Security
What is a certificate chain, and what is a root?
A certificate chain is a line of vouching: your certificate is vouched for by the one that issued it, which is vouched for by the one above, up to a root that vouches for itself. Software trusts a signature by following that line to a root it already recognises.
Every signature result in Verify PDF Signature has a row called Certificate chain, and the certificate details list the chain itself.
The everyday version
You apply for a job and say your name is Maria Santos. Why should anyone believe you?
- Your passport says so. But why believe the passport?
- Because the passport office issued it. Why believe them?
- Because the government set them up for exactly that purpose. And why believe the government?
- Because you already do. That is where the questions stop.
That last step is the root. Not because it is proved, but because it is where trust is anchored. Every chain has to stop somewhere.
The same thing with certificates
A typical chain, read from the bottom up:
- Maria Santos: the signer's certificate. Issued by...
- SomeCo Document Signing CA: an intermediate. Issued by...
- SomeCo Root CA: the root. Signed by itself; the end of the line.
Each level cryptographically vouches for the one below. Software checks the whole line: every link must hold, every certificate must have been in date, and the top must be a root the software already knows.
Why intermediates exist
Why not have the root sign everything directly?
Because a root is precious. Its key is usually kept offline, in a safe, in a building with guards. Using it every day would be reckless. So the root signs a small number of intermediates, and the intermediates do the daily work.
If an intermediate is ever compromised, it can be cancelled and replaced without touching the root. A bit like changing the locks on one office instead of rebuilding the whole building.
How chains reach your computer
Your operating system and your PDF reader ship with a list of roots they trust. A few hundred of them, from authorities around the world. On top of that there are specialist lists: Adobe's AATL for PDF signing, and the EU trusted lists for European regulated signatures.
A signature is "trusted" when its chain ends at a root on one of those lists. Nothing more mystical than that.
Reading the chain in a result
Expand Certificate details and you will see the chain listed, with (root) marked on the self-signed certificate at the top. Two things can go wrong:
"Incomplete: the certificates in the file do not reach a root certificate." The signer's software did not include the middle certificates when it signed. The signature may be perfectly good. The evidence needed to follow it upwards is simply missing from the file. Ask the signer to re-sign with a certificate file that includes its chain.
Chain valid, but trust says "Not trusted". The line holds together, but the root at the top is not on any list we check. Common for company certificates. It is not an accusation.
Why this matters when you sign
When you sign with a .pfx file, a good one contains not only your certificate but the issuer's certificates too. That is why the export instructions say to include all certificates in the certification path. It is what lets a reader on the other side follow your chain without going hunting.
If you know the issuer yourself
If a chain ends at a root you recognise (your employer's, a partner's) you can add that root in the verification tool with "Trust your own certificate". The check runs again treating it as trusted, and the result says exactly that: "The chain ends in a certificate you added for this check. No public trust list vouches for it." Honest, and useful.
Common questions
What is a certificate chain?
A line of certificates in which each one is vouched for by the one above it, ending at a root certificate that signs itself. Software follows the line to decide whether to trust a signature.
What is a root certificate?
The certificate at the top of a chain. It is signed by itself, and it is trusted because it is already on a list your software or a trust programme carries.
Why does my result say the chain is incomplete?
The intermediate certificates were not included in the file when it was signed, so the line cannot be followed up to a root. Ask the signer to re-sign with a certificate file that includes its full chain.
What is an intermediate certificate for?
It does the day-to-day issuing so the root's key can stay offline and protected. If an intermediate is compromised it can be replaced without affecting the root.
The chain is valid but the signature is not trusted. Why?
The chain holds together, but the root at the top is not on any list we check. That is normal for certificates a company issues internally.
Can I add a root I trust myself?
Yes. Add it with 'Trust your own certificate' and check again. The result will state that it is trusted only because you added it.