Seal's certificates

Seal seals every completed envelope with its own certificate authority, Seal Root CA. The sealed PDF carries a certifying signature from the Seal Document Sealing certificate, which the root issued, and a timestamp from a public timestamp authority.

PDF readers don't know Seal's root out of the box, so Adobe Acrobat shows the signature's identity as unknown while still confirming the document hasn't changed since it was sealed. To see it as trusted, add the root to Acrobat once:

  1. Download root.crt and compare its fingerprint with the one below.
  2. In Acrobat open Preferences (Windows: Edit > Preferences; Mac: Acrobat > Settings), then Signatures > Identities & Trusted Certificates > More….
  3. Choose Trusted Certificates > Import, pick root.crt and import it.
  4. Select Seal Root CA, choose Edit Trust, and tick Use this certificate as a trusted root and Certified documents.

Or skip all that: drop a sealed PDF on seal.nightroll.app/verify, which checks it in your browser against this root.

Files