Configure digital signature in Adobe Acrobat

On this page, you will learn how to configure a digital signature for PDF documents
You need a user certificate to sign documents electronically. You can request a user certificate in the RA-Portal and then import the certificate into the Windows certificate store.
Please note:
Group certificates or the digital ID of group certificates, such as those issued for functional e-mail inboxes, cannot be used for electronic signatures because they are not typically associated with a single person, which is a requirement for electronic signatures.
Please follow the steps below to set up a digital signature:
- Security settings in the Adobe Acrobat Reader
- Configure timestamp
- Configure trusted certificates
- Configure digital signature
1. Security settings in the Adobe Acrobat Reader
Step 1
Launch Acrobat Reader an choose Menu > Preferences.
Step 2
Choose Trust Manager and uncheck the boxes for Automatic Adobe Approved Trustlist (AATL) updates and Automatic European Union Trust Lists (EUTL) updates:

Step 3
Choose Signatures and click More in the Identities & Trusted Certificates field:

Step 4
Go to Trusted Certificates, select all listed certificates and click Remove to delete them. You can close the Trusted Certificates Settings now.
- Please note that the Adobe Root CA G2-Certificate (and sometimes also the Adobe Root CA) cannot be deleted or can be deleted but will appear automatically the next time you open Adobe Acrobat:

2. Configure timestamp
The DFN provides a verifiable and trusted timestamp that can be attached to the electronic signature. The timestamp is independent of the individual time configuration of your device. Since this time configuration can be manipulated, RWTH Aachen uses the DFN timestamp server.
To configute the timestamp, proceed as follows.
Step 1
Go to Preferences > Signatures and click More in the Document Timestamping field:

Step 2
Choose Time Stamp Servers and click the button New:

Step 3
Enter the following configuration settings:
- Name: DFN-Timestamp
- Server-URL: http://zeitstempel.dfn.de
Click OK to confirm the settings:

Step 4
Select the DFN-Timestamp in the table and click Set Default:

Click OK to confirm your choice:

For more information on the DFN Timestamp service, visit the DFN website (opens in new tab).
3. Configure Trusted Certificates
The default settings in Adobe Acrobat DC do not include the certificate chains or the root certificates for the user certificates used at RWTH.
In order to import all the necessary root certificates and configure them so that they are trusted by Adobe, please follow these steps.
Step 1
Close all dialogue windows in Adobe. You could even close the entire application.
Step 2
For this step, please connect to the RWTH network - a connection via eduroam or the RWTH VPN is sufficient.
Download the FDF file (opens in new tab) we have provided. It contains the required root certificates. The download will only work from within the RWTH network.
Step 3
Double-click the downloaded “root_certificates_for_SMIMEs_used_at_RWTH” file to open it in Adobe.
Step 4
The file contains four root certificates used for RWTH S/MIME certificates. These are:
- DFN-Verein Community Root CA 2022
- HARICA Client RSA Root CA 2021
- T-TeleSec GlobalRoot Class 2
- USERTrust RSA Certification Authority
In the dialogue box below, select Add Contacts to the List of Trusted Identities:

Step 5
In the next steps, you will set the trust level for each certificate individually.
Click once on the certificate in the upper field “Contacts”. Then click on the corresponding entry for the certificate in the lower field "Certificates" (after the first click, a single entry per certificate is displayed here). Now click on Trust:

Step 6
Check the boxes next to Use this certificate as a trusted root and Certified documents. Then click OK:

Step 7
Repeat steps 5 and 6 for the remaining three certificates.
Step 8
Click Import to complete the process. A confirmation message should appear. If you have already imported some of these root certificates in the past, they will be discarded as duplicates:

Step 9
Under Preferences > Signatures > Identities & Trusted Certificates > Trusted Certificates, the four root certificates should now be displayed. In this view, you could edit the certificates again, after they have been imported.
The Adobe Root CA is also displayed because Adobe automatically classifies it as trusted:

4. Configure Digital Signature
When configuring your digital signature, you decide which digital ID to use for signing. Adobe allows you to use certificates from your system's certificate store (Own Certificates).
Step 1
Under Settings > Signatures click More in the Identities and Trusted Certificates section:

Step 2
In the Digital IDs menu all certificates are listed. You can also switch to Digital IDs from Windows to show only certificates that reside in the Windows certificate store.
Select the certificate you want to use for digital signing.
- If no digital ID appears in this list, you either do not yet have a personal user certificate or you have not imported it into the certificate store.
- If you have several valid digital IDs (e.g., because you sign e‑mails for different addresses), select the one you want to use by default. Choose the ID that is linked to your name and personal e‑mail address.
- Note that digital IDs belonging to group certificates (used for functional e‑mail addresses) should not be selected here, as they are not tied to a single person:

Step 3
Click the pencil icon and choose Use for signing:

The chosen certificate is now marked with a pencil in the list. You may close the window:

Step 4
Click OK to finish the configuration:

You can now digitally sign PDF documents using Adobe Acrobat.
