Certificate Policy & Trust

GxPSign uses digital certificates to cryptographically sign PDF documents, ensuring authenticity and integrity.

Platform Signing Certificate

All documents signed through GxPSign are digitally signed using our platform certificate. This certificate is embedded in each signed PDF and can be verified by any PDF reader that supports digital signatures.

Certificate Details

Subject
CN=GxPSign Platform Signing Certificate,O=GxPSign,C=US
Issuer
CN=GxPSign Platform Signing Certificate,O=GxPSign,C=US
Serial Number
6C722684F936F8490D3C06FBCAAE285EAE63024D
Valid From
October 07, 2026
Valid Until
October 04, 2036

Certificate Fingerprints

Use these fingerprints to verify the authenticity of our signing certificate.

SHA-256 Fingerprint
C7:F7:FE:20:3D:9D:32:62:D8:BF:24:B4:8A:5E:FB:12:F8:D4:93:B9:C3:32:32:2B:6A:D8:71:0A:E7:14:55:CB
SHA-1 Fingerprint
46:1C:C5:3B:7C:6E:0B:59:3D:EA:D5:8F:99:66:98:E1:F4:12:FE:EB

Install Certificate

Installing our signing certificate in your trust store will cause signed PDFs to show as trusted in Adobe Acrobat, macOS Preview, and other PDF readers.

Download GxPSign Certificate (.crt)

After installing, confirm the SHA-256 fingerprint above matches what your OS shows for the imported certificate.

Windows
  1. Download the certificate file above.
  2. Double-click the .crt file — the Certificate dialog opens.
  3. Click Install Certificate…
  4. Choose Local Machine, then click Next.
  5. Select Place all certificates in the following store, click Browse, and choose Trusted Root Certification Authorities.
  6. Click Next, then Finish. Accept the security prompt.
macOS
  1. Download the certificate file above.
  2. Double-click the .crt file — Keychain Access opens.
  3. Select the System keychain (requires admin password), then click Add.
  4. In Keychain Access, find the GxPSign certificate under Certificates.
  5. Double-click it, expand Trust, and set When using this certificate to Always Trust.
  6. Close the dialog and enter your password to confirm.
Linux / Chrome / Firefox

Chrome / Chromium

  1. Go to Settings → Privacy and security → Security → Manage certificates.
  2. Click the Authorities tab, then Import.
  3. Select the downloaded .crt file.
  4. Check Trust this certificate for identifying websites and click OK.

Firefox

  1. Go to Settings → Privacy & Security → Certificates → View Certificates.
  2. Under Authorities, click Import.
  3. Select the .crt file and check Trust this CA to identify websites.

System-wide (Ubuntu/Debian)

sudo cp gxpsign-signing-cert.crt /usr/local/share/ca-certificates/
sudo update-ca-certificates
Adobe Acrobat / Reader
  1. Open Acrobat and go to Edit → Preferences → Signatures → Identities & Trusted Certificates.
  2. Click More…, then select Trusted Certificates in the left panel.
  3. Click Import, browse to the downloaded .crt file, and click Open.
  4. Select the certificate in the list, click Trust, check Use this certificate as a trusted root, and click OK.
View raw PEM certificate
-----BEGIN CERTIFICATE-----
MIIFXzCCA0egAwIBAgIUbHImhPk2+EkNPAb7yq4oXq5jAk0wDQYJKoZIhvcNAQEL
BQAwTjELMAkGA1UEBhMCVVMxEDAOBgNVBAoMB0d4UFNpZ24xLTArBgNVBAMMJEd4
UFNpZ24gUGxhdGZvcm0gU2lnbmluZyBDZXJ0aWZpY2F0ZTAeFw0yNjEwMDcxODE1
NDVaFw0zNjEwMDQxODE1NDVaME4xCzAJBgNVBAYTAlVTMRAwDgYDVQQKDAdHeFBT
aWduMS0wKwYDVQQDDCRHeFBTaWduIFBsYXRmb3JtIFNpZ25pbmcgQ2VydGlmaWNh
dGUwggIiMA0GCSqGSIb3DQEBAQUAA4ICDwAwggIKAoICAQCq1pqEd6Q1K23SfKnW
9HQ70Vxo0WYBiR5rAq5K7fMzmdfu1leWEwCVkVAdpJgedU73WyA1fzv+3GVIwtJ1
N1Md8yY/2NZy1bIqqbNhnxfdVqftwTaxTF+3MmVIq+aSAIz/BZ22/Yj+jEBNDiYY
rxq9jBDRTC4tsPaP41aLexOBwIpNYpxpAIeUHhwQgJ6t1rVFJCv8FI2Ae3bemJ70
D4rZE74MYi4kje/b7ZKAMlvHz9PM9MQqp71XSbAW1VeXbuqDvOn4MD1EoYqqQUnT
sSxjMUNZu824WJPf5ehwMYf879KpARJHhFx1PHykMpDwutbsuKiSvo/l+ukeGKBr
pfmQTu0+zQdK9ErMBZuvtS5WQEAZNGY3CIun5nMtZFbWRB5zSVIFTVe2g2/0Nryz
RvWBbFyj4tq3+wsgBU4K8AOZ7AxRfQNzSXPnJyaOJwTGv4SB3BJwGOQvgKg/koqK
8TCO345jEvFdXf24LBphQEshQFmaUDDxJL8ohXqJ5HlknWNfwlggTptAFMlmVpwo
EcxURQbn8mrO3zuzQa/B3HesogtA8nci0ZCBs0a+KZSMoNOdTIc/BITuw7OvfslZ
kyA9rDk5LxDrGaAevxkli1InRcYXdwO7jqpWdId9HXb1Wh0nd3SPGMjU88Cay7Er
1qbOEgWhWXEB9q11+RdihrStuQIDAQABozUwMzAMBgNVHRMBAf8EAjAAMA4GA1Ud
DwEB/wQEAwIGwDATBgNVHSUEDDAKBggrBgEFBQcDAzANBgkqhkiG9w0BAQsFAAOC
AgEADGsbd86DdNV9Sw6sMbDYfdPdUsxXibBu7Mq7mBhYg/libWv4Qh60hS8bLW5C
zEi+Lc0NXv9MVKtdivQtDjvwVBEpWN87YGWPMv3E+Ii+08DHXekekv9/suCKVILL
86Tm0Nq+R5vX8hq+7DcbCFTqY4TeI2vM3lh9j743UegfM46wNdPZZWCsHniBw+xm
Dfe3mb2Oj2YkLn79TjHyaIG7fvkzPoCq1mQtwAcO30rjiP4PDFMmyn6FFZ70+Ok7
YF4s2M1GGmbC0Ero7M8IHJdDdbKNO5FZ5sNmEBMFnVPl7sWA5XfpqjnYDksGfVlu
AJVR5m+g33uMPFjaxmybNRf60ljZV7J3u+FajYj4uvBeshlxqSwoameesS2SuFSR
hBXqkF1V+G4/UicTgIXG6oLQ5U+BeXAEB4t8FBS6uzmYZve0BubXkwRC+kIR5hTQ
WzZnHGz6IdaycPpaPqWF1OVaT1eFh7Q/FDRIjZ3GtAKlziKClLBVn7ROmQ09Pgel
bBDarnKpHYtwPcMdFYidZUisXfbQHiKMhDaJBdkCaWvbxmurrhn29+PNMV/hH+sq
C3DvO+X7LoeNb5h6cyK8yfUg6B4Fd1YSEQkMvnad1j/w94y5FFcIQzjJGJB+ACM8
RGUvI3EbHJSOQXXo8P1r21CHkp1cUQnyi5w7PVKdUY+VXvw=
-----END CERTIFICATE-----

Signature Standards

PAdES (PDF Advanced Electronic Signatures)

Compliant with ETSI EN 319 142 for PDF digital signatures.

SHA-256 Hash Algorithm

Industry-standard cryptographic hash for document integrity.

RSA 4096-bit Keys

Strong asymmetric encryption for digital signatures.

Verifying Signatures

Documents signed by GxPSign can be verified using any PDF reader that supports digital signatures:

Adobe Acrobat / Reader

Open the PDF and click on the signature panel. Adobe will show the signature status and certificate chain.

Preview (macOS)

Open the PDF and go to Tools > Show Inspector > Signatures to view signature details.

Command Line (OpenSSL)

Use pdfsig from poppler-utils to verify signatures programmatically.

Questions about our certificates?

Contact our security team for certificate-related inquiries.

Contact Security Team