You open a PDF and a blue, yellow or red bar appears talking about signatures. Or your signing tool refuses to sign because "the document is encrypted". Or a client asks whether that signature "counts". This guide explains, message by message, what each warning means — and how to verify a signature without depending on Adobe Acrobat.
If you first want to understand how a digital signature works inside, read what a digital signature is and how to verify a signed PDF.
First: is it a digital signature or just an image?
People often ask "how can I tell if the signature on this PDF is handwritten?". The distinction is this:
- Scanned signature (image): a photo or scan of a handwritten signature pasted into the document. It has no cryptographic protection — anyone can copy and paste it. Visually, it is just a picture;
- Digital signature: a cryptographic block embedded in the file and tied to a certificate. It may have an image attached, but what counts is the certificate behind it.
How to tell them apart: open the PDF in a reader that shows a signature panel (see below). If the panel is empty, there is no digital signature — what you see is just an image. Clicking the "signature" also helps: a digital signature opens a window with certificate details; an image does nothing.
What the most common warnings mean
"Signed and all signatures are valid" (blue/green bar)
The document has not been altered since it was signed and the certificate comes from a chain the reader trusts. The best-case scenario.
"Signature validity is unknown"
The signature is intact (the document was not altered), but the reader does not know the authority that issued the certificate. This is common with national or corporate certificate authorities that are not on the reader's trust list. It does not mean the signature is fake — it means your software cannot tell. The fix is to validate it with an official validator that recognises that authority (see below).
"At least one signature has problems"
This can mean:
- unknown validity for one of the certificates (the previous case);
- the document was altered after signing — someone merged, compressed, removed pages from or "printed to PDF" the signed file, creating a new file without a valid signature;
- the certificate was expired or revoked at the time of signing.
Open the signature panel to see which signature has a problem and why.
"The document has been altered or corrupted since the signature was applied"
This is the serious warning: the content covered by the signature has changed. Sometimes it is legitimate (a second person signed afterwards and the reader shows the revisions), sometimes not. Ask the sender for the original file.
"My signing tool says the PDF is encrypted" — what to do
Some PDFs have an open password or permission restrictions (no editing, printing or copying). Many signing tools refuse these files, because signing requires writing new data into the PDF.
What to do:
- If you created the document, generate the PDF again without a password or restrictions;
- If you received the protected PDF and know the password, create an unlocked copy and sign the copy. RoseLab's PDF tools ask for the password and create the unlocked copy right in your browser — see how to use a password-protected PDF without uploading it;
- Careful: if the PDF already has signatures, unlocking or recreating the file invalidates them. In that case, ask the sender for a version prepared for signing.
Sealed PDF vs signed PDF
E-signature platforms often use both terms:
- Signed: each signer applied their own signature (with a digital certificate or the platform's method — email, SMS code, ID check);
- Sealed: after everyone has signed, the platform applies its own digital signature (a seal) to the final file, "locking" the document and recording the audit trail. If anyone alters the file afterwards, the seal is no longer valid.
In practice, the seal is how the platform guarantees the integrity of the document as a whole — which is why the file must be kept exactly as it was downloaded.
Simple, advanced and qualified signatures
In the European Union, the eIDAS regulation defines three levels of electronic signature, and many other countries use similar tiers:
| Level | What it is | Example |
|---|---|---|
| Simple | Any electronic indication of intent to sign | Ticking "I agree", typing your name, a scanned signature |
| Advanced | Uniquely linked to the signer, under their sole control, and able to detect later changes | Certificate-based signatures from e-signature platforms |
| Qualified | An advanced signature created with a qualified certificate and device | Signatures with a qualified certificate from a trusted provider |
A qualified signature has the strongest legal effect — in the EU it is equivalent to a handwritten signature. In the United States, the ESIGN Act and UETA give electronic signatures legal validity without fixed tiers; what matters is proving intent and the integrity of the record. A "simple signature with hash and date" — where the system records the document's hash and the time of acceptance — is a valid electronic signature with an integrity trail, useful for many transactions, but it is not equivalent to a qualified signature.
How to verify a PDF signature without Adobe
- Official validators: many countries and the European Commission offer free online validators (for example, the EU's DSS demonstration validation service). Be aware that these services usually require uploading the file;
- LibreOffice: open the PDF in LibreOffice and go to File › Digital Signatures to see the signatures and their status;
- Other PDF readers (such as Foxit, and Okular on Linux) also have a signature panel;
- Your browser is not enough: Chrome, Edge and Firefox display the PDF but generally do not show signature validation status. A PDF that "opens fine" in the browser tells you nothing about its signature.
Signed it? Stop touching the file
The most common mistake of all: signing and then merging with other PDFs, compressing, removing pages or "printing to PDF" to reduce the size. Each of these creates a new file — and the original's signature does not come along. The right order is:
- Prepare everything first: merge, compress, remove pages;
- Sign last;
- Send the signed file exactly as it came out of the signing tool;
- For an extra record, keep the SHA-256 hash of the signed file — if someone presents a different version, the hash shows it instantly.
Frequently asked questions
Why does Adobe say the signature validity is unknown? Because the certificate chain used may not be on Adobe's trust list. The signature itself may be perfect; check it with an official validator for that certificate authority.
Does opening a signed PDF in the browser break the signature? No. Reading changes nothing. The problem is saving a new version or generating another file from it.
Can I merge two signed PDFs and keep the signatures? No: the merged PDF is a new file. Send the signed PDFs separately, or merge first and sign afterwards.
Does a hash replace a digital signature? No. A hash proves the file did not change; a signature proves who signed it. They complement each other — see the guide to document encryption.
Ready to put it into practice?
Free, no sign-up — and your files never leave your computer.
Check a PDF's integrity now — free