The user password: the real one
Set this and the document content is encrypted. Without the password, a reader holds ciphertext and shows you nothing: no pages, no text, no thumbnails.
This is what people mean when they say a PDF is locked. Lose it and the file is gone.
The owner password: a set of instructions
Set this and the content stays readable. What changes is the permission bits: printing, copying, editing, annotating, assembling. Readers that honor the flags gray those actions out.
The user password can be left empty while the owner password is set. That produces a file anyone can open and most readers won’t let them print or copy. Plenty of software does exactly this by default and calls the result protected.
Find out which one you have, in five seconds
- Try to open the file. If it asks for a password before showing anything, there’s a user password, and you need it.
- If it opens without asking but Print or Copy is unavailable, there’s an owner password. The content was never encrypted.
- To know rather than guess, drop the file into the tool here. The first panel reports the scheme (RC4 or AES), the key length (40, 128 or 256) and the permission bits, and asks for a password only if one is genuinely required.
What each scheme means
- RC4-40
- The original scheme. Broken for practical purposes, so keep nothing sensitive behind it.
- RC4-128
- The long-standing default of the 2000s, still common in exports from that era.
- AES-128
- Acrobat 7 era. A strong cipher, a short key by current standards.
- AES-256
- What modern tools produce. The password is the weak point, not the cipher.
If what you want is a file that stops asking
For a user-password file, the tool derives the key from the password you supply and writes an unencrypted copy. For an owner-password file there’s nothing to derive. The flags are cleared and the pages are copied as they were.
Either way the export is a plain PDF. Text layer, fonts and layout are untouched, and the metadata is a separate job if it matters.
