Skip to main content
New Participant
June 3, 2019
Question

How to disable pin caching for digital signatures?

  • June 3, 2019
  • 2 replies
  • 3564 views

Hi,

I have stored a digital certificate for digital signing of pdf files on a USB token (Yubikey 5). Usually the key is configured so that it always requires entering the PIN when a document is signed (verified e.g. with the Foxit PDF Reader). However, Adobe Reader DC requests the PIN only for the first document and not if additional documents are signed without restarting the Reader.

Is there any configuration option in the Adobe Reader to configure this behaviour and to enforce an ALWAYS_ENTER_PIN policy?

We contacted also the support of the USB token manufacturer and they also think that it is a special behaviour of the Adobe Reader.

Thanks

Thorsten 

This topic has been closed for replies.

2 replies

New Participant
June 26, 2019

This registry setting has no impact on Adobe Reader DC (independently from the key storage windows certificate store or Yubikey). The reader caches the PIN and the user is not required to reenter the PIN before signing a document, even when the security level was set to high during import of the pfx file

New Participant
August 21, 2021

I have the same issue. Any idea?

Community Manager
June 3, 2019

Hi Thorsten,

Please try adding the following Registry Key and check the behaviour:

Path: HKLM\SOFTWARE\WOW6432Node\Policies\Adobe\(product name)\(version)\FeatureLockdown\cSecurity\cPPKLite

Key Name (DWORD): bAllowPasswordSaving

Value: 0

More information on the Registry Key at https://www.adobe.com/devnet-docs/acrobatetk/tools/PrefRef/Windows/Security.html#idkeyname_1_16100

Regards,

Anoop

New Participant
June 3, 2019

This did not change the behaviour...