Home>User Manuals>Right PDF Pro (macOS)

After exchanging certificates with the recipients and adding them to the list of Trusted Identities, the certificate-based security lets you ensure only the intended recipients open and view the document. A certificate includes the public key component of a digital ID that can be shared and added to your list of trusted identities. See Manage Digital IDs.

Before you distribute a certificate-secured PDF file, you must receive certificates from those whom you intend to send the file to and add the certificates to the list of trusted identities, setting them as trusted recipients. Likewise, to open a certificated-secured PDF file, you need to create your own digital ID (consisting of a private key and a public key) and share the certificate (the public key of you digital ID) with the person who distributes the file encrypted with certificates.

When managing certificate security, you can specify who can view the document and define permissions for each recipient. For example, you can grant one person the power to perform any function except extracting pages, while another is limited to filling in form fields and signing signature fields.

Note: remember to add your own certificate to the list of intended recipients of the encrypted document when you manage certificate-based security. This way, you have the access to the PDF file.


Encrypt PDF or PDF Portfolio with a certificate

To encrypt a single PDF or a PDF file within a PDF Portfolio with a certificate, you can use either the Certificate Security Settings dialog box or a custom Security Scheme. But if you want to encrypt an entire PDF portfolio, you can only use Certificate Security Settings.

  • Certificate Security Settings dialog box. You can specify the document components to encrypt, algorithm, recipients and their permissions. To open the Certificate Security Settings dialog box, choose Security > Encryption > Interactive Certificate. Or, open the Document Properties dialog box, click Security, and then select Certificate Security from the Security Method drop-down menu.

  • Security Scheme. This is a security settings file that you can customize and reuse. If you need to repeatedly apply the same set of security settings to multiple files, you can save time by creating a security scheme. See Create a new security scheme.


Encrypt a PDF or PDF Portfolio with a certificate

You can use Certificate Security Settings to encrypt a single PDF or a PDF portfolio and save your settings (e.g. files to encrypt and trusted recipients).

 

Use Certificate Security Settings to encrypt PDF or PDF portfolio

  1. Open a PDF or a PDF portfolio, and do any of the following to open Certificate Security Settings:
    • Choose File > Encryption > Interactive Certificate, and click in the popup dialog box.

    • Choose File > Properties to open Document Properties dialog box. Click Security tab, and choose Certificate Security from the Security Method drop-down menu. To encrypt an entire PDF portfolio, choose Option > Cover Sheet in advance so that changes made in security settings will be applied to the entire PDF portfolio.

  2. In the Certificate Security Settings dialog box, decide whether to save the settings as a scheme. Click Next >. Select the document components to encrypt, choose a level of encryption from the Encryption Algorithm drop-down menu, and click Next>. The encryption algorithm and key length are version-specific. Choose a PDF version compatible with the recipients' reader or PDF application.

    • If you select 128-bit, recipients must have PDF 1.5 and later to open the document.

    • If you select 128-bit AES, recipients must have PDF 1.6 and later to open the document.

    • If you select 256-bit AES, PDF 1.7 and later are required to open the document.

  3. Create a list of recipients for the encrypted PDF and then click Next>. Remember to always include your own certificate in the recipient list so that you also have access to the document. Select trusted contacts from the list of Trusted Identities and then click Add>> to add them to the list of recipients. Then, you can change encryption settings as stated below:

    • To add more trusted identities, click Import Certificate to trust list (A) and select a certificate file.

    • To check the information of a trusted recipient, select the recipient and then click Recipient Details (D) to open the Certificate Attributes dialog box.

    • To remove a recipient, select one and then click Remove<<. Make sure your certificate is still on the recipient list unless you don't want the access to the encrypted file.

    • To individually define permissions for each recipient, select one recipient and then click Set Permissions (C). In the Recipient Permission Settings dialog box, make any changes as needed and then click OK. For more on Recipient Permission Settings, see Restrict editing, printing and copying PDF content.

  4. Click Finish. Then click Save Now to apply this security scheme to the document.

chapt9_security_trustedidentities
Create a list of recipients A. Import Certificate to trust list B. Create Certificate C. Set Permission D. Recipient Details


Encrypt PDF by applying Certificate Security Scheme

Certificate Security Scheme keeps all of your security settings so that you can reuse and save time. If you keep close links with specific recipients, you can save the settings to a scheme and apply to the document without having to repeatedly add recipients every single time.

  1. Open a PDF or a portfolio and do any of the following to open Security Panel:

  • Choose Security > Security Panel .

  • Click Security Panel in Sidebar Navigation Pane.

  1. You can create a security scheme if needed. Click Create Security Scheme to open New Security Scheme dialog box, in which you set the name, description and appearance of it. When finished, click Next >, and select Use public key certificate as the security type. If you want to use a predefined security scheme, edit it before you apply. See Security Scheme.

  2. Do any of the following to apply a security scheme of Certificate Security:

  • Right-click the certificate security scheme that you want to apply and choose Apply Security Scheme.

  • Select the certificate security scheme that you want to apply. Click Security Scheme Option and choose Apply Security Scheme.

  • Double-click the certificate security scheme that you want to apply.

  1. Click Yes in the popup notification box.

  2. Click Save Now to apply the new security settings.


Adding certificate to Trusted Identities list

When you receive certificates from others, you can add them to your list of trusted identities and set them as trusted roots. There are two ways to store certificates in your list of trusted identities: 1) import an existing certificate or 2) add a certificate from a digital signature in a signed PDF document. The list of trusted identities helps you validate the signatures of the users on any documents you receive from them.

 

Import an existing certificate

  1. Open a PDF file.

  2. Choose Security > Trusted Identities.

  3. In the Manage Trusted Identities dialog box, click Add....

  4. In the Open dialog box, select the certificate to use and click Open.

  5. To set a certificate as a trusted identity in any documents, select a certificate and click Set as a Trusted Root.

 

Add a certificate from a digital signature in a signed PDF

You can directly add a certificate from a signed PDF document to your list of trusted identities.

  1. Open a PDF that contains digital signatures.

  2. Do any of the following to open the Signature Properties dialog box:

    • In the Signatures panel, right-click on the signature and select Properties....

    • Right-click on a signature field on your page and select Properties....

    • In the Signatures panel, click the Signatures Panel Options button and select Properties... from the menu.

  3. In the Signature Properties dialog box, click the General tab. In the Additional Information section, click Verify Identity....

  4. In the Verify Identity dialog box, click Add as a Trusted Root to store the certificate of the digital signature in your list of trusted identities, making signatures of the user valid on any documents.