Adobe 22020737 Acrobat X Pro Manual - Page 261

Setting up signature validation, Set signature verification preferences, Verification options

Page 261 highlights

USING ACROBAT X PRO 255 Digital signatures Setting up signature validation When you receive a signed document, you may want to validate its signature(s) to verify the signer and the signed content. Depending on how you have configured your application, validation may occur automatically. Signature validity is determined by checking the authenticity of the signature's digital ID certificate status and document integrity: • Authenticity verification confirms that the signer's certificate or its parent certificates exist in the validator's list of trusted identities. It also confirms whether the signing certificate is valid based on the user's Acrobat or Reader configuration. • Document integrity verification confirms whether the signed content changed after it was signed. If content changes, document integrity verification confirms whether the content changed in a manner permitted by the signer. Set signature verification preferences 1 In Acrobat or Reader, click Edit > Preferences. 2 From the Preferences dialog box, select Security on the left. 3 To automatically validate all signatures in a PDF when you open the document, select Verify Signatures When The Document Is Opened. This option is selected by default. 4 Click Advanced Preferences, and then click the Verification tab. 5 Select verification options. 6 (Windows only) Click the Windows Integration tab, and specify whether you can import identities from the Windows Certificates feature into the list of trusted identities. In addition, specify whether to trust all root certificates in the Windows Certificates feature when validating signatures and certified documents. Selecting these options can compromise security. Note: It is not recommended to trust all root certificates in the Windows Certificate feature. Many certificates that are distributed with Windows are designed for purposes other than establishing trusted identities. Verification options When Verifying These options specify methods that determine which plug-in to choose when verifying a signature. The appropriate plug-in is often selected automatically. Contact your system administrator about specific plug-in requirements for validating signatures. Require Certificate Revocation Checking To Succeed Whenever Possible During Signature Verification Checks certificates against a list of excluded certificates during validation. This option is selected by default. If you deselect this option, the revocation status for approval signatures is ignored. The revocation status is always checked for certifying signatures. Verify Signatures Using Select an option to specify how to check the digital signature for validity. By default, you can check the time based on when the signature was created. Alternatively, check based on the current time or the time set by a timestamp server when the document was signed. Use Expired Timestamps Uses the secure time provided by the timestamp or embedded in the signature, even if the signature's certificate has expired. This option is selected by default. Deselecting this option allows discarding of expired timestamps. Last updated 10/11/2011

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496

255
USING ACROBAT X PRO
Digital signatures
Last updated 10/11/2011
Setting up signature validation
When you receive a signed document, you may want to validate its signature(s) to verify the signer and the signed
content. Depending on how you have configured your application, validation may occur automatically. Signature
validity is determined by checking the authenticity of the signature’s digital ID certificate status and document
integrity:
Authenticity verification confirms that the signer's certificate or its parent certificates exist in the validator’s list of
trusted identities. It also confirms whether the signing certificate is valid based on the user's Acrobat or Reader
configuration.
Document integrity verification confirms whether the signed content changed after it was signed. If content
changes, document integrity verification confirms whether the content changed in a manner permitted by the
signer.
Set signature verification preferences
1
In Acrobat or Reader, click Edit > Preferences.
2
From the Preferences dialog box, select Security on the left.
3
To automatically validate all signatures in a PDF when you open the document, select Verify Signatures When The
Document Is Opened. This option is selected by default.
4
Click Advanced Preferences, and then click the Verification tab.
5
Select verification options.
6
(Windows only) Click the Windows Integration tab, and specify whether you can import identities from the
Windows Certificates feature into the list of trusted identities. In addition, specify whether to trust all root
certificates in the Windows Certificates feature when validating signatures and certified documents. Selecting these
options can compromise security.
Note:
It is not recommended to trust all root certificates in the Windows Certificate feature. Many certificates that are
distributed with Windows are designed for purposes other than establishing trusted identities.
Verification options
When Verifying
These options specify methods that determine which plug-in to choose when verifying a signature.
The appropriate plug-in is often selected automatically. Contact your system administrator about specific plug-in
requirements for validating signatures.
Require Certificate Revocation Checking To Succeed Whenever Possible During Signature Verification
Checks
certificates against a list of excluded certificates during validation. This option is selected by default. If you deselect this
option, the revocation status for approval signatures is ignored. The revocation status is always checked for certifying
signatures.
Verify Signatures Using
Select an option to specify how to check the digital signature for validity. By default, you can
check the time based on when the signature was created. Alternatively, check based on the current time or the time set
by a timestamp server when the document was signed.
Use Expired Timestamps
Uses the secure time provided by the timestamp or embedded in the signature, even if the
signature’s certificate has expired. This option is selected by default. Deselecting this option allows discarding of
expired timestamps.