GhostXStudio tools

How to verify a signed PDF

Updated

Short answer

To verify a signed PDF, open it in a validator that checks the embedded digital signature. It should confirm the document hasn’t changed since signing, whether anything was added afterwards, whether the signing certificate is trusted, and whether any timestamp is valid. A visible signature image on the page proves nothing on its own.

A signature image is not a signature

Many signed PDFs show a handwritten-style signature on the page. That image can be copied onto any document. What makes a PDF verifiable is a cryptographic signature embedded in the file, which binds the document’s bytes to a certificate. Some e-signature services add one; many documents signed by drawing on a page don’t have one at all. Those can be checked another way — by comparing the file’s fingerprint with the one recorded on a certificate or audit trail.

What a validator checks

  1. Integrity: the hash of the signed bytes matches the value in the signature, so nothing in the signed range has changed.
  2. Coverage: the signed range covers the whole file. If bytes were appended after signing — a new annotation, a form edit, another signature — the file has changed since that signature, even though the signature itself still verifies.
  3. The certificate: whether it chains to a trusted root, was valid at signing time, and has not been revoked.
  4. The timestamp: whether a trusted time-stamping authority signed the time, rather than the signer’s own clock.
  5. Permissions: a certification signature can forbid later changes; a validator checks whether later changes, if any, were allowed.

Verifying in Adobe Acrobat or Reader

Open the PDF and look at the signature bar at the top, then open the Signatures panel for details on each signature. A green check means the document is unchanged and the certificate is trusted. ‘Signature validity is unknown’ usually means the cryptography checks out but the certificate doesn’t chain to a source Acrobat trusts. A warning that the document has been modified since it was signed means content was added after the signature; the panel lets you view the version that was signed and compare. A red X means the signed bytes were altered or the signature is broken.

Other ways to verify

On the command line, pdfsig from the Poppler utilities lists every signature in a PDF with its validation status. The European Commission’s DSS demonstration web app validates PAdES signatures against EU trust lists, but it requires uploading the file to the Commission’s servers and is explicitly a demonstration, not a production service — don’t use it for confidential documents.

Verifying a GhostSign document at /verify

GhostX’s /verify page checks embedded signatures in your browser: it confirms the covered bytes match the signature, that the signature is valid, that the signing certificate is the one bound into it, whether the signature covers the whole file, and whether an RFC 3161 timestamp is valid and chains to a pinned DigiCert or Sectigo root. For a valid GhostX seal, it then looks up the seal’s fingerprint in GhostX’s evidence log; that lookup is a network request carrying the hash, not the file.

The result is shown as a plain-language verdict, for example ‘Sealed by GhostX — not modified’, ‘Sealed version intact — but something was added later’, ‘Seal broken — this file was changed’, or ‘Valid digital signature — not a GhostX seal’ for signatures from other services. It also shows the file’s SHA-256, so documents without an embedded signature can be compared against the hashes printed on their certificate.

When a check fails

If the signature is broken or the file was modified after signing, ask the sender for the original signed file and compare fingerprints. Email systems, PDF editors, and ‘optimize’ or ‘reduce size’ functions often rewrite files, which breaks signatures without any bad intent. If the signed version is intact but something was added later, view the signed version to see what the signer actually approved.

Frequently asked questions

  • Does a valid signature prove the signer is who they claim?

    Only as far as the certificate does. A certificate from a provider that verified identity ties the key to a person or organization; a self-issued certificate proves the key holder signed, not who they are. Audit trails and email verification add separate evidence.

  • Why does my signed PDF say it was modified?

    Something was written to the file after the signature — often a form edit, an annotation, or a program rewriting the file. The signed part can still be intact; use the validator’s option to view the signed version.

  • Can I verify a signed PDF offline?

    Integrity and signature checks can run offline. Checking revocation, and lookups in a service’s own records such as GhostX’s evidence log, need a connection.

  • Is it safe to upload a signed contract to an online validator?

    Server-based validators receive the whole file. For confidential documents, use a desktop reader or a validator that runs in your browser.

References