Adobe 22002484 User Guide - Page 220

Choosing security methods within FIPS mode (Windows)

Page 220 highlights

USING ACROBAT 9 STANDARD 215 Security Protection required: Action: Prevent forms from being tampered with Use LiveCycle Designer to secure forms and create locking signature fields. See the Adobe LiveCycle Designer Help. Send secure file attachments via Use security envelopes. email Allow only the people you specify to view a PDF Choose Encrypt With Certificate from the Secure button in the Tasks toolbar, or apply security using Adobe LiveCycle Rights Management ES. You must have certificates for users who can view the documents. For more information on using security features, see these resources: • Legal professionals: http://blogs.adobe.com/acrolaw/ • PDF Portfolios: www.adobe.com/go/lrvid4201_a9 More Help topics "Removing sensitive content" on page 236 "Setting up security policies" on page 226 Choosing security methods within FIPS mode (Windows) Acrobat and Reader provide a FIPS mode to restrict data protection to Federal Information Processing Standard (FIPS). FIPS mode uses FIPS 140-2 approved algorithms using the RSA BSAFE Crypto Micro Edition (ME) 2.1.0.3 cryptographic module. The following security options aren't available in FIPS mode: • Applying password-based security policies to documents. You can use public key certificates or Adobe LiveCycle Rights Management ES to secure the document, but you cannot use password encryption to secure the document. • Creating self-signed certificates. To create a self-signed digital ID, it must be saved to the Windows certificate store. You cannot create a self-signed digital ID that is saved to a file. • RC4 encryption. A PDF file can only be encrypted by using the AES encryption algorithm when in FIPS mode. • MD5 or RIPEMD160 digest methods. In FIPS mode, only the SHA-1 and SHA-2 families of digest algorithms can be used when creating a digital signature. In FIPS mode, you can open and view documents that are protected with algorithms that are not FIPS compliant. However, you can't save any changes to the document using password security. To apply security policies to the document, use either public key certificates or Adobe LiveCycle Rights Management ES. FIPS mode is configured in the Windows registry by a system administrator. For more information, see Document Security User Guide For Adobe Acrobat and Adobe Reader (PDF) at www.adobe.com/go/learn_acr_security_en. Last updated 9/30/2011

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380

215
USING ACROBAT 9 STANDARD
Security
Last updated
9
/30/2011
For more information on using security features, see these resources:
Legal professionals:
PDF Portfolios:
www.adobe.com/go/lrvid4201_a9
More Help topics
Removing sensitive content
” on page
236
Setting up security policies
” on page
226
Choosing security methods within FIPS mode (Windows)
Acrobat and Reader provide a FIPS mode to restrict data protection to Federal Information Processing Standard
(FIPS). FIPS mode uses FIPS 140-2 approved algorithms using the RSA BSAFE Crypto Micro Edition (ME) 2.1.0.3
cryptographic module.
The following security options aren’t available in FIPS mode:
Applying password-based security policies to documents. You can use public key certificates or Adobe LiveCycle
Rights Management ES to secure the document, but you cannot use password encryption to secure the document.
Creating self-signed certificates. To create a self-signed digital ID, it must be saved to the Windows certificate store.
You cannot create a self-signed digital ID that is saved to a file.
RC4 encryption. A PDF file can only be encrypted by using the AES encryption algorithm when in FIPS mode.
MD5 or RIPEMD160 digest methods. In FIPS mode, only the SHA-1 and SHA-2 families of digest algorithms can
be used when creating a digital signature.
In FIPS mode, you can open and view documents that are protected with algorithms that are not FIPS compliant.
However, you can’t save any changes to the document using password security. To apply security policies to the
document, use either public key certificates or Adobe LiveCycle Rights Management ES.
FIPS mode is configured in the Windows registry by a system administrator. For more information, see
Document
Security User Guide For Adobe Acrobat and Adobe Reader
(PDF) at
www.adobe.com/go/learn_acr_security_en
.
Prevent forms from being
tampered with
Use LiveCycle Designer to secure forms and create
locking signature fields. See the Adobe LiveCycle
Designer Help.
Send secure file attachments via
email
Use security envelopes.
Allow only the people you
specify to view a PDF
Choose Encrypt With Certificate from the Secure button
in the Tasks toolbar, or apply security using Adobe
LiveCycle Rights Management ES. You must have
certificates for users who can view the documents.
Protection required:
Action: