Skip to content
Administrators

Your organization's own certificate

With your own certificate, every document signed in bb-sign is sealed in your organization’s name, and validators such as Adobe Acrobat recognize that seal. Whoever receives the PDF sees who sealed it and can confirm it has not changed since it was signed. The PDF’s signature box can also show your organization’s name and reason, which Binary Bridges configures in Signature Appearance.

Before paying, confirm with the issuer that the certificate meets these points:

  • It is in the organization’s name, as a legal-entity, public-function or document-signing certificate. The product’s commercial name varies by issuer.
  • It is delivered as a PKCS#12 file (.p12 or .pfx) with an exportable private key. bb-sign needs the file, so a certificate delivered on a USB token or that exists only in the vendor’s cloud does not work for this use.
  • It uses an RSA key of at least 2,048 bits. Elliptic-curve (EC) keys are not supported.
  • It has the key usage digital signature (digitalSignature) and, preferably, non-repudiation (nonRepudiation).
  • It includes the full certification chain: the organization’s certificate, the intermediates and the root.

Buy from a Digital Certification Entity (ECD) accredited by ONAC. Confirm the current accreditation in ONAC’s directory (onac.org.co) before buying.

Entities listed in public sources as accredited ECDs:

Entity Official site
Certicámara certicamara.com
GSE (Gestión de Seguridad Electrónica) gse.com.co
Andes SCD andesscd.com.co
Camerfirma Colombia camerfirma.co
Olimpia IT olimpiait.com
Thomas Signe thomas-signe.com
Viafirma Colombia viafirma.com.co

List verified on 2026-10-07. Confirm with the entity that it delivers the certificate as a PKCS#12 file with an exportable key.

If your organization is outside Colombia, buy from a member of the Adobe Approved Trust List (AATL), so Adobe Acrobat trusts the seal without installing anything else. DigiCert, GlobalSign, Sectigo, Entrust and SSL.com issue document-signing certificates in an organization’s name.

Several of these products ship by default on a USB token or in a cloud HSM. Ask explicitly for a software certificate with an exportable key.

List verified on 2026-10-07. Confirm with the entity that it delivers the certificate as a PKCS#12 file with an exportable key.

Export the certificate with the full chain

Section titled “Export the certificate with the full chain”

The file must contain the organization’s certificate, the intermediate certificates and the root.

  • On Windows: open certmgr.msc, select the certificate and choose Export. Say you want to export the private key, choose the PKCS#12 format and tick “Include all certificates in the certification path if possible”.
  • With OpenSSL:
Ventana de terminal
openssl pkcs12 -export -inkey clave.key -in certificado.crt -certfile cadena.pem -out organizacion.p12

If bb-sign cannot upload the file and the password is correct, export it again with OpenSSL 3’s -legacy option.

Ventana de terminal
openssl pkcs12 -in organizacion.p12 -nokeys -info

The output must list the organization’s certificate, the intermediates and the root.

To review a sealed PDF, open it in Adobe Acrobat and check the signature panel. The seal carries the organization’s certificate, so to see the full path and the identity as valid, import your certification entity’s root into Acrobat as trusted.

The Signing Certificate section is on the organization’s page, reached from Organizations in the sidebar. If your menu does not show Organizations, arrange the upload with Binary Bridges.

  1. Open Organizations, enter your organization and find the Signing Certificate section. If you do not have your own certificate yet, you see “No certificate configured — global fallback will be used”.
  2. Press Upload certificate, or Replace certificate if there already is one.
  3. Type a Label (for example, “Acme Corp 2026”), choose the Certificate file (.p12, .pfx, .pem) and type the Password (if protected).
  4. Press Upload Certificate. When it finishes, the section shows the label and the expiry date after Expires:.

If “Failed to upload certificate” appears, check the file with the verification command and confirm the password. bb-sign applies these rules when it receives the file:

Rule What bb-sign does
Accepted extensions .p12, .pfx, .pem
Maximum file size 5 MB
Expired certificate Rejected.
Key under 2,048 bits Rejected.
Key usage Requires digitalSignature.
New upload Replaces the previous certificate.
Password Stored encrypted and used only to seal.
PEM files Accepted on upload, but sealing requires a PKCS#12. Upload a .p12 or .pfx file.

Keep the .p12 file and its password in your organization’s secret manager and upload them only from the application, never by email.

Note the expiry date shown in the Signing Certificate section and upload the renewed certificate before that date. New seals use the renewed certificate within 5 minutes.

QR-code verification compares the seal with the organization’s active certificate. After a certificate change, documents sealed with the previous one no longer show as valid in that check; the PDF stays intact and its signature panel in Acrobat remains valid. See Verify a signed document.