If I've sent you a PDF with a digital signature, this page helps you confirm two things: that it really came from me, and that nobody has changed it since I signed it.
All good. No certificates have been revoked. Revocation list refreshed October 1, 2026 · next refresh due by January 29, 2027
Why your PDF reader may say "unknown"
I run my own small signing authority instead of paying a commercial one, so Adobe Reader and similar apps don't recognise it out of the box. They may show a yellow "validity unknown" note. The signature still proves the document hasn't been altered. Importing my root certificate once makes your reader show it as valid. That also covers anything I sign later.
Choose Trusted Certificates → Import and select root.crt.
Select it, click Edit Trust, and tick Use this certificate as a trusted root and Signed documents or data.
Ways to double-check it's really me
This page lives on my own domain. It's served over HTTPS from pki.jskier.com, and the domain's DNS is protected with DNSSEC.
Published in my DNS. The same fingerprint is in a DNSSEC-signed TXT record, so it can be checked without trusting this website at all:
dig +dnssec TXT _docsign.jskier.com
Look for root-sha256=009e86978cf1b8293d521db039b26425132db4c9f5e01c462b0ffe34b7594302 and the ad (authenticated data) flag in the answer.
Signed with my PGP key. The fingerprints on this page are also in a statement signed by my PGP key for [email protected], which your mail client or GnuPG can fetch straight from my domain (fingerprint 4A88 618E F535 CB09 F8CB 2A69 BAAA 5B81 FAD5 D8CF).
You don't need to import this one; it's checked through the root. If it's ever compromised I'll revoke it, and PDF readers check the revocation list automatically.