The Short Answer: Verify the Chain, the Status, and the Signature
An Indonesian digital certificate is valid when five conditions hold: the chain of trust terminates at the national root operated by BSrE (Balai Sertifikasi Elektronik) under BSSN, the National Cyber and Crypto Agency; the certificate is within its validity period; it has not been revoked; the digital signature attached to the document verifies against the certificate's public key; and the issuing CA is accredited. Check all five and you have a defensible answer. Stop after one and you have an assumption.
This matters far beyond curiosity. Under Indonesia's electronic transaction framework — the Electronic Information and Transactions Law (UU No. 11/2008, as amended by UU No. 19/2016) and its implementing regulation PP No. 71/2019 — a digital signature that relies on a certificate issued by an accredited CA is given stronger evidentiary weight. An unverifiable certificate weakens that position precisely when you need it, which is usually in a dispute.
Who Signs Indonesian Digital Certificates: BSrE and Licensed CAs
Indonesia operates a hierarchical trust model. At the top sits BSrE, which acts as the national root certification authority and supervises licensed certification authorities (CAs). Commercial CAs such as PrivyID, Vida, and the electronic meterai provider operated by PERURI issue end-entity certificates to individuals and organizations, and those certificates chain upward to the BSrE root.
The practical consequence: when you hold an Indonesian digital signature, the certificate in your PDF or email should show a chain that runs through the issuing CA and terminates at the BSrE root. If the chain is missing, or terminates at a root you do not recognize, the certificate is not verifiable against the Indonesian national trust anchor — even if the signature itself was produced correctly.
Two cautions before you start. First, Adobe Acrobat Reader and most desktop PDF tools do not ship with the Indonesian national root in their default trust store, so a "signature validity unknown" warning is common and is not by itself proof of a broken certificate — it often just means the reader does not trust the chain. Second, an Indonesian certificate can be fully valid yet still not be what the other party needs: some documents require a specific certificate type, and a valid personal certificate does not substitute for an organizational one. Our explainer on how digital signatures work in real workflows covers the general mechanics behind these distinctions.
Step-by-Step: Verifying an Indonesian Digital Signature
Run these checks in order. Each one answers a different question, and a certificate is only as strong as the weakest check.
1. Inspect the certificate chain. Open the signature properties in your PDF reader and expand the certificate chain. You are looking for three links: the end-entity certificate, the issuing CA, and a root. In the Indonesian model the root should be BSrE (or a root BSSN operates for electronic certification). If the reader cannot render the chain, export the signed file's certificate and inspect it with OpenSSL or a certificate viewer.
2. Check the validity period. The certificate shows a "not before" and "not after" date. A signature made outside that window is not valid, even if the certificate was legitimate for other documents. Signers occasionally keep using expired certificates because their platform did not warn them; the document timestamp then becomes the decisive evidence of when the signature was applied.
3. Check revocation status. Valid certificates get revoked — because a private key was compromised, an employee left, or a CA enforced policy. The authoritative checks are OCSP (Online Certificate Status Protocol) and CRL (certificate revocation list), both published by the issuing CA and anchored to the BSrE framework. Your reader may check OCSP automatically; if it does not, query the issuing CA's revocation service directly.
4. Verify the signature cryptographically. The signature must be mathematically verifiable against the certificate's public key: the signer's private key signed that specific document, and any change to the document breaks the verification. In PDF tools this is the "validate signature" action; in OpenSSL it is a verify command against the extracted public key. A signature that verifies confirms the document content is what the signer signed.
5. Confirm the CA's authorization. Indonesia's framework ties the evidentiary weight of a digital signature to accredited CAs. If you are relying on the signature for a regulatory or court context, confirm the issuing CA is a licensed/recognized certification body operating under the BSrE framework. Our guide to Indonesia's digital identity and signature ecosystem walks through how PrivyID and similar services fit into that accreditation structure.
A Verification Checklist for Indonesian Digital Signatures
A certificate that passes all five rows is trustworthy for the technical and evidentiary purpose. A certificate that fails even one row needs explanation before you rely on it — and the explanation belongs in your records.
What to Do When Verification Fails
A failed check does not automatically mean fraud, but it does mean you must stop treating the signature as verified. The most common causes in practice:
Reader trust-store gap. The PDF reader does not know the BSrE root and shows "unknown." Fix it by importing the BSrE root into the reader's trust store or by checking the chain manually. This is why digital signatures can appear unverifiable in Chrome even when they are fine.
Expired certificate. Ask the signer to re-sign, or rely on a qualified timestamp if the framework supports one. Do not "accept" an expired certificate as a substitute.
Revoked certificate. Contact the issuer to understand why, and ask the counterparty for a replacement signature. A revoked certificate is a red flag worth escalating, especially if the revocation happened close to the signing date.
Broken chain or unknown root. Treat the document as unverified and request the certificate chain file (usually .cer/.p7b or embedded in the PDF) so you can inspect it properly. If the chain does not reach BSrE, the document does not carry a verifiable Indonesian digital signature.
Signature does not verify. The document may have been modified after signing. Compare hashes, review the document history, and check whether the signature was manipulated before drawing conclusions.
Verification Methods You Can Reuse on Any Certificate
The Indonesian workflow is a specific instance of a general skill, and the general skill is worth having. The same chain-then-status-then-signature order applies to certificates from any country, whether you are checking a U.S. certificate, a European one under eIDAS, or an Asian one under a national root. Browser-based checking covers the basics but not the depth — our guide to verifying digital signatures in Chrome shows where browsers stop and where dedicated tools take over. For a wider view of how trust roots are organized worldwide, the certificate authority list maps the major national and commercial roots you are likely to encounter.
Compliance-Grade Signing With Certificates That Stay Verifiable: Nota Sign
The point of verification is not to add friction — it is to ensure that when a counterparty audits your signature, the chain, status, and cryptographic proof all come back clean. That is what a compliance-grade signing platform does in the background: it manages certificates with proper custody, keeps revocation checks current, and produces an audit trail that documents when and how each signature was applied. Nota Sign, FaDaDa's global e-signature platform, builds this evidence depth into the signing flow across 100+ countries and regions, with compliance alignment that includes SES/AES/QES categories and regional identity integrations such as iAM Smart and Singpass.
For teams in or working with Indonesia — where certificate verification has real evidentiary weight — that means the signatures you collect are verifiable from day one instead of becoming a remediation project later. Nota Sign charges no per-seat fees, keeping the platform accessible to small legal and compliance teams, while enterprise buyers can shape tailored plans around volume. Talk to the Nota Sign team about your certificate and compliance workflow.









