Skip to content

PDF encryption

Papyra encrypts PDF output with AES-256 using the PDF 2.0 standard security handler (ISO 32000-2, /V 5 /R 6) - the current, non-deprecated encryption scheme. Older schemes (RC4, AES-128) are deliberately not offered.

byte[] pdf = document.RenderAsPdf(new PdfRenderOptions
{
Standard = PdfStandard.Pdf20,
Encryption = new PdfEncryption
{
UserPassword = "open-me",
OwnerPassword = "admin-only",
Permissions = PdfPermissions.Print | PdfPermissions.ExtractForAccessibility,
},
});

PDF/A forbids encryption, and Papyra’s default output is PDF/A. Encryption therefore requires Standard = PdfStandard.Pdf20 - the plain (non-archival) PDF 2.0 mode, which carries none of the PDF/A scaffolding (no XMP packet, output intent, or embedded ICC profile; document metadata lives in the Info dictionary, encrypted like everything else).

Any other standard throws at render time, and the bundled analyzer flags the literal-initializer case at compile time as PAPY106, with a code fix that sets the standard for you.

Encryption and Factur-X e-invoicing are mutually exclusive - Factur-X requires PDF/A-3. Plain attachments work under Pdf20 and are encrypted along with the rest of the file.

UserPassword Required to open the document. When null or empty, the document opens without a password, but Permissions still apply.
OwnerPassword Grants full access regardless of Permissions. When null, the user password also acts as the owner password.

At least one password must be non-empty. Passwords are Unicode-normalized (NFC), UTF-8 encoded, and truncated to 127 bytes per the spec. Full RFC 4013 SASLprep is not applied - everyday passwords (including non-ASCII letters like umlauts) interoperate with mainstream readers, but passwords built from exotic control or format characters may not round-trip against a strictly conforming reader.

PdfPermissions is a flags enum mapped to the standard permission bits (ISO 32000-2 Table 22). The default is All.

Flag Allows
Print Printing (possibly degraded without PrintHighResolution)
PrintHighResolution Full-resolution printing
CopyContent Copying/extracting text and graphics
ExtractForAccessibility Extraction for accessibility (PDF 2.0 readers always allow this; the bit still matters to older readers)
ModifyContents Editing document content
Annotate Adding annotations and filling forms
FillForms Filling forms even when Annotate is denied
AssembleDocument Inserting/rotating/deleting pages, creating bookmarks

Permissions restrict readers opened with the user password; the owner password is never restricted. Note that permissions are an instruction to the viewer, not cryptography - a viewer can simply ignore them; only the passwords are cryptographically enforced.

Papyra’s unencrypted output is byte-identical for identical documents. Encrypted output deliberately is not: the file encryption key, salts, and per-string/stream initialization vectors are freshly random on every render, as sound cryptographic practice requires. Rendering the same document twice produces different bytes that decrypt to identical content.