Using checksum values

Prev Next

You can override the protection applied to a system by authorizing certain files based on their SHA-1 or SHA-256 values.

Authorizing files by their SHA-1 or SHA-256 value allows them to run on a protected system. If a file is not added to the allow list but configured as an authorized file, it is allowed to run. Regardless of the source of a file, if the SHA-1 or SHA-256 value matches, the file is allowed to run. Likewise, files can be banned from execution based on their checksum, preventing them to run even if the files are in the allow list.

You can also provide updater permissions to an authorized file. Configuring an authorized binary as an updater provides the updater permissions in addition to the execution. An authorized file that is configured as an updater is allowed to update or run software on a protected system. Installers can also be authorized by SHA-1 or SHA-256 value and configured as updaters to allow them to install new software and update the software components. For example, if you authorize the installer for the Microsoft Office 2010 suite by SHA-1 or SHA-256 and also configure the installer as an updater, if the SHA-1 or SHA-256 value matches, the installer is allowed to install the Microsoft Office suite on the protected systems.