Your organization's own certificate
With your own certificate, every document signed in bb-sign is sealed in your organization’s name, and validators such as Adobe Acrobat recognize that seal. Whoever receives the PDF sees who sealed it and can confirm it has not changed since it was signed. The PDF’s signature box can also show your organization’s name and reason, which Binary Bridges configures in Signature Appearance.
Which certificate to buy
Section titled “Which certificate to buy”Before paying, confirm with the issuer that the certificate meets these points:
- It is in the organization’s name, as a legal-entity, public-function or document-signing certificate. The product’s commercial name varies by issuer.
- It is delivered as a PKCS#12 file (.p12 or .pfx) with an exportable private key. bb-sign needs the file, so a certificate delivered on a USB token or that exists only in the vendor’s cloud does not work for this use.
- It uses an RSA key of at least 2,048 bits. Elliptic-curve (EC) keys are not supported.
- It has the key usage digital signature (
digitalSignature) and, preferably, non-repudiation (nonRepudiation). - It includes the full certification chain: the organization’s certificate, the intermediates and the root.
Where to buy it in Colombia
Section titled “Where to buy it in Colombia”Buy from a Digital Certification Entity (ECD) accredited by ONAC. Confirm the current accreditation in ONAC’s directory (onac.org.co) before buying.
Entities listed in public sources as accredited ECDs:
| Entity | Official site |
|---|---|
| Certicámara | certicamara.com |
| GSE (Gestión de Seguridad Electrónica) | gse.com.co |
| Andes SCD | andesscd.com.co |
| Camerfirma Colombia | camerfirma.co |
| Olimpia IT | olimpiait.com |
| Thomas Signe | thomas-signe.com |
| Viafirma Colombia | viafirma.com.co |
List verified on 2026-10-07. Confirm with the entity that it delivers the certificate as a PKCS#12 file with an exportable key.
Where to buy it in other countries
Section titled “Where to buy it in other countries”If your organization is outside Colombia, buy from a member of the Adobe Approved Trust List (AATL), so Adobe Acrobat trusts the seal without installing anything else. DigiCert, GlobalSign, Sectigo, Entrust and SSL.com issue document-signing certificates in an organization’s name.
Several of these products ship by default on a USB token or in a cloud HSM. Ask explicitly for a software certificate with an exportable key.
List verified on 2026-10-07. Confirm with the entity that it delivers the certificate as a PKCS#12 file with an exportable key.
Export the certificate with the full chain
Section titled “Export the certificate with the full chain”The file must contain the organization’s certificate, the intermediate certificates and the root.
- On Windows: open
certmgr.msc, select the certificate and choose Export. Say you want to export the private key, choose the PKCS#12 format and tick “Include all certificates in the certification path if possible”. - With OpenSSL:
openssl pkcs12 -export -inkey clave.key -in certificado.crt -certfile cadena.pem -out organizacion.p12If bb-sign cannot upload the file and the password is correct, export it again with OpenSSL 3’s
-legacy option.
Check the file before uploading
Section titled “Check the file before uploading”openssl pkcs12 -in organizacion.p12 -nokeys -infoThe output must list the organization’s certificate, the intermediates and the root.
To review a sealed PDF, open it in Adobe Acrobat and check the signature panel. The seal carries the organization’s certificate, so to see the full path and the identity as valid, import your certification entity’s root into Acrobat as trusted.
Upload the certificate
Section titled “Upload the certificate”The Signing Certificate section is on the organization’s page, reached from Organizations in the sidebar. If your menu does not show Organizations, arrange the upload with Binary Bridges.
- Open Organizations, enter your organization and find the Signing Certificate section. If you do not have your own certificate yet, you see “No certificate configured — global fallback will be used”.
- Press Upload certificate, or Replace certificate if there already is one.
- Type a Label (for example, “Acme Corp 2026”), choose the Certificate file (.p12, .pfx, .pem) and type the Password (if protected).
- Press Upload Certificate. When it finishes, the section shows the label and the expiry date after Expires:.
If “Failed to upload certificate” appears, check the file with the verification command and confirm the password. bb-sign applies these rules when it receives the file:
| Rule | What bb-sign does |
|---|---|
| Accepted extensions | .p12, .pfx, .pem |
| Maximum file size | 5 MB |
| Expired certificate | Rejected. |
| Key under 2,048 bits | Rejected. |
| Key usage | Requires digitalSignature. |
| New upload | Replaces the previous certificate. |
| Password | Stored encrypted and used only to seal. |
| PEM files | Accepted on upload, but sealing requires a PKCS#12. Upload a .p12 or .pfx file. |
Keep the .p12 file and its password in your organization’s secret manager and upload them only from
the application, never by email.
Renew the certificate
Section titled “Renew the certificate”Note the expiry date shown in the Signing Certificate section and upload the renewed certificate before that date. New seals use the renewed certificate within 5 minutes.
QR-code verification compares the seal with the organization’s active certificate. After a certificate change, documents sealed with the previous one no longer show as valid in that check; the PDF stays intact and its signature panel in Acrobat remains valid. See Verify a signed document.