Skip to main content
Participating Frequently
September 9, 2026
Question

Why doesn't the signature validator honour the id-etsi-extension-validityAssured-ST-1 extension in signing certificates

  • September 9, 2026
  • 10 replies
  • 64 views

If a signing certificate has the extension `id-etsi-extension-validityAssured-ST-1` (defined in this etsi standard), adobe doesn’t honour the extension, but instead looks for LTV data for the signing certificate. Since none is present in the /DSS, Adobe states that the signers identity isn’t valid (because of expiration or not yet valid).

The proper behaviour should be that if the certificate has that extension, and its validity is within the signing time of the signature and covered by a time stamp, Adobe should validate the identity as  trusted.
I’m aware that I can change the preferences for Signature validation to ignore document validation information, but this is a very blunt way to solve this. IMHO the validation should be able to make this distinction automatically.

Is there any plans to make changes to the signature validation process? 

    10 replies

    Participating Frequently
    September 10, 2026

    Hi. Yes of course, I should’ve added that information.
    I’m on Mac OS but I know windows users have experienced it as well. 
    I’m on this Adobe Acrobat version: 

    Architecture: arm64

    Processor: Apple M2 Pro

    Build: 26.2.21869.0

    AGM: 8.0.3

    CoolType: 11.0.0

    JP2K: 5.0.0.59456

    The Signature is of the PAdES -B-LT level, QES and the certificate chain leads to an EUTL trust anchor.

    Here’s a pic of the signature panel:

    And here’s a pic of the certificate details:
     

    And here’s a pic of the signature properties:
     

    Here’s a pic on the advance properties:
     

    And here’s a pic on the timestamp certificate:
     


    My Signature Verification Preferences looks like this:
     

    It only validates with a green check mark if I have unticked the “Require certificate revocation checking to succeed whenever possible during signature verification” box. Irrelevant how I have the two following boxes ticked. 
    Another  interesting note is that it seems like Adobe validates the signature at Current Time, even though in the preferences it states that it should do it at the Secure time (timestamp). 


    I understand that it’s difficult to debug the issue without me sharing a signed PDF that has it. 
    I’ll try to see if I can get permission to share one here. Will get back to you about that. 

    A little more background, especially for you MikelKlink (I assume you’re mkl on Stackoverflow): Where I work we use the iText library to handle pdfs and do the signing operation. For this particular signature provider, which uses these end-user certificates with the valassured-ST-certs extension(provider documentation), we previously used iText7 to add the LTV-data to the /DSS. That made the CRL for these certificates being included. When we migrated to iText9, the code that adds LTV-data is more modern and honours the “valassured“ extension and doesn’t add any CRL. 
    So documents signed using the older code validates fine in Adobe (and has a CRL for the signing certificate), but the ones using the new code has the issue described(and are missing a CRL for the signing certificate). 

    Again I will try to get permission to share a signed document.

    Thank you, and looking forward to your input.

    MikelKlink
    Participating Frequently
    September 10, 2026

    Another  interesting note is that it seems like Adobe validates the signature at Current Time, even though in the preferences it states that it should do it at the Secure time (timestamp). 

     

    Not just an interesting note, this is why Acrobat reports the verdict that the signer certificate is expired. The question is, what makes Acrobat select that validation time. If Acrobat is happy with your time stamp, validation time should be the time stamp time.

    It only validates with a green check mark if I have unticked the “Require certificate revocation checking to succeed whenever possible during signature verification” box. Irrelevant how I have the two following boxes ticked. 

    When you uncheck that box, does the validation time switch to the time stamp time? And what happens if you select “Time at which the signature was created” instead of “Secure time (timestamp) embedded in the signature”?

    Participating Frequently
    September 10, 2026

    When I uncheck that box, it validates against the timestamp time and it is valid
     


    When I select “Time at which the signature was created”, and have the above box ticked, it validates against the secure (timestamp) time, but it says that the validity is UNKNOWN,  see this pic:
     

     

    So the signature is only found to be Valid if the “Require certificate revocation checking to succeed whenever possible during signature verification” is unchecked , regardless which one of the top two verification time options that are chosen. (choosing Current time doesn’t validate obviously)
    And if that box is ticked, it never validates green.

    MikelKlink
    Participating Frequently
    September 10, 2026

    > Since none is present in the /DSS, Adobe states that the signers identity isn’t valid (because of expiration or not yet valid).

    Hmmm, "because of expiration or not yet valid" does not sound like being related to Acrobat missing validation related information but more like the signing time is not in the (short) certificate lifetime. 

    Can you share a signed PDF that illustrates the issue? (To reproduce and analyze the issue.)

     

    Anand Sri Bhattacharya
    Community Manager
    Community Manager
    September 9, 2026

    Hello @focused_Whirlc99c,

     

    I hope you are doing well, and thanks for reaching out. We're sorry for the trouble you had.

     

    Could you please share more details about the issue/workflow?

     

    1. Which platform are you using: Windows or macOS?

    2. What exact Acrobat/Acrobat Reader version and build shows this validation behaviour? Check from Menu (Win) | Acrobat (Mac) > Help > About Adobe Acrobat.

    3. Is the affected signature PAdES Baseline (for example B-T/B-LT/B-LTA), and which profile is being produced?

    4. Does the signing certificate chain to an Adobe-trusted/AATL or EUTL trust anchor, or to a separately configured trusted CA?

    5. Can you share the exact Acrobat Signature Properties/validation message shown for the signer certificate when id-etsi-extension-validityAssured-ST-1 is present?

     

    Please ensure you have the latest version of Acrobat installed on the machine: 26.002.21901, Planned update, Sep 08, 2026. Check for any pending updates by navigating to Menu > Help> Check for Updates. Install the updates, restart the app and the machine, and try again.

     

    Open the PDF’s Signatures panel, select Options > Validate Signatures, and then open Signature Properties > Show Signer’s Certificate. Record:

    • The signer identity-status message

    • Certificate validity dates and chain status

    • Timestamp status

    • Whether the timestamp certificate is trusted

    • Any revocation-status message
      Acrobat documents signer-certificate trust and timestamp verification as separate validation checks.

    • Please check this article for more details: https://adobe.ly/46aw3VB

     

    Review, but do not broadly disable, the signature-validation settings:

    • Windows: Menu > Preferences > Signatures > Verification: More

    • macOS: Acrobat > Preferences > Signatures > Verification: More

    Check the current Verification Time, Use expired timestamps, and certificate-revocation settings. Adobe warns that changing these options can affect document security, so I would not recommend ignoring document validation information as a general workaround. Check this article for more information: https://adobe.ly/4gUQ1IL

     

    Confirm that the certificate chains to the expected trusted root. If AATL/EUTL trust is expected, verify that trust-list updates are enabled under Preferences > Trust Manager and select Update Now where applicable. For a private PKI, verify that the intended trust anchor, not only the end-entity certificate, is configured appropriately. Reference help article: https://adobe.ly/4iVFtM1

     

    As a diagnostic on a copy of the PDF, right-click the signature and select Add Verification Information, if available, then save and revalidate the file. Please note that the command is available only under specific conditions, including a valid signature trusted through a certificate chain and a verification time other than Always use current time. Reference help article: https://adobe.ly/4yo0DXD

     

    I hope this helps, and please let us know how it goes, and reach out if you need any assistance.

     

    Regards,

    Anand Sri.