...
- Open Acrobat by clicking on it if it's in your dock, or by going to your Applications folder and double clicking Acrobat Pro/Acrobat Pro DC/Acrobat Reader DC
- Go to the Acrobat Menu and slide down to Preferences
- slide Scroll down to Signatures and click on it
- in the Identities & Trusted Certificates section, click More
- Click Add ID (ID card icon with plus symbol)
- Leave the default selection of My existing digital ID from: A file and click Next
- Browse to your Downloads folder, click on the .P12 file, and click Open
- Enter the password from the stache Stache field labeled Encrypted file password or paste the previously copied password (Command-V or choose Paste from up top in the Edit menu)
- Click Next
- Click Finish
- Click Close
- Open the application Keychain Access found in the Utilities folder in Applications in Finder
- If prompted, use your login password to unlock Keychain Access.
- In the left-hand column, select login
- In the row at the top of the window, select My Certificates
- Drag and drop the .P12 file into My Certificates
- Paste (Command-V or choose Paste from up top in the Edit menu) the Encrypted file password you copied from Stache into the Password prompt.
- Click on the > symbol beside the new certificate.
- Double-click your email address that just dropped down.
- Click Access Control
- Click the newly imported Digital ID that has your FIrstName LastName <emailaddress>up in the Usage Options headingthe + button
- Navigate to Application to Adobe Acrobat 2020 and select Adobe Acrobat
- Click Add
- Click Save Changes
- Enter your login password
- Close Keychain Access
- Go to the Acrobat Menu and slide down to Preferences
- Scroll down to Trust Manager and click on it. The reason for these next steps is listed towards the bottom of the wiki under Update the Adobe Trusted Root Certificates To Allow For Successful Validation of UT Employee Signed Documents
- Tick the box Load Trusted Root Certificates From An Adobe AATL Server. This option allows Acrobat or Reader to automatically download trust settings from an Adobe server. These trust settings ensure that the user or organization associated with the certificate has met the assurance levels of the Adobe Approved Trust List (AATL) program.
- Tick the box Ask Before Updating.
- Click Update Now.
- You may repeat these steps for the Automatic European Union Trusted Lists (EUTL) updates.
- Click OK
- Restart Adobe Acrobat/Reader to put the change into effect.
- Reopen Acrobat
- Go to the Acrobat Menu and slide down to Preferences
- Scroll down to Signatures and click on it
- in the Identities & Trusted Certificates section, click More
- Click the ID that has your FIrstName LastName <emailaddress>. There are two. Select the one that has Mac Keychain Store under the Storage Mechanism column
- At the top, click Certificate Details. The following steps will resolve all the certificate path errors.
- At the left column, select The University of Texas at Austin RSA CA
- Click the Trust tab
- Click Add to Trusted Certificates... and OK on the Adobe prompt
- On the pop-up window, make sure to tick all four boxes including the one that says Use this certificate as a trusted root.
- Click Trust
- Click OK
- Click OK again. The certificate path should be valid now.
- up in the Usage Options heading (pencil icon), slide down and click Use for signing. Do this again for Use for Certifying and Use for Encryption. Note: Acrobat Reader DC will only have the Use for signing option.
- Click Close
- Click OK
- To test it out, you can open a PDF document and sign a document AFTER you Update the Adobe Trusted Root Certificates (below). If prompted by Keychain Access, enter your login password and click Always Allow. If you press enter, it will only allow it once.
For Windows:
- Double clicking the downloaded .p12 file will open Certificate Import Wizard.
Go through the wizard. You shouldn't have to tick off anything. Do not check the box to force strong protection or it will make you enter your password every time you want to use the certificate for signing. You will need the password from the stache entry in your encryption and mail signing cert. - Finish the wizard.
...