Did this really
come from askFinz?
Every document we issue is sealed so that any later change can be detected. Drop your copy in and find out where it stands. Nothing here stops somebody editing a file they hold — it stops them doing it quietly.
Drop a document here to check it.
It is read in this browser and never uploaded. Only its 64-character fingerprint is sent to us — never the file, and never anything it says.
Sealed, not merely signed.
Documents we issue carry a certification signature at the strictest level — no changes allowed. Your reader treats the file as read-only, and an edit saved anyway is reported as breaking the seal.
The time comes from somebody else.
Each signature carries a timestamp from DigiCert, an authority your reader already trusts. When a document was sealed is therefore verifiable without trusting us at all.
The author is not verified, and we will not pretend otherwise.
Our certificate is our own. Acrobat trusts its own list of authorities rather than your operating system's, and we are not on it — so it reports the author as unverified until you decide otherwise.
The fingerprint.
Installing a certificate because a web page told you to is exactly how somebody would attack you. Before trusting this one, compare its SHA-256 with the value beside this — your reader will show it to you. If they differ, stop.
This page is served over a connection your browser pins to askfinz.com. If you would rather not depend on that, the same fingerprint is published in DNS, which is a different channel with different people in the way of it.
2D:AC:9A:5E:90:FE:66:7F:5E:AE:02:62:BA:FB:C6:1E:85:6F:CF:A7:DE:EE:69:00:66:1F:9E:4F:D7:49:F7:DF
dig +short TXT _docsign.askfinz.com
- Issued to
- askFinz Document Signing · O=askFinz · C=NL
- Serial
- 7ACF56BDC285D3D31149B33EEDC1B778B453129A
The name proves nothing. The fingerprint does.
Anyone can generate a certificate that calls itself askFinz Document Signing. It takes one command and no permission from us, and a reader prints that name in the signature panel exactly as it prints ours. So a document claiming to be from askFinz, showing our name, and reporting the author as unverified is precisely what a forgery would look like.
What cannot be copied is the fingerprint above, because producing it would mean holding our private key. That is the one thing worth checking, and it is why this page exists.
Comparing is enough. Installing is optional.
Steps one to three answer the question completely, and we would rather you stopped there. Step four is a convenience — it turns the warning into our name on every future document — and it is not free, so it carries its own note.
- Open the document and click the certification bar at the top.
- Choose Signature Properties, then Show Signer’s Certificate.
- On the Details tab, compare the SHA-256 fingerprint with the one above. If it matches, the document is ours and unaltered. If it does not, stop — and please tell us.
- Optional. To have future documents verify without this check, open Trust → Add to Trusted Certificates and tick Use this certificate as a trusted root.
If you do install it, leave three boxes unticked.
In that same dialog Acrobat offers to trust this certificate for certified documents, dynamic content, embedded high-privilege JavaScript and privileged system operations. We never need any of those, and granting them would let a document run code on your machine. Signature validation is the only box we ask for.
And know what you are accepting: this certificate has no revocation list. If our signing key were ever stolen we could not switch it off in your reader — we could only publish a new fingerprint here and ask you to remove the old one. That is a real cost, it is the honest reason to prefer comparing over installing, and it disappears when we move to a qualified seal.
Installing it, platform by platform.
This puts the certificate in your operating system’s own store. It is worth knowing what that does and does not change: Acrobat keeps a trust list of its own on every platform, so the four steps above are still what turns its banner green. What an OS install gets you is everything else — the built-in viewers, and anything you check from a shell.
PowerShell. One paste, from any directory.
& {
$fp = "2DAC9A5E90FE667F5EAE0262BAFBC61E856FCFA7DEEE6900661F9E4FD749F7DF"
$crt = "$env:USERPROFILE/Downloads/askfinz-document-signing.crt"
Invoke-WebRequest https://askfinz.com/askfinz-document-signing.crt -OutFile $crt
$c = New-Object Security.Cryptography.X509Certificates.X509Certificate2 $crt
if ($c.GetCertHashString("SHA256") -ne $fp) {
Remove-Item $crt
Write-Host "STOPPED - fingerprint did not match. Nothing installed." -Fore Red
return
}
Import-Certificate -FilePath $crt -CertStoreLocation Cert:\CurrentUser\Root | Out-Null
Write-Host "Installed. SHA-256 now trusted:" -Fore Green
Get-ChildItem Cert:\CurrentUser\Root |
Where-Object Subject -like "*askFinz*" |
ForEach-Object { $_.GetCertHashString("SHA256") }
}What it changes: Windows itself, Edge and anything using the platform crypto APIs. Acrobat still reads its own list unless you turn on Windows Integration under Preferences → Signatures → Verification.
Terminal. One paste, from any directory.
(
set -e
fp="2D:AC:9A:5E:90:FE:66:7F:5E:AE:02:62:BA:FB:C6:1E:85:6F:CF:A7:DE:EE:69:00:66:1F:9E:4F:D7:49:F7:DF"
crt="$HOME/Downloads/askfinz-document-signing.crt"
curl -fsSL https://askfinz.com/askfinz-document-signing.crt -o "$crt"
openssl x509 -in "$crt" -noout -fingerprint -sha256 | grep -q "$fp" || {
rm -f "$crt"
echo "STOPPED - fingerprint did not match. Nothing installed."; exit 1
}
# Keychain will ask you to confirm
security add-trusted-cert -r trustRoot \
-k "$HOME/Library/Keychains/login.keychain-db" "$crt"
echo "Installed:"
security find-certificate -c "askFinz Document Signing" | head -4
)What it changes: Preview, Safari and the command line. Acrobat on macOS keeps its own list, so use the four steps above for it.
Terminal. One paste, from any directory.
(
set -e
fp="2D:AC:9A:5E:90:FE:66:7F:5E:AE:02:62:BA:FB:C6:1E:85:6F:CF:A7:DE:EE:69:00:66:1F:9E:4F:D7:49:F7:DF"
crt="$HOME/askfinz-document-signing.crt"
curl -fsSL https://askfinz.com/askfinz-document-signing.crt -o "$crt"
openssl x509 -in "$crt" -noout -fingerprint -sha256 | grep -q "$fp" || {
rm -f "$crt"
echo "STOPPED - fingerprint did not match. Nothing installed."; exit 1
}
# Okular and Evince validate through NSS, not the system bundle
mkdir -p "$HOME/.pki/nssdb"
certutil -d sql:"$HOME/.pki/nssdb" -A -t "C,," \
-n "askFinz Document Signing" -i "$crt"
echo "Installed:"
certutil -d sql:"$HOME/.pki/nssdb" -L | grep askFinz
)What it changes: The PDF readers most distributions ship. For openssl and curl as well, copy it into /usr/local/share/ca-certificates and run sudo update-ca-certificates — that one does want sudo.
Everything above installs for your user alone, which is the right scope for a certificate you are trusting on your own judgement — the one exception is the second Linux command, which writes to the system bundle and says so. To undo any of them, remove the same entry. The note about revocation applies here too: if you ever hear from us that the fingerprint has changed, remove the old one first.
On a work laptop it may not stick. We watched this happen on a machine joined to a company directory and managed centrally: the certificate installed, reported itself correctly, and had been removed from every store again a few minutes later. Managed devices routinely clear root certificates their owner did not authorise, and that is your employer’s policy working as intended rather than anything going wrong here. If it vanishes, comparing the fingerprint still answers the question perfectly well — which is the better habit anyway.
If you would rather not use a reader.
Every issued copy is served with its SHA-256 in an x-askFinz-Sha256 response header, and the same value is recorded against the copy on our side.
# the file you hold shasum -a 256 askFinz-deck-long-<id>.pdf # the certificate this page publishes openssl x509 -in askfinz-document-signing.crt -noout -fingerprint -sha256 # the same fingerprint, from DNS rather than from this page dig +short TXT _docsign.askfinz.com
A seal you will not have to trust by hand.
We are moving to a qualified electronic seal from a European trust service provider. Readers trust the EU Trusted List out of the box, so documents will verify as askFinz with nothing for you to install, the key will live in certified hardware rather than on a disk, and it will be revocable if it ever needs to be. Until then, this page is the honest version.
Questions about a document you received: hello@askfinz.com · Security · Trust