Hi,
I am hoping someone can help me. Please understand that i am new to this so I might sound a bit stupid. I have been asked to setup digital signatures (for our own internal use only) in my company and I am having some difficulties in doing so. It took some time but I managed to get an internal CA up and running and now I have my own digital ID. When I use this digital signature to sign a test document and send it to my colleague, he gets the following message:
'Signers identity is unknown because it has not been included in your list of trusted identities and none of its parent certificates and trusted identities'
The good news is that I managed to get past this error message on MY own PC. In Adobe Professional, I went to Edit=> Preferences => Security => Advanced Preferences => Trust All root certificates in the Windows Certificate Store for the following operations => Selected 'Validating Signatures' This worked. I checked this up and it said:
Windows Integration:
Specify whether to trust all root certificates in the Windows Certificates feature when validating signatures and certified documents. Selecting these options can compromise security. Note: It is not recommended to trust all root certificates in the Windows Certificate feature. Many certificates that are distributed with Windows are designed for purposes other than establishing trusted identities.
My problems is that I don't know how to get rid of this error message using another solution. What are the drawbacks of having this selected?
The second error message I get is as follows:
'Signature is valid but revocation of the signer's identity could not be checked'
Again I am able to solve this by going to Edit=> Preferences => Security => Advanced Preferences => UNTICKING 'Require certificate revocation checking to succeed whenever possible signature verification' When this option is unchecked the error goes away and my signature is fine.
We are using signatures for internal use only so is revocation checking necessary?
Thanks in advance if anyone can help.
Regards,
Declan
P.S I have it working but to be honest, I don't know why!! :o) :o) :o)