Home / Support / Validating Your Captures

How to Validate Your Forensic OSINT Captures in Adobe

Confirm your PDF evidence has not been altered since capture, and understand Adobe's trust warning

Every Forensic OSINT capture is exported as a PDF that is digitally signed at the moment it is created. That signature lets anyone confirm, at any time, that the document is byte-for-byte identical to what was captured, with no later alterations.

When you first open a signed capture in Adobe Reader or Acrobat, you may see a message that the signature validity is unknown, or that "at least one signature has problems." This guide explains what that message really means, and walks you through validating the signature so Adobe displays a green check instead.

What Actually Matters for Evidentiary Integrity

The important line is the one Adobe shows first:

check_circle

"The document has not been modified since this signature was applied." This is the part that matters for evidentiary integrity. It is Adobe cryptographically confirming the PDF is unchanged, byte-for-byte, since the moment it was signed. That is the tamper-evidence, and it is intact.

Adobe validates two independent things: whether the document was altered (integrity), and whether it recognizes the signer (identity, or trust). These are separate checks. When the line above appears, the integrity check has passed. A trust warning does not change that, and it does not affect the validity of the signature.

Why Adobe Shows a "Validity Unknown" Warning

The "Signature validity is UNKNOWN" warning is the identity check, not the integrity check. It is a trust-configuration message, not a sign that anything is wrong with the file.

Adobe automatically trusts a signature only when its certificate chains up to a root on the Adobe Approved Trust List (AATL), plus any certificates you have added yourself. Anything else shows as "unknown" until you explicitly trust it. Out of the box, that is every signer Adobe has not been told to trust, so this warning is expected and looks the same on every default Adobe install.

lightbulb

In short: "Not modified" is about the evidence. "Validity unknown" is about your local Adobe settings. The steps below add the signing certificate to Adobe's trusted list so the warning is replaced with a green validation check.

1

Open the Signature Panel

  1. Open your capture PDF in Adobe Reader or Acrobat.
  2. Open the Signature Panel (the notification bar at the top usually has a link, or use View → Show/Hide → Navigation Panes → Signatures).
  3. Click the dropdown menu next to Validate All and select Validate Signature.
  4. Click the Signature Properties... button.
Adobe Signature Panel showing the Validate Signature option
2

Review the Signature Properties

The Signature Properties window shows the details of the digital signature. This is where you will see the confirmation that the document has not been modified since it was signed.

  1. Read the summary at the top. Look for the line confirming the document has not been modified since the signature was applied.
  2. Click Show Signer's Certificate... to inspect the certificate.
Adobe Signature Properties window with Show Signer's Certificate button
3

View the Certificate

  1. The Certificate Viewer opens and displays the signing certificate details on the Summary tab.
  2. Click the Trust tab at the top of the window.
Adobe Certificate Viewer Summary tab
4

Open the Trust Tab

On the Trust tab you will see that the certificate is not yet trusted for signing. This is the default state described above.

  1. Click Add to Trusted Certificates...
Adobe Certificate Viewer Trust tab with Add to Trusted Certificates button
5

Set the Trust Settings

  1. In the trust settings window, select Use this certificate as a trusted root.
  2. Also select Certified documents.
  3. Click OK.
info

The Dynamic Content, Embedded high privilege JavaScript, and Privileged system operations options do not need to be selected.

Adobe trust settings window with trusted root and certified documents selected
6

Re-Validate the Signature

  1. Close the certificate windows to return to the document.
  2. In the Signature Panel, click the menu icon again and select Validate Signature.
Re-validating the signature in the Adobe Signature Panel
7

Confirm the Signature Is Valid

Adobe now shows a green check and the message "Signed and all signatures are valid." The signer's identity is displayed instead of the earlier warning.

Adobe confirming Signed and all signatures are valid
lightbulb

Nothing about the file changed. The signature was always valid and the document was always unaltered. Once you (or your organization) tell Adobe to trust the signing certificate, Adobe shows the signer's identity and a green validation check instead of the warning. Only the local trust setting changed.

A Second, Independent Proof

Independent of Adobe, Forensic OSINT also records the cryptographic hash of every capture in our system. A hash is a unique fingerprint of the file: if even a single byte changes, the hash changes.

So if signature validation is ever questioned in a proceeding, the hash gives you a second, independent way to prove the PDF has not been altered. You are never relying on Adobe's trust settings alone.

fingerprint

Two independent checks back every capture: the embedded digital signature verified in Adobe, and the cryptographic hash recorded at capture time. Either one confirms the document is unchanged.

View Your Trusted Certificates

Once a certificate has been trusted, you can confirm it is on your list at any time:

  1. In Adobe, go to Edit → Preferences.
  2. Select Signatures from the left menu.
  3. Under Identities & Trusted Certificates, click More... to view the certificates Adobe currently trusts.
Location of trusted certificates in Adobe Signature preferences
lightbulb

Related: Learn more about how our captures are built to withstand legal scrutiny on our Court Admissibility page.

help_outline

Questions about validation?

If a signature or hash is ever challenged, our team can help. Contact us: Support@ForensicOSINT.com

Browse Support →

Capture evidence that holds up

From capture to courtroom, evidence integrity at every step.

Minimum Requirements:

  • 8 Characters
  • 1 Upper
  • 1 Lower
  • 1 Digit