A digital signature proves the document has not changed and that a particular certificate signed it. Whether that certificate belongs to who you think is a separate question.
What actually happens
Signing runs the whole document through a hash function, producing a short fixed-length fingerprint. Change one byte anywhere and the fingerprint changes completely.
That hash is then encrypted with the signer's private key and stored in the file along with their certificate. Verification reverses it: the reader hashes the document itself, decrypts the stored hash with the public key from the certificate, and compares.
If the two match, the document is byte-identical to what was signed and the signature was produced by whoever holds that private key. Both facts follow from mathematics rather than from anyone's assurance, which is what makes this different from a drawn signature.
The two claims, and the one it does not make
| Claim | Proven? | By what |
|---|---|---|
| The document has not changed | Yes | The hash comparison |
| This certificate signed it | Yes | The public key decryption |
| The certificate belongs to that person | Not by the maths | The issuing authority |
| The signer intended to agree | No | Context and law |
| The signing date is accurate | Only with a timestamp | A timestamp authority |
That third row is where the trust actually lives. Anyone can generate a self-signed certificate saying anything — the cryptography works perfectly and proves only that the holder of that self-made key signed. A certificate from a recognised authority means someone verified the holder's identity before issuing it, and that verification is what you are relying on.
Reading the status message
Readers report several states and they mean quite different things.
- "Signed and all signatures are valid." Hash matches, certificate chains to a trusted root. The strongest result.
- "Validity is unknown" or "not trusted." The hash matches — nothing has been altered — but the certificate does not chain to a root your reader trusts. Common with self-signed certificates and with corporate internal ones.
- "Document has been altered or corrupted." The hash does not match. Something changed after signing, even if only a re-save.
- "Signature is valid, but the document has been updated." A later incremental save added something. The signed version is intact and there is content after it.
- "Certificate has expired." Valid at signing, expired since. With a trusted timestamp this is fine; without one you cannot show it was signed before expiry.
The second state causes the most confusion. "Unknown validity" is not a failure — the integrity check passed. It means your reader has no basis for believing the identity, which is a different and often acceptable situation.
What invalidates one
Any change to the file bytes, without exception. This catches people who did something innocuous.
- Compressing after signing. Re-encodes images, changes bytes.
- Merging with another document.
- Rotating a page, which is a one-number change and still a change.
- Adding a watermark or a stamp as page content.
- Re-saving in some editors, which rewrite the structure even with no visible edit.
- Flattening, which merges annotations into the page.
Hence the ordering rule that keeps appearing: assemble, compress, watermark, then sign, then encrypt. Signing is second to last because everything before it changes the file and everything after it must not.
Removing a signature
Two quite different requests get worded the same way.
Removing a signature image — a drawn or pasted graphic — is straightforward if it was added as an annotation: select and delete. If it was flattened into the page it is page content, and removing it means editing the page or covering it, with the usual caveat that covering is not removing.
Removing a cryptographic signature is possible in most editors via a "clear signature" action, if you have permission. Doing so does not conceal anything — the document then simply carries no signature, and any earlier signed revision may still be inside the file if it was saved incrementally.
Worth being plain: there is no way to alter a digitally signed document and have the signature still validate. That is the entire point of the mechanism. Anything claiming otherwise is either removing the signature or misrepresenting what it did.
When it is worth the effort
Most agreements do not need this. A drawn signature plus the surrounding email trail is what almost everyone uses and it is legally sufficient — the position is set out in are e-signatures legally binding.
A cryptographic signature earns its cost where integrity has to be demonstrable to a third party: regulated filings, tender submissions, audited financial statements, published software, anything a court might examine.
For those, add a trusted timestamp as well. Without one, an expired certificate leaves you unable to show the signature predates expiry — and certificates are typically valid for one to three years, while documents last longer than that.
Frequently asked questions
What does a digital signature actually prove?
Two things: the document is byte-identical to what was signed, and the holder of that specific private key signed it. It does not prove the certificate belongs to the person named on it — that depends on who issued the certificate.
Why does my reader say "validity unknown"?
The integrity check passed — nothing has been altered — but the certificate does not chain to a root your reader trusts. Common with self-signed and corporate internal certificates. It is not a failure, just an absence of identity assurance.
Why did my signature become invalid?
Something changed the file after signing. Compressing, merging, rotating a page, adding a watermark, flattening, or even re-saving in an editor that rewrites the structure. Sign second to last — after everything else, before encryption.
Can a digitally signed PDF be edited?
Not while keeping the signature valid. Any byte change breaks the hash comparison, which is the entire point. You can remove the signature and then edit, but the document then carries no signature rather than a valid one.
How do I remove a signature from a PDF?
A drawn signature image added as an annotation can be selected and deleted. If it was flattened it is page content and must be edited out or covered — and covering is not removing. A cryptographic signature can be cleared in most editors if you have permission.
Do I need a timestamp?
For anything long-lived, yes. Certificates are valid for one to three years and documents last longer. Without a trusted timestamp you cannot demonstrate the signature was applied before the certificate expired.