
Acrobat 9 Family of Products
Migrating and Sharing Security Settings
Security Feature User Guide
Exporting Application Settings with FDF Files 155
10.2.2 Exporting Application Settings with FDF Files
FDF files can be created by administrators, end users, and even a server. It is a good idea to sign FDF files so
that recipients of the file can establish a level of trust for the contents of the FDF file. For example, when an
FDF file is signed, the
Accept the level of trust specified by the signer for all contacts in this file
checkbox becomes enabled, thereby allowing the importer to accept the level of trust you have specified.
Note:
Recipients won’t be able to validate your signature unless you have previously sent them your
digital ID certificate or your certificate was issued by someone they already trust.
Figure 114 Signing an FDF file
10.2.2.1 Distributing a Trust Anchor or Trust Root
Distributing a trusted certificate from Acrobat involves wrapping one or more certificates in an FDF file
and making it available to other users via email, a network directory, or a Web site. Recipients simply click
on the file or a link to the file to open the Acrobat wizard which downloads and/or installs the certificate.
Data injection
server
browser
Allowed
Allowed if:
Link to PDF contains #FDF=url.
FDF has no /FDF key.
x-domain policy permits it.
Data injection
server
Application
Allowed
Allowed if:
PDF makes EFS POST/GET and FDF sends
data in https response to same PDF.
x-domain policy permits it.
Data injection
Varied
Varied
Allowed
Authorization required if enhanced security is on and
document is not set as a privileged location.
Script injection
Any
Any
Allowed
Injection is blocked unless if enhanced security is on
and FDF is not in a privileged location.
Table 5 Rules for opening a PDF via FDF
Action
FDF
location
PDF
location
8.x behavior
9.x behavior