signature can be validated for only a limited time. This limitation occurs because certificates related to the signature eventually expire or are revoked. Once a certificate expires, the issuing authority is no longer responsible for providing revocation status on that certificate. Without conforming revocation status, the signature cannot be validated. The required elements for establishing the validity of a signature include the signing certificate chain, certificate revocation status, and possibly a timestamp. If all the required elements are available and embedded at signing, the signature can be validated without going to outside resources for validation information. Acrobat and Reader can embed all the required elements, as long as the elements are available. The PDF creator must enable usage rights for Reader users (Advanced > Extend Features In Adobe Reader). Note: Embedding timestamp information requires a properly configured timestamp server. In addition, the signature validation time must be set to Secure Time (Preferences > Security > Advanced Preferences > Verification tab). More Help topics "Validate a timestamp certificate" on page 249 "Configure a timestamp server" on page 240 "Set signing preferences" on page 240 Add verification information at signing 1 Make sure that your computer can connect to the appropriate network resources. 2 Check that the preference Include Signature's Revocation Status When Signing is still selected. (Preferences > Security > Advanced Preferences > Creation tab.) This preference is selected by default. 3 Sign the PDF. If all the elements of the certificate chain are available, the information is added to the PDF automatically. If a timestamp server has been configured, the timestamp is also added. Add verification information after signing In some workflows, signature validation information is unavailable at signing, but can be obtained later. For example, suppose a company official signs a contract using a laptop while traveling by air. The computer cannot communicate with the Internet to obtain timestamping and revocation information to add to the signature. Later, when Internet access becomes available, anyone who validates the signature can add this information to the PDF. All subsequent signature validations can also use this information. 1 Make sure that your computer can connect to the appropriate network resources, and then right-click the signature in the PDF. 2 Choose Add Verification Information. The command is unavailable if the signature is invalid, or signed with a self-signed certificate. Set signature verification preferences 1 Open the Preferences dialog box, and select Security on the left. Last updated 9/30/2011

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380

247
USING ACROBAT 9 STANDARD
Digital signatures
Last updated
9
/30/2011
Establish long-term signature validation
Long-term signature validation allows you to check the validity of a signature long after the document was signed. To
achieve long-term validation, all the required elements for signature validation must be embedded in the signed PDF.
Embedding these elements can occur when the document is signed, or after signature creation.
Without certain information added to the PDF, a signature can be validated for only a limited time. This limitation
occurs because certificates related to the signature eventually expire or are revoked. Once a certificate expires, the
issuing authority is no longer responsible for providing revocation status on that certificate. Without conforming
revocation status, the signature cannot be validated.
The required elements for establishing the validity of a signature include the signing certificate chain, certificate
revocation status, and possibly a timestamp. If all the required elements are available and embedded at signing, the
signature can be validated without going to outside resources for validation information. Acrobat and Reader can
embed all the required elements, as long as the elements are available. The PDF creator must enable usage rights for
Reader users (Advanced > Extend Features In Adobe Reader).
Note:
Embedding timestamp information requires a properly configured timestamp server. In addition, the signature
validation time must be set to Secure Time (Preferences > Security > Advanced Preferences > Verification tab).
More Help topics
Validate a timestamp certificate
” on page
249
Configure a timestamp server
” on page
240
Set signing preferences
” on page
240
Add verification information at signing
1
Make sure that your computer can connect to the appropriate network resources.
2
Check that the preference Include Signature’s Revocation Status When Signing is still selected. (Preferences >
Security > Advanced Preferences > Creation tab.) This preference is selected by default.
3
Sign the PDF.
If all the elements of the certificate chain are available, the information is added to the PDF automatically. If a
timestamp server has been configured, the timestamp is also added.
Add verification information after signing
In some workflows, signature validation information is unavailable at signing, but can be obtained later. For example,
suppose a company official signs a contract using a laptop while traveling by air. The computer cannot communicate
with the Internet to obtain timestamping and revocation information to add to the signature. Later, when Internet
access becomes available, anyone who validates the signature can add this information to the PDF. All subsequent
signature validations can also use this information.
1
Make sure that your computer can connect to the appropriate network resources, and then right-click the signature
in the PDF.
2
Choose Add Verification Information.
The command is unavailable if the signature is invalid, or signed with a self-signed certificate.
Set signature verification preferences
1
Open the Preferences dialog box, and select Security on the left.