Home / Support / Verifying Digital Signatures

Verifying Forensic OSINT Digital Signatures

How to check that a Forensic OSINT report has not been changed, and what the signature confirms.

info

Which reports this page covers. This page covers PDF reports created by Forensic OSINT. In Adobe, the signer's certificate on these reports is issued by ForensicNotesClientBasic, which is issued by ForensicNotesRootCA.

You will see the name "Forensic Notes" in the signature panel. Forensic OSINT is made by TwiceSafe Software Solutions Inc., the company behind Forensic Notes, and reports are signed by the company's Forensic Notes certificate authority.

If the signer certificate on your document does not chain to ForensicNotesRootCA, this page does not describe it. Contact us and we will tell you how to verify it.

1. What the signature confirms

Each Forensic OSINT PDF report is digitally signed when the report is created.

The signature confirms two things

  • The PDF has not been changed since it was signed. If any signed byte of the file changes, the signature check fails.
  • It was signed with a certificate issued under our certificate authority. The chain is: the signer certificate, then ForensicNotesClientBasic, then ForensicNotesRootCA, operated by TwiceSafe Software Solutions Inc.

How it fits with the rest of the report

  • The whole report is protected. The signature covers everything in the report, including the capture details it records, such as the capture ID and the capture date and time. Together with the investigator's own notes, these document what was captured, when, and how.
  • The account that signed it. The signer certificate identifies the Forensic OSINT account by an internal identifier. The investigator and case details are recorded inside the report, which the signature protects.
  • Revocation information. Reports do not embed revocation information. See "About revocation messages" below.

About the signing time. Each report records the date and time it was signed, in UTC, from the Forensic OSINT server that created it. Our servers run in Microsoft Azure, and their clocks are synchronized by Azure's managed time service. Adobe describes any signature without a separate timestamp authority as "Signing time is from the clock on the signer's computer." That is Adobe's standard wording, not a warning about the report. We plan to add independent RFC 3161 timestamping in a future release.

Our root certificate is not on the Adobe Approved Trust List. Adobe will not trust it automatically. Each reader decides whether to trust it, and section 3 explains how to check that you have the right certificate before you do.

2. How to check a report in Adobe Acrobat or Adobe Reader

  1. Open the PDF in Adobe Acrobat or the free Adobe Acrobat Reader.
  2. Open the Signatures panel. Click the link in the blue bar at the top, or use the signature icon in the side panel.
  3. Expand the signature and click Signature Details, then Signature Properties.
  4. Read the summary. Then click Show Signer's Certificate to see the chain.

Adobe gives one of three results.

check_circle Valid (green check): "Signed and all signatures are valid."

What it means: the document has not changed since it was signed, and the certificate chain ends at a root you have chosen to trust.

What to do: once, check that the trusted root is ours. In the Certificate Viewer, select ForensicNotesRootCA at the top of the chain, open the Details tab, and compare its fingerprint with the table in section 4. A different root with the same name is not ours.

warning Unknown (yellow warning): "Signature validity is UNKNOWN" or "At least one signature has problems."

What it means: look for the line "Document has not been modified since this signature was applied." If it is there, the integrity check passed. The warning is about identity: Adobe does not yet trust our root, so it cannot say who signed. This is the normal result on a computer where our root has not been installed.

What to do: if you only need to know whether the file was changed, the "not modified" line answers that. To have Adobe show a valid signature, trust our root (section 3), then right-click the signature and choose Validate Signature.

cancel Invalid (red X): "Signature is INVALID."

What it means: if the details say "Document has been altered or corrupted since it was signed", the file is not the same as the file that was signed.

What to do: do not rely on this copy. Get a fresh copy from the person or organization who produced the report. If you received the file directly from Forensic OSINT and still see this, contact us.

If Adobe says the document was modified after signing. Adobe sometimes reports changes made after the signature, such as comments or highlights added in Acrobat. Click View Signed Version in the signature panel to see exactly what was signed.

About revocation messages. Adobe may say that revocation checks could not be done, or were not performed. Reports do not embed revocation information, so Adobe has to fetch it online and may not be able to. This message does not change the integrity result. You can check the current certificate revocation lists yourself, using the links in section 4.

3. Trusting our root certificate

You only need to do this once per computer. Check the fingerprint first (step A), then install by one of the methods below.

A. Check the fingerprint before you trust it

Download the root certificate (ForensicNotesTrustedSigningRootCA.cer) from the link in section 4, then compute its SHA-256 hash:

  • Windows (Command Prompt): certutil -hashfile ForensicNotesTrustedSigningRootCA.cer SHA256
  • macOS (Terminal): shasum -a 256 ForensicNotesTrustedSigningRootCA.cer

The result must be:

8f18b10a17ce8f0b4b9b4db6fa8cde13774e4ecaf7277464a443b7f193a50914

This is the SHA-256 fingerprint in section 4, written without colons. If it does not match, do not install the file. Contact us.

For extra assurance, confirm the fingerprint with us by phone or email through a contact you already know, not one taken from the file itself.

B. Windows: the installer

  1. Download the installer: forensic-osint-digital-signature-root-certificates.bat. You can open it in Notepad to read it first. It is a short script.
  2. Right-click the file and choose Run as administrator. Administrator rights are required. Your IT team may need to run it for you.
  3. The script downloads our root certificate and the ForensicNotesClientBasic intermediate from ca-authority.forensicnotes.com. It adds the root to the Windows Trusted Root store and the intermediate to the Intermediate store.
  4. Confirm what was installed. In Command Prompt, run certutil -store Root ForensicNotesRootCA and check that the "Cert Hash(sha1)" line matches the SHA-1 fingerprint in section 4 (Windows shows it in lowercase without colons).
  5. Reopen the report in Adobe.

Adobe uses the Windows store only if it is set to. If Adobe still shows "unknown" after you run the installer, open Edit > Preferences > Signatures. Under Verification, click More. Under Windows Integration, tick Validating signatures. Alternatively, import the root directly into Adobe (method C).

If you ran the installer before October 2026, you may want to run it again so that you have the renewed copy. It is safe to run more than once.

C. Adobe Acrobat or Reader on Windows or macOS: manual import

This works on any computer, without administrator rights, and affects only Adobe.

  1. Download both certificates from section 4: the root (ForensicNotesTrustedSigningRootCA.cer) and the intermediate (ForensicNotesClientBasicIntermeidateCa.cer). Check the root's fingerprint (step A).
  2. Open Adobe preferences: Edit > Preferences on Windows, or Acrobat > Settings (older versions: Preferences) on macOS.
  3. Select Signatures. Under Identities & Trusted Certificates, click More.
  4. Select Trusted Certificates, click Import, then Browse, and add both files. Click Import.
  5. In the list, select ForensicNotesRootCA and click Edit Trust. Tick Use this certificate as a trusted root and click OK. Leave the other options unticked. You do not need to mark ForensicNotesClientBasic as a trusted root.
  6. Reopen the report, or right-click the signature and choose Validate Signature.

D. macOS

There is no macOS installer. Use the Adobe manual import (method C). Adobe on macOS keeps its own list of trusted certificates. Adding our root to the macOS Keychain is not needed for Adobe.

4. Certificate details

Fingerprints are hashes of the certificate file. Serial numbers are shown in hexadecimal. Some tools, including Windows, add a leading 00.

FieldRoot certificateIntermediate certificate
Name (subject)CN=ForensicNotesRootCA, O=TwiceSafe Software Solutions, C=CACN=ForensicNotesClientBasic, O=TwiceSafe Software Solutions, C=CA
Issued byItself (root)ForensicNotesRootCA
Serial numberA590C6CE5D488350794DA17AF8F2B3976523613AFBE87C3B2F5CF6BE2D35
Valid fromOctober 8, 2024, 02:29:55 UTCOctober 8, 2024, 02:29:55 UTC
Valid toOctober 5, 2028, 00:22:39 UTCOctober 5, 2028, 00:22:41 UTC
KeyRSA 2048-bit, signed with SHA-256RSA 2048-bit, signed with SHA-256
SHA-256 fingerprint8F:18:B1:0A:17:CE:8F:0B:4B:9B:4D:B6:FA:8C:DE:13:77:4E:4E:CA:F7:27:74:64:A4:43:B7:F1:93:A5:09:143F:04:40:43:9F:66:80:8E:1E:EE:7F:73:2D:64:FE:4D:92:E1:1A:92:0B:32:62:01:8C:1D:81:36:19:6F:A4:A5
SHA-1 fingerprintB4:3F:A3:78:5A:6C:98:7C:6E:53:6A:00:ED:6E:8E:E9:58:6E:91:AF56:CD:12:3E:53:85:77:D9:7F:DE:8B:0A:24:9E:7E:BB:97:79:16:1D
Download (DER, .cer)Certificate/RootCACertificate/ClientBasic
Download (PEM)Certificate/PemRootCA
Revocation list (CRL)CRL/RootCACRL/ClientBasic

All links are on https://ca-authority.forensicnotes.com. The root's CRL lists revoked intermediates. The intermediate's CRL lists revoked signer certificates.

Earlier copy of the same root

Until October 2026, the root was published with an end date of October 8, 2026. It is the same certificate authority with the same key, name and serial number, so it has a different fingerprint:

  • Root, previous copy: SHA-256 89:04:96:90:65:10:DF:9C:0E:93:F1:9C:1F:46:89:F9:5F:91:07:48:73:EF:DB:93:D9:5F:47:C1:25:D5:6A:34, SHA-1 65:B9:D2:54:3F:23:92:A1:0C:A9:DE:50:58:98:02:19:8D:0B:33:1F
  • Intermediate, previous copy: SHA-256 FF:FA:2D:43:AB:0C:41:DA:AA:8B:F7:D8:BA:65:FA:D7:13:B8:9A:11:BA:4C:99:9B:80:5E:E0:82:15:0D:6F:A4, SHA-1 6E:16:3D:84:30:99:C4:D7:56:C4:54:6C:AA:CA:CA:A4:BB:8D:1C:44

If your trust list shows the previous copy, replace it with the current one.

5. Renewal note

autorenew
Renewed October 2026. Same keys; existing reports remain valid.

In October 2026 we renewed the root and intermediate certificates. They keep the same keys, names, serial numbers and start date. Only the end date changed, to October 2028. Reports signed before the renewal validate exactly as before, and nothing needs to be regenerated.

6. Questions

If you have a question about verifying a Forensic OSINT report, or a signature result you do not understand, email support@forensicosint.com. Include the report's file name and a screenshot of Adobe's Signature Properties window.

Ready to capture evidence?

Start preserving web content with forensic integrity.

Minimum Requirements:

  • 8 Characters
  • 1 Upper
  • 1 Lower
  • 1 Digit