Security

What does a self-signed Digital ID prove, and what does it not?

A self-signed Digital ID proves the document has not changed since it was signed, and shows the name you typed. Nobody has checked that name, so other people's software shows the signer as unknown until they choose to trust your certificate.

4 min read

If you do not have a certificate, the Digital Signature tool offers to make one: "Create a free self-signed Digital ID". It takes about a minute and it is made entirely in your browser. This page is about what you get and what you do not.

What it genuinely does

Do not let "self-signed" make you think it is fake. The cryptography is exactly the same as any other certificate. With one, your signed PDF:

  • detects any change. Alter one character after signing and the signature shows as invalid, in any PDF reader.
  • records a name, a date and your reason for signing, as you entered them.
  • cannot be copied onto another document. The signature is tied to the exact bytes it was made for.

That is a lot. For an internal document it may be all you need.

What it does not do

It does not prove who you are.

With a certificate from a certification authority, somebody checked your ID papers before issuing it. With a self-signed one, you typed a name into a box. The certificate faithfully records what you typed. It does not claim anyone verified it, and it should not.

So when somebody else opens your signed PDF, their software shows something like *signature valid, signer unknown*. That is not an error. It is the software being honest: the document is fine, but no authority vouches for the name.

The everyday version

  • Certificate from an authority: a passport. A government checked your documents and issued it. Border officers accept it without knowing you.
  • Self-signed Digital ID: a name badge you printed yourself. It is genuinely yours, and inside your own office everybody knows it is you. At a border, it means nothing.

Both are real objects. They carry different weight with strangers.

When it is a good choice

  • Inside a team that already knows each other. Your colleagues know your email address; they do not need a certification authority to confirm your name.
  • Documents that must be tamper-evident, not identity-proved. A signed-off version of a spreadsheet, a set of minutes, a report you want to be able to prove was not edited.
  • Learning and testing. Trying out signing, timestamps and verification before buying anything.
  • When the recipient will deliberately trust your certificate. They can add it once, and after that your signatures show as trusted to them. In Verify PDF Signature this is the "Trust your own certificate" option, and the result then says plainly *"Trusted because you added it"*, never pretending a public authority vouched for it.

When it is the wrong choice

  • Government or court filings. These almost always name the authorities they accept.
  • Tenders, bank submissions, tax filings. Same.
  • Anything sent to a stranger who must rely on your identity. They have no way to check you are who the certificate says.
  • Anywhere a green tick in Adobe Acrobat is required. Acrobat only shows that for certificates on Adobe's own trust list, and a self-signed ID will never be on it.

One practical limit

A self-signed certificate usually publishes no way to check whether it has been cancelled. That means long-term validation cannot be completed for it. The tool will say so rather than pretend. Your signature still works; it just will not carry its own evidence.

What the creator asks you

  • Your name: what appears as the signer.
  • Email, organisation, country: optional, for context.
  • Valid for: how many years the ID lasts.
  • Key type: RSA 2048 opens in every PDF reader; RSA 3072 is stronger; ECDSA P-256 is compact but needs a recent reader.
  • A password for the .pfx file.

The key pair is generated on your own device, and the file downloads to your computer. Keep it and its password safe: it is the only copy, and nobody can recover either.

If you just need a signature on a page

If what you actually want is your signature visible at the bottom of a form, you do not need a certificate at all. Sign PDF lets you draw, type or upload one and place it. The difference between the two is explained in what is a digital signature in a PDF.

Common questions

Is a self-signed digital signature real?

Yes. The cryptography is identical to any other certificate, so it detects changes to the document and cannot be copied to another file. What it lacks is an outside authority confirming the signer's name.

Why does Adobe say 'signer unknown' for my self-signed signature?

Because no recognised authority issued the certificate. Acrobat is saying the document is intact but it cannot confirm who signed. Recipients can choose to trust your certificate, after which it shows as trusted for them.

Can I use a self-signed ID for a government filing?

Almost never. Official filings usually list the certification authorities they accept. Check with the office before you sign anything important.

Where is the self-signed Digital ID created?

In your own browser. The key pair and the .pfx file are made on your device and downloaded to your computer.

Can I get long-term validation with a self-signed ID?

Usually not. Self-signed certificates publish no cancellation service, so there is nothing to store. The tool reports that rather than claiming LTV was included.

What if I lose the file or the password?

It cannot be recovered. There is only one copy and nothing is stored on our side. You would create a new Digital ID, and documents signed with the old one remain valid.