You can define protection rules when changing or creating a protection policy or rule group.
Select Menu → Policy → Policy Catalog.
Select Solidcore 8.x.x: Change Control for the product.
You can create a policy or duplicate an existing one.
Read-protect files and directories.
Select a policy from the list, then click Add on the Read-Protect tab. The Add File dialog box appears.
Specify the file or directory name and indicate whether to include or exclude from read protection.
Click OK.
Write-protect files and directories.
Select a policy from the list, then click Add on the Write-Protect File tab. The Add File dialog box appears.
Specify the file or directory name and indicate whether to include or exclude from write protection.
Click OK.
Write-protect registry keys:
Click Add on the Write-Protect Registry tab. The Add Registry dialog box appears.
Specify the registry key and indicate whether to include or exclude from write protection.
Click OK.
Specify trusted programs permitted to override the read and write protection rules.
Click Add on the Updater Processes tab. The Add Updater dialog box appears.
Specify whether to add the updater based on the file name, SHA-1, or SHA-256. If you add the updater by name, it isn't authorized automatically. But, when you add the updater by SHA-1 or SHA-256, the updater is authorized.
Enter the location of the file (when adding by name), SHA-1, or SHA-256 of the executable file.
Enter a unique identification label for the executable file. For example, if you specify Adobe Updater Changes as the identification label for the
Adobe_Updater.exefile, all change events made by theAdobe_Updater.exefile are tagged with this label.Specify conditions that the file must meet to run as an updater:
Select None to allow the file to run as an updater without any conditions.
Select Library to allow the file to run as updater only when it has loaded the specified library. For example, when configuring
iexplore.exeas an updater to allow Windows Updates using Internet Explorer, specifywuweb.dllas the library. This makes sure that theiexplore.exeprogram has updater rights only until the Web Control library (wuweb.dll) is loaded.Select Parent to allow the file to run as an updater only if it is started by the specified parent. For example, when configuring
updater.shas an updater to allow changes to Mozilla Firefox, specifyfirefoxas the parent. Althoughupdater.exeis a generic name that can be part of any installed application, using the parent makes sure that only the correct program is allowed to run as an updater.
Indicate whether to disable inheritance for the updater. For example, if Process A (that is set as an updater) starts Process B, disabling inheritance for Process A makes sure that Process B doesn't become an updater.
Indicate whether to suppress events generated for the actions performed by the updater. Typically, when an updater changes a protected file, a
File Modifiedevent is generated for the file. If you select this option, no events are generated for changes made by the updater.Click OK.
Specify users permitted to override the read and write protection rules.
On the Users tab, click Add. The Add User dialog box appears.
On the Add User dialog box, create two rules for each user: one with UPN/SAM and domain account name (in domainName\user format) and another with domain netbiosName (in netbiosName\user format).
Specify a unique identification label for the user. For example, if you specify John Doe Changes as the identification label for the John Doe user, all changes made by the user are tagged with this label.
Type the user name, then click OK.