SetPDFMACEnabled

Security and signatures

Description

Enables or disables a standalone PDF MAC integrity token for the selected document and subsequent file encryption operations on the same library instance

The token authenticates the complete encrypted PDF except for its own hexadecimal value and is verified automatically when a protected document is loaded

Syntax

Delphi

Function TPDFlib.SetPDFMACEnabled(Enabled: Integer): Integer;

ActiveX

Function PDFlib::SetPDFMACEnabled(Enabled As Long) As Long

DLL

int DLSetPDFMACEnabled(int InstanceID, int Enabled);

Parameters

EnabledUse a nonzero value to enable PDF MAC generation or zero to disable it before encryption

Return values

1The setting was accepted
0The selected document state cannot accept the setting; LastErrorCode returns 418

Remarks

Call this function before Encrypt, EncryptFile, or EncryptFileEx

PDF MAC requires encryption strength 4 for AES-256 revision 6 or strength 5 for AES-GCM; other strengths fail with error 418

Generation uses a 32-byte random MAC key, HKDF-SHA-256 key derivation, AES-256 key wrap, HMAC-SHA-256, and a CMS AuthenticatedData token

See also

GetPDFMACStatus, ValidatePDFMAC, Encrypt