SetPDFMACEnabled
Security and signatures
Description
Enables or disables a standalone PDF MAC integrity token for the selected document and subsequent file encryption operations on the same library instance
The token authenticates the complete encrypted PDF except for its own hexadecimal value and is verified automatically when a protected document is loaded
Syntax
Delphi
Function TPDFlib.SetPDFMACEnabled(Enabled: Integer): Integer;
ActiveX
Function PDFlib::SetPDFMACEnabled(Enabled As Long) As Long
DLL
int DLSetPDFMACEnabled(int InstanceID, int Enabled);
Parameters
| Enabled | Use a nonzero value to enable PDF MAC generation or zero to disable it before encryption |
|---|
Return values
| 1 | The setting was accepted |
|---|---|
| 0 | The selected document state cannot accept the setting; LastErrorCode returns 418 |
Remarks
Call this function before Encrypt, EncryptFile, or EncryptFileEx
PDF MAC requires encryption strength 4 for AES-256 revision 6 or strength 5 for AES-GCM; other strengths fail with error 418
Generation uses a 32-byte random MAC key, HKDF-SHA-256 key derivation, AES-256 key wrap, HMAC-SHA-256, and a CMS AuthenticatedData token