Adding Signatures and Security in Adobe Acrobat 9

Acrobat 9 gives you all the tools you need to sign a PDF document to indicate your approval or certify a PDF document to approve its contents. Acrobat also provides the tools you need to secure your PDF documents. You can use passwords to restrict users from opening, printing, and editing PDF documents. You can use a certificate to encrypt PDF documents so that only an approved list of users can open them. If you want to save security settings for later use, you can create a security policy that stores security settings. You can also permanently remove sensitive content from your PDF documents by using the Redaction feature.

In this exercise, you’ll create a digital ID that uses an image, digitally sign documents, apply password protection to a file to restrict who can open it, apply a password to limit printing and changing of the file, and learn how to certify a document. (If you don’t have the example files from the book, you can work with your own PDF documents.)

About Digital Signatures

A digital signature, like a conventional handwritten signature, identifies the person signing a document. Unlike a handwritten signature, however, a digital signature is difficult to forge because it contains encrypted information that is unique to the signer and easily verified.

To sign a document, you must obtain a digital ID from a third-party provider or create a self-signed digital ID for yourself in Acrobat. The digital ID contains a private key that is used to add the digital signature and a certificate that you share with those who need to validate your signature.

For information about Adobe security partners that offer third-party digital IDs and other security solutions, visit the Adobe.com.

Creating Digital Signatures

For this exercise, you’ll use a self-signed digital ID, which is often adequate for signing documents within a corporate environment. In the Security preferences, you can set the appearance of your digital signature, select your preferred digital signature signing method, and determine how digital signatures are verified. Before you open a signed document, you should also set your preferences to optimize Acrobat for validating signatures.

  1. Start Acrobat.
  2. Choose Edit > Preferences (Mac OS: Acrobat > Preferences), and select Security in the left pane. You may need to scroll down the list.

Adding Images to Your Digital Signatures

First you’ll add the company logo to your signature block.

In the Preferences dialog box, click New to open the Configure Signature Appearance dialog box. This is where you can personalize your digital signature by adding a graphic. For the moment, the Preview pane shows the default digital signature appearance, which is text-based.

  1. First you’ll name the appearance of your signature and then add your corporate logo to the signature block.
  2. In the Title text box, enter a name for the appearance of your signature. We entered Logo because we’re going to add our corporate logo to the signature line. You should use a name that’s easy to associate with the contents of the signature appearance. You can create several digital signatures for yourself.
  3. In the Configure Graphic section of the dialog box, select the Imported Graphic option, and click File
    In the Select Picture dialog box, click Browse, and select the Clarity_Logo.pdf file in the Lesson08 folder. Click Select, and then click OK to return to the Configure Signature Appearance dialog box.

Now you’ll specify the information to be included in the text block of your signature. You’ll include your name, the reason for signing the document, and the date.

In the Configure Text area of the Configure Signature Appearance dialog box, leave Name, Date, and Reason selected. Deselect all the other options (see Figure 4).

  1. When you’re happy with the preview of your signature block, click OK.
  2. In the Preferences dialog box, select “View documents in preview document mode when signing.”
  3. Click Advanced Preferences, and click the Creation tab. Select the “Show reasons when signing” option, and click OK

Signing in Preview Document Mode

Use the Preview Document mode when you want to analyze a document for content that may alter the appearance of the document after you sign it. Such content may include transparency, scripts, fonts, and other dynamic content that can alter a document’s appearance. The Preview Document mode suppresses this dynamic content, allowing you to view and sign the document in a static and secure state.

When you view a PDF in Preview Document mode, a document message bar lets you know whether the PDF complies with the PDF/SigQ Level A or Level B specification. Level A indicates that the document contains no dynamic content that can alter its appearance. Level B indicates that the document contains dynamic content that can be suppressed during signing. If the document doesn’t comply with Level A or B, you may want to refrain from signing the document and contact the document author about the problem.

You can use Preview Document mode to check the integrity of a document at any time.

Acrobat automatically runs the Document Integrity Checker, which checks for Qualified Signatures conformance, before entering the signature preview mode.

You opt to use the Preview Document mode in the Security preferences.

Selecting a Signing Method

Now you’ll specify a default signing method.

Click the Advanced Preferences button in the Security pane of the Preferences dialog box again.

On the Verification tab of the Digital Signatures Advanced Preferences dialog box, notice that “Require certificate revocation checking to succeed whenever possible during signatures verification” is selected . This option ensures that certificates are always checked against a list of excluded certificates during validation.

  1. Make sure that the first verification option is selected. (“Use the document-specified method. Prompt if it is not available.”) You’ll be prompted if you don’t have the necessary software when you try to open a document.Also on the Verification tab is a pop-up menu allowing you to choose the default method for verifying signatures. This menu is dimmed unless you change the verification method by selecting a different radio button. On the Creation tab, you set the default method to be used when signing and encrypting documents.
  2. Click the Creation tab and check that Adobe Default Security is selected for the “Default method to use when signing and encrypting documents” option.On Windows, you also have a Windows Integration tab where you can specify whether identities from Windows certificates can be imported and whether all root certificates in the Windows certificates can be trusted. We recommend that you leave the default settings on this tab.
  3. Click OK, and click OK again to close the Preferences dialog box.

Opening the Work File

In this part of the exercise, you’ll send an advertisement for Clarity skin lotion to an advertising agency for finalization. You’ve reviewed the document and made required changes, and now you’ll sign the revised advertisement electronically.

Signing a document electronically offers several advantages, not least of which is that you can email the signed document rather than having to fax it or send it by courier. Although digitally signing a document doesn’t necessarily prevent people from changing the document, it does allow you to track any changes made after the signature is added and revert to the signed version if necessary. (You can prevent users from changing your document by applying appropriate security to the document, as you’ll see later in this exercise.)

  1. Choose File > Open.
  2. Select Lotion.pdf in the Lesson08 folder, and click Open.
  3. Choose File > Save As, rename the file Lotion1.pdf, and save it in the Lesson08 folder.

Creating Digital IDs

A digital ID is like a driver’s license or passport. It proves your identity to people with whom you communicate electronically. A digital ID usually contains your name and email address, the name of the company that issued your digital ID, a serial number, and an expiration date.

A digital ID lets you create a digital signature or decrypt a PDF document that has been encrypted. You can create more than one digital ID to reflect different roles in your life. For this section of the exercise, you’ll create a digital ID for T. Simpson, Director of Advertising.

  1. Choose Advanced > Security Settings.
  2. In the Security Settings dialog box, select Digital IDs in the left pane. Then click the Add ID button
  1. You’ll create a self-signed digital ID. With a self-signed ID, you share your signature information with other users by using a public certificate. (A certificate is a confirmation of your digital ID and contains information used to protect data.) While this method is adequate for most unofficial exchanges, a more secure approach is to obtain a digital ID from a third-party provider.
  2. In the Add Digital ID dialog box, select “A new digital ID I want to create now.” Click Next.If you’re working in Mac OS, skip to step 5. If you’re working in Windows, you’ll choose where to store your digital ID. The http://www.rsa.com/rsalabs/node.asp?id=2138 digital ID file option stores the information in a file that you can share with others. A Windows default certificate digital ID is stored in the Windows certificate store. Because you want to share your digital ID with colleagues, you’ll use the PKCS #12 option.
    1. Make sure that New PKCS #12 Digital File ID is selected, and click Next.Now you’ll enter your personal information.
    2. Enter the name you want to appear in the Signatures tab and in any signature field that you complete, and enter a corporate or organization name (if necessary) and an email address. We entered T. Simpson, Director for the name, Clarity for the organization name, and clarity@xyz.net for the email address. Make sure that you select a country/region. We used the default US – United States.
    3. Choose a key algorithm to set the level of security. We chose the default 1024-bit RSA. Although 2048-bit RSA offers more security protection, it’s not as universally compatible as 1024-bit RSA.Now you’ll specify how the encryption is applied. You can use the digital ID to control digital signatures, data encryption (security), or both. When you encrypt a PDF document, you specify a list of recipients from your trusted identities, and you define the recipient’s level of access to the fileā€”for example, whether recipients can edit, copy, or print the files. You can also encrypt documents by using security policies.

      For this exercise, you’ll choose digital signatures.

    4. From the “Use digital ID for” drop-down list, choose Digital Signatures, and then click Next
    1. If you want to change the location where your information is stored, click the Browse button and locate the required folder. For this exercise, you’ll use the default. Now you must set a password. We used Lotion123 as the password. Reenter your password to confirm it.

      NOTE

      Remember that the password is case-sensitive. Be sure to make a note of your password and keep it in a safe place. You cannot use or access your digital ID without this password. Your password cannot contain double quotation marks ([dp][dp]) or any of the following characters:

      ! @ # $ % ^ & * , | \ ; < > _

    2. Click Finish to save the digital ID file in the Security folder.

    Your new digital ID appears in the Security Settings dialog box. In Windows, select the digital ID to see its details. In Mac OS, double-click it to view the certificate details. When you’ve finished checking your digital ID, click Close to close the dialog box.

    Sharing Certificates with Other People

    Your digital ID includes a certificate that other people need in order to validate your digital signature and to encrypt documents for you. If you know that others will need your certificate, you can send it in advance to avoid delays when exchanging secure documents. Businesses that use certificates to identify participants in secure workflows often store certificates on a directory server that participants can search to expand their list of trusted identities.

    If you use a third-party security method, you usually don’t need to share your certificate with others. Third-party providers may validate identities using other methods, or these validation methods may be integrated with Acrobat. See the documentation for the third-party provider.

    When you receive a certificate from someone, that person’s name is added to your list of trusted identities as a contact. Contacts are usually associated with one or more certificates and can be edited, removed, or reassociated with another certificate. If you trust a contact, you can set your trust settings to trust all digital signatures and certified documents created with that certificate.

    You can also import certificates from a certificate store, such as the Windows certificate store. A certificate store may contain numerous certificates issued by different certification authorities.

    Now you’ll sign the advertisement and return it to the agency.