Your country

Tools that support it use your country for local currency, number formats, units and paper size. Your choice is saved only in this browser.

Type a name or a two-letter code. Use the up and down arrow keys to move through the countries, Enter to choose one and Escape to close.

Digitally Sign PDF with a Certificate

A certificate-based signature that PDF readers can verify — made on your device.

PDF No upload Free to try, no sign-up Pro tool Pro pass from ₹79

Works with certificate files (.p12 / .pfx). Certificates on a USB token or smart card can’t be used from a web page, and no trusted timestamp is added — the signing time is your device’s clock.

PDF to sign

Your certificate

Details and appearance

ETSI.CAdES.detached — the current standard (PAdES baseline B-B).

Appearance

The stamp shows the signature on the page; readers also list it in their signature panel.

Drag the stamp to move it and the corner handle to resize it. With the keyboard: Tab to the stamp, arrows move it (Shift = faster), + and − resize it.

The page appears here once a PDF is open.

Choose a PDF and open your certificate to sign.

Next steps

For general information only, not legal advice. Templates are generic starting points — have a qualified lawyer review anything you rely on.

About the Digitally Sign PDF with a Certificate

Add a digital signature to a PDF with a certificate you already have as a file (.p12 or .pfx). The signature is a standard PAdES signature (a CMS/PKCS #7 signature over the whole file), so Adobe Acrobat Reader and other PDF readers show who signed and can tell if the document was changed afterwards. You can add a visible stamp — “Digitally signed by …” with the date, reason and location — placed where you drag it, or sign invisibly.

The PDF, the certificate and its password stay in your browser: they are used in memory only and are never uploaded or saved. Two things a web page can’t do: use a certificate kept on a USB token or smart card (a browser has no access to the token), and add a trusted timestamp from a timestamp server — the signing time is your device’s clock.

How to use it

  1. Choose the PDF you want to sign.
  2. Choose your certificate file (.p12 or .pfx), enter its password and press Open certificate. Check the name, issuer and validity shown.
  3. Optionally pick a reason and enter a location. If the PDF has an empty signature field (a “sign here” box), the signature goes into it — or choose Add a new signature. Keep Visible stamp to show the signature on a page, then drag the stamp where it should go (corner handle to resize), or choose Invisible.
  4. Press Sign PDF, then Download. Don’t edit the signed file: readers report any later change.

Examples

What the stamp shows
Result
Digitally signed by
Asha Rao
Date: 2026.10.04 18:45:30 +05'30'
Reason: I approve this document
Location: Mumbai
What a reader reports
Result
Signed by Asha Rao · Document has not been modified since this signature was applied · Signer’s identity is valid / unknown

The identity shows as valid only when the reader trusts the certificate’s issuer; a self-signed or company certificate shows as unknown until it is trusted on that computer.

Common uses

  • Signing contracts, approvals and reports with a certificate issued to you by your company or a certificate authority.
  • Countersigning a PDF that someone else has already signed — their signature stays valid.
  • Testing signature workflows and PDF validators with your own test certificates.
  • Signing documents on a computer where you can’t install signing software.

What kind of signature this is

The signature follows the PAdES baseline B-B level of ETSI EN 319 142-1 (V1.1.1, clause 6.3): the PDF’s signature dictionary has /SubFilter ETSI.CAdES.detached and a /ByteRange that covers the whole file except the signature itself, and /Contents holds a CMS SignedData (RFC 5652) with the signed attributes content-type, message-digest and signing-certificate-v2 (RFC 5035). As PAdES requires, there is no CMS signing-time attribute — the claimed signing time is the dictionary’s /M entry — and your certificate and the chain certificates in the file are included. RSA keys and P-256 keys sign with SHA-256, P-384 with SHA-384 and P-521 with SHA-512.

For older software you can choose the earlier adbe.pkcs7.detached format instead (ISO 32000-1 §12.8.3.3). The signature is added as an incremental update, so the original bytes — and any signatures already in the file — stay exactly as they were.

When the PDF already has an empty signature field, the signature is put into that field (its value) and the stamp fills the field’s box; nothing else in the form changes. Otherwise a new signature field is added where you place the stamp.

Why a reader may say the signer is “unknown”

Readers check two things. The signature itself — that the file hasn’t changed since it was signed — is checked with mathematics and works for any certificate. The signer’s identity is accepted only if the certificate leads to a root certificate the reader trusts: Adobe’s trust lists, the computer’s certificate store, or a certificate you trust manually. A self-signed or in-house certificate is therefore shown as “validity unknown” on other people’s computers until they trust it.

This tool doesn’t check whether your certificate has been revoked; readers do that when they validate the signature.

Timestamps and long-term validation

No trusted timestamp is added (that needs an RFC 3161 timestamp server, usually a paid service), so the signing time is the time on your device, as the signer claims it. Once the certificate expires, readers can no longer confirm the signature was made while it was valid. Documents that must be verifiable for years usually need a timestamp and long-term validation data (PAdES B-T and B-LT), which a signing service or desktop software can add.

Certificates on USB tokens and smart cards

Many Digital Signature Certificates are kept on a USB token or smart card whose private key can’t be copied out. A web page can’t use them: browsers give web pages no access to a token’s keys. Sign with the software that came with your token or with a desktop PDF application. This tool works with certificate files (.p12/.pfx) that contain the private key — for example exported from Windows (“Yes, export the private key”), macOS Keychain or your certificate provider.

Legal recognition

India. Under section 3 of the Information Technology Act, 2000 a subscriber may authenticate an electronic record by affixing a digital signature made with an asymmetric crypto system and a hash function, and section 5 accepts an electronic signature, affixed in the manner the Central Government prescribes, where a law requires a signature. A subscriber is the person in whose name the certificate is issued (s. 2(1)(zg)), and a Digital Signature Certificate is one issued under section 35(4) by a Certifying Authority licensed under the Act (s. 2(1)(g) and (q)). A self-made or company certificate is not such a certificate.

European Union. Under Article 25 of the eIDAS Regulation (EU) No 910/2014 (as amended by Regulation (EU) 2024/1183), an electronic signature can’t be denied legal effect or admissibility as evidence just because it is electronic or not qualified, but only a qualified electronic signature has the equivalent legal effect of a handwritten one. Article 26 lists the requirements for an advanced electronic signature. A qualified signature must be made with a qualified signature creation device and a qualified certificate (Art. 3(12)); a certificate file used in a browser is not such a device, so this tool can’t make qualified signatures.

Whether a particular document may or must be signed this way depends on the law and the recipient. This is general information, not legal advice.

Sources

  • ISO 32000-1:2008 §12.8 (digital signatures) and §7.5.6 (incremental updates).
  • ETSI EN 319 142-1 V1.1.1 (2016-04), clause 6.3, Table 1 — etsi.org.
  • RFC 5652 (Cryptographic Message Syntax), RFC 5035 (ESS signing-certificate-v2), RFC 7292 (PKCS #12).
  • Information Technology Act, 2000, ss. 2(1)(g), (p), (q), (zg), 3, 3A, 5 and 35 — India Code.
  • Regulation (EU) No 910/2014, consolidated text, Arts. 3(12), 25 and 26 — EUR-Lex.

Limitations

  • Certificates on USB tokens, smart cards or cloud signing services (including Aadhaar eSign) can’t be used from a web page.
  • No trusted timestamp and no long-term validation data are added (PAdES B-B only).
  • Password-protected or encrypted PDFs must be unlocked first with Unlock PDF; PDFs certified with “no changes allowed” can’t be signed again, and PDFs certified to allow only form filling and signing should be signed in one of their empty signature fields.
  • RSA and ECDSA (P-256, P-384, P-521) keys are supported; RSA-PSS, DSA and Ed25519 keys are not.
  • The stamp’s text uses Noto Sans (Latin, Greek and Cyrillic); scripts that need shaping, such as Devanagari, can’t be drawn in the stamp. The signature itself is unaffected.
  • Damaged PDFs can’t be signed safely; open the file in a PDF reader, save a fresh copy and sign that.

Privacy

The PDF, your certificate file and its password are processed in your browser’s memory and are never uploaded, stored or remembered. Reloading or closing the page clears them.

Frequently asked questions

Is my certificate or password sent anywhere?

No. The certificate file is decrypted with your password inside your browser, the signature is made there with the Web Crypto API, and nothing is sent to MySmartCoPilot or anyone else. The password is not stored; you enter it each time.

Why does Adobe Reader say “signature validity is unknown”?

Because it doesn’t trust the certificate’s issuer. The file is still reported as unchanged since signing. Certificates from issuers on the trust lists Acrobat Reader downloads (the Adobe Approved Trust List and the EU Trusted Lists) are normally shown as valid; others must be trusted on each computer (in Acrobat Reader: Signature Panel → signature properties → show the signer’s certificate → Trust → add to trusted certificates).

Can I use my DSC on a USB token?

No. Browsers don’t let web pages use the keys on USB tokens or smart cards, and the key can’t be copied off the token. Use the signing utility that came with the token, or a desktop PDF application.

How is this different from Sign PDF?

Sign PDF adds a picture of your handwritten or typed signature — a visual electronic signature. This tool adds a cryptographic digital signature tied to your certificate, which readers can verify and which shows whether the file was changed after signing. You can use both: add the visual signature first, then sign digitally.

Will signing break signatures already in the PDF?

No. The new signature is appended as an incremental update, so the bytes the earlier signatures cover don’t change. The only exception is a PDF certified with “no changes allowed”, which can’t be signed again.

Can I sign an empty signature field that is already in the PDF?

Yes. Empty signature fields are listed under Where to sign; the signature goes into the field you choose and the stamp fills its box. A PDF certified to allow only form filling and signing should be signed this way: readers may report a new signature field as a change the certification doesn’t allow, and the page says so when it opens such a file.

Quick answers and tool search

Type to search tools or to get a quick answer, for example 18% of 2500. Use the up and down arrow keys to move through the results, Enter to choose, and Escape to close.