Skip to main content
Participant
November 11, 2019
Answered

Signature validation using AIA extension (not enabled by default)

  • November 11, 2019
  • 1 reply
  • 3047 views

Hello,

 

We discovered that Adobe signature validation doesn’t build the certificate path using the Authority Information Access (AIA) extension by default. This causes validation issues when validating qualified electronic signatures issued by an intermediate CA (not listed in a EU Trusted List) for which the Root CA is listed in a EU Trusted List; Adobe can't build the certificate path until this Root CA and so can't validate this signature as qualified.

 

The only way we found (cf. here) to activate the certificate path building using the AIA extension via Adobe in Windows is:

  1. Open the “Registry Editor”;
  2. Access to “HKEY_CURRENT_USER\Software\Adobe\Acrobat Reader\DC\Security\cASPKI\cAdobe_ChainBuilder”;
  3. Create a new “DWORD Value” named “bFollowURIsFromAIA” and set the value to “1”.

But, as this manipulation may not be easy for everyone, we were wondering if there were other ways to activate this feature? Or if a user-friendly ‘enabling checkbox’ is planned in the future?

 

We were also wondering why this ‘feature’ is not activated by default? Is it for security purposes (e.g. not downloading a certificate from an untrusted source)? Otherwise, is this ‘feature’ planned to be enabled by default in the future?

 

Thank you in advance.

This topic has been closed for replies.
Correct answer AndreaValle

Acrobat by default does not build certificate path using the AIA extension because this creates issues with multiple cross-certified path that exist under the AATL (mainly from the US Federal Bridge PKI). Normally this is not required if the signature follows the recommended practice to include the full certificate chain in the signature.

In the future Acrobat might expose this option in the Signature Preference panel, but at the moment this has not been confirmed.

1 reply

AndreaValle
Adobe Employee
AndreaValleCorrect answer
Adobe Employee
February 4, 2020

Acrobat by default does not build certificate path using the AIA extension because this creates issues with multiple cross-certified path that exist under the AATL (mainly from the US Federal Bridge PKI). Normally this is not required if the signature follows the recommended practice to include the full certificate chain in the signature.

In the future Acrobat might expose this option in the Signature Preference panel, but at the moment this has not been confirmed.

xschlAuthor
Participant
February 4, 2020

Dear Andrea,

Thank you for your answer. An option in the Signature Preference panel would be indeed very useful.

Best regards.