Quick answer: Open the PDF in PDFCore, choose Secure PDF, enter an open password and/or owner password, choose print, copy and modify permissions, then save to a new file. Close it and test the result in a separate PDF reader before sharing.
Open password versus owner password
These two passwords serve different purposes:
- Open password (user password): the reader must provide it before viewing the encrypted PDF.
- Owner password: authorizes changes to security settings and controls permission flags such as printing, copying and modifying in compatible readers.
If only one password is entered in PDFCore, it can be used for both roles. For a controlled distribution, separate passwords can make responsibilities clearer: recipients receive the open password, while the document owner retains the owner password.
Permission flags are not digital rights management. Cooperative PDF readers enforce them, but a hostile or nonconforming tool may ignore restrictions once it can access the document. Use access controls, approved storage and organizational policy for sensitive information.
Protect a PDF with PDFCore
- Preserve an unprotected working copy in an approved location. Do not make a protected file your only copy.
- Open the PDF and choose Secure PDF. If the source is already restricted, supply the authorized owner password first.
- Enter the password required to open. Leave it blank only when recipients should be able to view the file without a password.
- Enter the owner password. Use a different strong password when security settings must be controlled separately.
- Choose permissions. Decide whether compatible readers should allow printing, copying text/content and modifying the document or annotations.
- Save to a new output filename. A suffix such as
-protectedreduces confusion. - Close all open copies and test. Reopen in PDFCore and at least one other reader. Check the password prompt and each permission that matters.
- Transfer the password separately. Do not send the protected PDF and its password in the same message or shared location.
Choose a strong, usable password
Prefer a long unique passphrase generated or stored by a password manager. Length and uniqueness matter more than replacing every letter with punctuation. Avoid company names, document titles, dates, phone numbers and passwords reused on other systems.
- Use a unique phrase for each distribution or sensitivity class.
- Record who is authorized to receive it.
- Store the owner password in an approved password manager or records system.
- Plan recovery before distribution; PDFCore does not recover forgotten passwords.
- Rotate the distribution file and password if a recipient should lose access.
What the permission choices mean
| Permission | When allowed | When restricted |
|---|---|---|
| Recipients can print through compatible readers | Useful for screen-only review, but cannot stop screenshots or photography | |
| Copy | Text and content extraction are allowed | Can reduce casual copying; may also hinder accessibility and legitimate reuse |
| Modify | Compatible readers can change the document and annotations | Helps signal that the distributed copy should remain unchanged |
Restrictions can affect assistive technology, indexing, archival workflows and automated review. Do not disable copying merely as a default if it prevents an authorized recipient from using the document accessibly.
Encryption is not the same as a signature
A password protects confidentiality and requests permissions. It does not prove who created the PDF or whether it changed after approval. A certificate-based digital signature serves authenticity and integrity goals. PDFCore 8.0.1 can place a typed or image signature appearance; it does not claim to create a certificate digital signature, timestamp or long-term validation package.
If legal authenticity matters, use an approved certificate-signing workflow after content is finalized. Changing or re-encrypting a signed PDF can invalidate its signature.
Removing a PDF password or restrictions
Use Remove restrictions only for a document you own or are authorized to modify. PDFCore asks for the owner password and creates a new unrestricted output. It does not attempt password cracking or recovery.
Keep an audit trail when removing restrictions is part of a business process. The unrestricted copy may contain information that was previously protected, so store it according to its actual sensitivity rather than its new technical state.
Security verification checklist
- The final file opens only with the intended open password.
- An incorrect password is rejected.
- The owner password can change security settings when authorized.
- Print, copy and modify behavior matches the chosen policy in target readers.
- The PDF still has the correct page count and visible content.
- Bookmarks, links, forms and attachments behave as required.
- No password is embedded in the filename, email subject or adjacent note.
- The recipient channel and password channel are separate.
- The unprotected original is retained or destroyed according to policy.
What password protection cannot do
Once an authorized person can view a document, technical controls cannot prevent every form of capture or disclosure. Screenshots, cameras, manual transcription and compromised endpoints remain possible. PDF passwords complement device security, least-privilege access, secure transfer, training and incident response; they do not replace those controls.
Questions about PDF passwords
Can I password-protect a PDF without uploading it?
Yes. PDFCore applies PDF security locally on Windows and saves a new file.
What happens if I forget the password?
PDFCore does not recover or crack it. Preserve an authorized original and store important passwords in an approved password manager.
Is restricting copy the same as redacting content?
No. Copy restrictions request reader behavior; the content remains in the PDF. Secure redaction removes covered source content from affected pages.
Can I email the password-protected file?
You can, but communicate the password through a separate approved channel and consider whether email itself meets the organization’s security requirements.
Protect locally, verify separately
Use PDFCore to set PDF passwords and permissions without uploading the source document.
Download PDFCore