Adobe 22002486 Digital Signature User Guide - Page 154

FDF Files and Security

Page 154 highlights

Acrobat 9 Family of Products Security Feature User Guide Migrating and Sharing Security Settings FDF Files and Security 154  "Distributing a Trust Anchor or Trust Root" on page 155  "Setting the Certificate Trust Level" on page 158  "Exporting Your Certificate" on page 158  "Emailing Your Certificate" on page 159  "Saving Your Digital ID Certificate to a File" on page 160  "Requesting a Certificate via Email" on page 161  "Emailing Server Details" on page 162  "Exporting Server Details" on page 163 10.2.1 FDF Files and Security FDF files are data exchange files. Like acrobatsecurity files, they help you move certificate, server, and other data from one machine to another. This data transfer usually involves some mechanism such as data injection into a PDF form field, installing files, executing a script, and so on. These actions represent a potential security risk, and in some environments that risk may be unacceptable. Acrobat therefore provides a new security feature that, when turned on, disables some FDF functionality unless those FDF files originate from a specifically privileged file, folder, or server. The new feature is called Enhanced Security and may be enabled or disabled by choosing Edit > Preferences > Security (Enhanced). Table 5 lists the high level rules defining FDF behavior. Tip: If you need to configure your environment for enhanced security or need to troubleshoot FDF workflows that may not be working as expected, see "Enhanced Security" on page 132. Table 5 Rules for opening a PDF via FDF Action FDF PDF location location 8.x behavior Opening a target PDF local local PDF opens and no authentication required. Opening a target PDF local http server PDF opens Opening a target PDF Opening a target PDF Data injection https server https server n/a http server PDF opens and no authentication required. local Blocked n/a Allowed 9.x behavior Same. User authorization required unless trusted via enhanced security feature. Same. Http hosted FDFs cannot open local files. Allowed if:  Data retuned via a form submit with url#FDF.  FDF has no /FDF key.  cross-domain policy permits it.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189

Acrobat 9 Family of Products
Migrating and Sharing Security Settings
Security Feature User Guide
FDF Files and Security
154
“Distributing a Trust Anchor or Trust Root” on page 155
“Setting the Certificate Trust Level” on page 158
“Exporting Your Certificate” on page 158
“Emailing Your Certificate” on page 159
“Saving Your Digital ID Certificate to a File” on page 160
“Requesting a Certificate via Email” on page 161
“Emailing Server Details” on page 162
“Exporting Server Details” on page 163
10.2.1
FDF Files and Security
FDF files are data exchange files. Like acrobatsecurity files, they help you move certificate, server, and
other data from one machine to another. This data transfer usually involves some mechanism such as data
injection into a PDF form field, installing files, executing a script, and so on. These actions represent a
potential security risk, and in some environments that risk may be unacceptable. Acrobat therefore
provides a new security feature that, when turned on, disables some FDF functionality unless those FDF
files originate from a specifically privileged file, folder, or server.
The new feature is called Enhanced Security and may be enabled or disabled by choosing
Edit >
Preferences > Security (Enhanced)
.
Table 5
lists the high level rules defining FDF behavior.
Tip:
If you need to configure your environment for enhanced security or need to troubleshoot
FDF workflows that may not be working as expected, see
“Enhanced Security” on page
132
.
Table 5
Rules for opening a PDF via FDF
Action
FDF
location
PDF
location
8.x behavior
9.x behavior
Opening a target PDF
local
local
PDF opens and no
authentication required.
Same.
Opening a target PDF
local
http server
PDF opens
User authorization required unless trusted via
enhanced security feature.
Opening a target PDF
https
server
http server
PDF opens and no
authentication required.
Same.
Opening a target PDF
https
server
local
Blocked
Http hosted FDFs cannot open local files.
Data injection
n/a
n/a
Allowed
Allowed if:
Data retuned via a form submit with
url#FDF.
FDF has no /FDF key.
cross-domain policy permits it.