
Acrobat 9 Family of Products
Migrating and Sharing Security Settings
Security Feature User Guide
FDF Files and Security 154
“Distributing a Trust Anchor or Trust Root” on page 155
“Setting the Certificate Trust Level” on page 158
“Exporting Your Certificate” on page 158
“Emailing Your Certificate” on page 159
“Saving Your Digital ID Certificate to a File” on page 160
“Requesting a Certificate via Email” on page 161
“Emailing Server Details” on page 162
“Exporting Server Details” on page 163
10.2.1 FDF Files and Security
FDF files are data exchange files. Like acrobatsecurity files, they help you move certificate, server, and
other data from one machine to another. This data transfer usually involves some mechanism such as data
injection into a PDF form field, installing files, executing a script, and so on. These actions represent a
potential security risk, and in some environments that risk may be unacceptable. Acrobat therefore
provides a new security feature that, when turned on, disables some FDF functionality unless those FDF
files originate from a specifically privileged file, folder, or server.
The new feature is called Enhanced Security and may be enabled or disabled by choosing
Edit >
Preferences > Security (Enhanced)
.
Table 5
lists the high level rules defining FDF behavior.
Tip:
If you need to configure your environment for enhanced security or need to troubleshoot
FDF workflows that may not be working as expected, see
“Enhanced Security” on page
132
.
Table 5 Rules for opening a PDF via FDF
Action
FDF
location
PDF
location
8.x behavior
9.x behavior
Opening a target PDF
local
local
PDF opens and no
authentication required.
Same.
Opening a target PDF
local
http server
PDF opens
User authorization required unless trusted via
enhanced security feature.
Opening a target PDF
https
server
http server
PDF opens and no
authentication required.
Same.
Opening a target PDF
https
server
local
Blocked
Http hosted FDFs cannot open local files.
Data injection
n/a
n/a
Allowed
Allowed if:
Data retuned via a form submit with
url#FDF.
FDF has no /FDF key.
cross-domain policy permits it.