Adobe 22002486 Digital Signature User Guide - Page 116

Troubleshooting Digital ID Certificates

Page 116 highlights

Acrobat 9 Family of Products Security Feature User Guide Validating Signatures Troubleshooting an Identity Problem 116 Show Signature Properties and then Show Certificate). Specify the certificate's trust settings as described in "Certificate Trust Settings" on page 35.  Verify that a revocation check occurred. Open the Certificate Viewer's Revocation tab (right click on a Signature, choose Show Signature Properties and then Show Certificate). Check the following:  If revocation checking occurred, Problems encountered is active and you can select the button to view a description of the problems.  If revocation checking did not occur at all, Check revocation is active and you can select the button to check revocation manually.  If online revocation checking is required, it may have failed as a result of no online access or an application problem. 3. If the status is invalid (displays a red X), the signer's certificate is invalid. Do the following:  Contact the signer. The signer may need to get a new digital ID and re-sign a new document.  Policy restrictions on a trust anchor can result in signature invalidity. If you have set a policy restriction, determine if that is the problem remove the restriction. 4. If you still cannot pinpoint the problem, or you need help with some of the steps above, read the following:  "Troubleshooting Digital ID Certificates" on page 116  "Displaying the Signer's Certificate" on page 117  "Verifying the Identity of Self-Signed Certificates" on page 118  "Checking Certificate Revocation Status" on page 119  "Exporting a Certificate Other than Yours to a File" on page 120 7.5.1.1 Troubleshooting Digital ID Certificates Someone becomes your trusted identity when you import their valid digital ID certificate and set a specific trust level for that certificate. You can set trust levels ahead of time if you have access to those certificates. If you do not have access to those certificates, simply validate and trust certificates "on-the-fly" as you receive individual documents. As shown in Table 12, the Certificate Viewer provides six tabs with functionality for working with and verifying digital ID certificates. Table 12 Certificate Viewer information Tab What it shows What you can do Summary Details Revocation Trust Signer and Issuer information, validity dates, and intended usage. Export the certificate to a file. Certificate data such as subject, issuer, used algorithms, public key, and so on. The data can be used in a variety of ways such as using the digests to verify the certificate's origin. Shows certificate validity status of a revocation Signer Details: Open the certificate in the Certificate Viewer. The button is check and provides an explanation. only active if the revocation check was successfully completed. Problems encountered: View revocation checking problems. The button is only active if revocation checking occurred but failed. Check revocation: Enables manual revocation checking. The button is only active if no checking occurred AND a check is possible. Lists the user-specified certificate trust settings. Add the certificate to the Trusted Identity list.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189

Acrobat 9 Family of Products
Validating Signatures
Security Feature User Guide
Troubleshooting an Identity Problem
116
Show Signature Properties
and then
Show Certificate
). Specify the certificate’s trust settings as
described in
“Certificate Trust Settings” on page 35
.
Verify that a revocation check occurred. Open the Certificate Viewer’s Revocation tab (right click on
a Signature, choose
Show Signature Properties
and then
Show Certificate
). Check the following:
If revocation checking occurred,
Problems encountered
is active and you can select the button
to view a description of the problems.
If revocation checking did not occur at all,
Check revocation
is active and you can select the
button to check revocation manually.
If online revocation checking is required, it may have failed as a result of no online access or an
application problem.
3.
If the status is invalid (displays a red X), the signer’s certificate is invalid. Do the following:
Contact the signer. The signer may need to get a new digital ID and re-sign a new document.
Policy restrictions on a trust anchor can result in signature invalidity. If you have set a policy
restriction, determine if that is the problem remove the restriction.
4.
If you still cannot pinpoint the problem, or you need help with some of the steps above, read the
following:
“Troubleshooting Digital ID Certificates” on page 116
“Displaying the Signer’s Certificate” on page 117
“Verifying the Identity of Self-Signed Certificates” on page 118
“Checking Certificate Revocation Status” on page 119
“Exporting a Certificate Other than Yours to a File” on page 120
7.5.1.1
Troubleshooting Digital ID Certificates
Someone becomes your trusted identity when you import their valid digital ID certificate and set a specific
trust level for that certificate. You can set trust levels ahead of time if you have access to those certificates.
If you do not have access to those certificates, simply validate and trust certificates “on-the-fly” as you
receive individual documents. As shown in
Table 12
, the Certificate Viewer provides six tabs with
functionality for working with and verifying digital ID certificates.
Table 12
Certificate Viewer information
Tab
What it shows
What you can do
Summary
Signer and Issuer information, validity dates,
and intended usage.
Export the certificate to a file.
Details
Certificate data such as subject, issuer, used
algorithms, public key, and so on.
The data can be used in a variety of ways such as using the digests to
verify the certificate’s origin.
Revocation
Shows certificate validity status of a revocation
check and provides an explanation.
Signer Details
: Open the certificate in the Certificate Viewer. The button is
only active if the revocation check was successfully completed.
Problems encountered
: View revocation checking problems. The button
is only active if revocation checking occurred but failed.
Check revocation
: Enables manual revocation checking. The button is
only active if no checking occurred AND a check is possible.
Trust
Lists the user-specified certificate trust settings.
Add the certificate to the Trusted Identity list.