Security

How to verify a PNPKI digitally signed PDF in the Philippines

PNPKI certificates are issued under the Philippine National Public Key Infrastructure run by the DICT and chain to the Philippine Root CA, which Adobe does not include by default, so signatures often show as having problems even when they are intact. Check that the signature is valid and nothing changed after signing, confirm the chain ends at the genuine Philippine root, and only then add that root to your trusted certificates.

4 min read

Philippine government agencies, state universities and local government units increasingly sign documents with certificates from the Philippine National Public Key Infrastructure (PNPKI), operated by the Department of Information and Communications Technology (DICT). Recipients then open the PDF in Adobe Reader and see a yellow bar: "At least one signature has problems." Here is what that means and how to verify properly.

The short answer

  • PNPKI certificates chain to the Philippine Root CA: the certificate the DICT's guidance tells users to install is named Philippine Root CA - G2.
  • That root is not included in Adobe's trust list by default, so Adobe cannot confirm the signer's identity and shows a warning. The DICT's own troubleshooting guidance says both signers and recipients must add the root to Adobe's trusted certificates, once per device.
  • The document may still be completely intact. Check integrity first, confirm the root, then trust it.
  • The Electronic Commerce Act of 2000 (Republic Act No. 8792) gives electronic documents and signatures legal recognition, and the Rules on Electronic Evidence govern how they are proved in court.
  • The PNPKI provides government-issued certificates. The DICT's FAQ says any individual of legal age with the required documents may apply, and government agencies use them widely to sign official documents.
  • Individuals can hold two kinds of PNPKI certificate: an authentication certificate, for logging in to systems and signing or encrypting email, and a signing certificate, for digitally signing documents such as PDF and Word files. On a signed PDF, expect the signing certificate.

What a genuine PNPKI chain looks like

When you open Certificate details on a PNPKI-signed PDF, the chain should read, from bottom to top:

  1. The signer: an individual (often a government employee) or, for agency-level signatures, the agency.
  2. One or more PNPKI issuing authorities: the DICT certification authority that issued the signer's certificate.
  3. The root: Philippine Root CA - G2.

If the chain stops before the root, the signer's software did not embed the full chain; the signature can still be intact, but ask for a properly signed copy if identity matters. If the chain ends at an unrelated root or the certificate is self-signed, it is not a PNPKI certificate, whatever name it shows.

Step 1: check integrity and changes

Upload the PDF, exactly as received, to Verify PDF Signature:

  • Signature: Valid with Unchanged since [name] signed it: the signed content is intact.
  • Changes after signing: listed page by page. On a memorandum, certificate or payroll document, a changed page after signing is a warning sign; a co-signer's later signature is normal.
  • Compare the changed pages and Download the version that was signed show you exactly what was signed.

This check does not depend on trust settings.

Step 2: confirm the chain

In Certificate details, the Certificate chain should run from the signer, through a PNPKI issuing authority, up to the Philippine Root CA. Trust: Not trusted may appear here too, because that root is not on this service's list. It describes the list, not the signature.

To be sure the root is genuine, compare its SHA-256 fingerprint with the root certificate the DICT publishes through its official PNPKI pages.

Step 3: make Adobe recognise PNPKI signatures

Following the same approach the DICT describes:

  1. Right-click the signature and choose Show Signature Properties.
  2. Click Show Signer's Certificate.
  3. In the certificate viewer, select the topmost certificate. The Philippine Root CA.
  4. Open the Trust tab and click Add to Trusted Certificates.
  5. Tick Use this certificate as a trusted root and confirm.
  6. Close the windows and click Validate Signature.

You only need to do this once per computer. Do it only after confirming the root's fingerprint. Trusting a root means trusting everything it issues. More detail: Why Adobe says “Signature validity is unknown”.

Revocation and long-term validity

If a PNPKI certificate is revoked (for example, when an employee leaves or a key is lost), later checks will report it. Signatures made before the revocation remain valid, but proving that later requires a trusted timestamp or long-term validation data in the signature. Our report shows the Revocation, Timestamp and Long-term validation rows separately; see What is LTV, and why does my signed PDF say the certificate expired?

Common real-life situations

"The agency's PDF shows a signature, but the checker finds none"

The file was probably printed to PDF, scanned or re-saved after signing. Ask the agency for the original signed file.

"One signature is fine, the other has problems"

Look at each signature: they may come from different chains (one PNPKI, one commercial), or something was added after the first signature. The changes list shows what.

Verifying a certificate or clearance

Many Philippine agencies also provide online verification for documents they issue, such as a reference number or QR code checked on the agency's own site. Use it: reached through the agency's official site you found yourself. See How to verify a government certificate or university degree PDF.

Common questions

Why does Adobe say “At least one signature has problems” on a PNPKI document?

Because the Philippine Root CA is not included in Adobe's trust list by default, so Adobe cannot confirm the signer's identity. The document may still be intact; check integrity, then add the root to your trusted certificates.

How do I add the Philippine Root CA to Adobe?

Open the signature properties, click Show Signer's Certificate, select the topmost certificate (Philippine Root CA - G2), open the Trust tab, click Add to Trusted Certificates, tick Use this certificate as a trusted root, confirm and validate the signature again.

Do I need to do this every time?

No, once per computer. The trust setting stays in Adobe on that device.

Is a PNPKI digital signature legally valid?

The Electronic Commerce Act of 2000 recognises electronic signatures, and PNPKI certificates are the government's own. How a document is proved in court follows the Rules on Electronic Evidence.