Troubleshoot customer-managed encryption in Acrobat Sign

Last updated on Aug 31, 2026
Alert

This article contains prerelease information. Release dates, features, and other information are subject to change without notice.

Resolve common customer-managed encryption issues, including AWS KMS validation failures, unavailable keys, credential problems, and migration errors.

Customer-managed encryption depends on Adobe Acrobat Sign maintaining access to the AWS KMS key configured for your account.

Use this page to diagnose common configuration and operational problems. For setup instructions, see Configure Customer Managed Encryption. For planned key or migration operations, see Manage customer-managed encryption keys.

Customer-managed encryption can't be enabled

When you save the customer-managed encryption configuration, Acrobat Sign validates the AWS credentials and KMS key before activating the configuration.

If validation fails, review the error shown in Security Settings.

Access Denied

What it means

The configured AWS credentials do not have permission to use the specified KMS key.

What to check

  1. Verify that the AWS Access Key ID and Secret Access Key belong to the intended IAM user.
  2. Verify that the IAM policy is attached to that user or its group.
  3. Confirm that the policy grants the required KMS permissions.
  4. Confirm that the policy is scoped to the exact KMS key ARN configured in Acrobat Sign.
  5. Save the Acrobat Sign configuration again.

If validation succeeds, Acrobat Sign accepts the updated configuration.

Key Not Found

What it means

Acrobat Sign can't locate or access the KMS key identified by the configured ARN.

What to check

  1. Verify the KMS Key ARN in AWS KMS.
  2. Confirm that the complete ARN was entered in Acrobat Sign.
  3. Confirm that the key belongs to the AWS account associated with the configured credentials.
  4. Correct the ARN and save the configuration again.

Key Disabled

What it means

The configured KMS key exists but is disabled in AWS.

What to do

  1. Open the key in AWS KMS.
  2. Enable the key.
  3. Return to Acrobat Sign.
  4. Save the customer-managed encryption configuration again.

Acrobat Sign validates the key before accepting the configuration.

Previously protected agreements are unavailable

If agreements protected with the customer-managed key can no longer be opened or downloaded, verify that Acrobat Sign still has access to the configured AWS KMS key.

Common causes include:

  • the KMS key was disabled;
  • the KMS key was deleted;
  • AWS credentials were deactivated;
  • credentials were rotated without updating Acrobat Sign;
  • IAM permissions were removed or changed.

Acrobat Sign can continue using cached key information for the configured Key Cache TTL. After the cache expires, content that depends on an unavailable customer-managed key can become inaccessible.

Restore access after a disabled key

If the key was disabled:

  1. Re-enable the same key in AWS KMS.
  2. Verify that the configured IAM credentials can access it.
  3. Retry access to the affected content.

Restoring access to the same key restores the dependency Acrobat Sign needs to decrypt content protected by that key.

Restore access after credentials were deactivated

If the IAM credentials were disabled:

  1. Reactivate the credentials in AWS, or create replacement credentials with access to the configured KMS key.
  2. If using replacement credentials, update AWS Access Key ID and AWS Secret Access Key in Acrobat Sign.
  3. Save the configuration.

Acrobat Sign validates replacement credentials before accepting them.

Note

Do not delete a KMS key while Acrobat Sign content remains protected by it. After the AWS deletion waiting period completes, deletion is permanent and the key can no longer be restored.

Updated AWS credentials aren't accepted

When AWS credentials are changed in Acrobat Sign, the new credentials are validated before the configuration is saved.

If validation fails:

  • confirm that the new credentials are active;
  • confirm that they belong to the expected AWS account;
  • verify access to the configured KMS key;
  • verify the required KMS permissions;
  • verify that the IAM policy references the correct key ARN.

A failed credential update does not replace the existing working configuration.

This allows you to correct the new credentials without losing the previously validated configuration.

A re-encryption or rollback job shows failures

Bulk encryption and decryption operations can complete successfully for most content while individual items fail.

When this happens, the job can show Completed with failures.

  1. Go to Account Settings > Security Settings > Customer Managed Encryption.
  2. Open View details for the operation.
  3. Review the processed and failed counts.
  4. Retry the failed items.

Successfully processed items do not need to be processed again.

A migration appears to have stopped

Bulk encryption and decryption jobs do not process continuously throughout the day.

They run during the account's off-peak processing window, from 7:00 PM to 7:00 AM local time. Large accounts can require multiple processing windows.

Before treating the job as stalled:

  • check its current status;
  • confirm whether the account is currently within the processing window;
  • refresh the page to retrieve the latest processing status.

The processing page does not automatically refresh.

If a job was intentionally stopped, resume it from the job details when you're ready to continue.

An agreement shows the unexpected encryption state

During account-wide migration, some agreements can already be protected by the customer-managed key while others remain protected by Adobe-managed encryption.

To verify a specific agreement:

  1. Open the agreement from Manage.
  2. Open Protection Information.
  3. Review which encryption protection is currently applied to the agreement.

A different protection state during an active migration does not necessarily indicate a failure. Check the account-wide migration status before troubleshooting the individual agreement.

Acrobat Sign reports a key-access failure

When Acrobat Sign detects a problem accessing the configured customer-managed key, active account administrators receive an email notification describing the failure and corrective action.

Examples include:

  • a disabled or unavailable key;
  • invalid or revoked credentials;
  • loss of permission to use the key.

Start by checking the AWS KMS key, configured credentials, and IAM permissions.

Key-access notifications are rate-limited, so a continuing condition does not generate a new message for every failed operation.

A rollback can't complete

When customer-managed encryption is disabled, Acrobat Sign must still use the customer-managed key to decrypt content before returning that content to Adobe-managed encryption.

If the key or its credentials become unavailable during rollback:

  1. Restore access to the same customer-managed key.
  2. Verify the configured credentials and IAM permissions.
  3. Resume or retry the affected migration operation.

Keep the AWS KMS key and required credentials active until the rollback completes.

When to contact Adobe Support

Contact Adobe Support when:

  • a bulk encryption or decryption operation remains unable to progress after key access has been verified;
  • failed items continue to fail after retrying;
  • Acrobat Sign reports a protection state that does not match the completed migration state;
  • content remains unavailable after access to the correct KMS key has been restored.

When opening a support request, include the account information, the operation being performed, the visible status or error, and the affected agreement IDs where applicable.

Do not include AWS secret access keys or other sensitive credentials in the support request.