What are certificates?

Prev Next

Application Control allows trusted certificates that are associated with software packages to run on a protected system.

After you add a certificate as a trusted or authorized certificate, you can run all software, signed by the certificate on a protected system without entering Update mode. For example, if you add Adobe's code-signing certificate, all software issued by Adobe and signed by Adobe's certificate are allowed to run.

Note

Application Control supports only X.509 certificates.

To allow in-house applications to run on protected systems, you can sign the applications with an internal certificate and define the internal certificate as a trusted certificate. After you do so, all applications signed by the certificate are allowed.

You can also provide updater permissions to the certificate. All applications and binary files that are either added or changed on a system and signed by a certificate that has the updater permissions are automatically added to the allow list. Use this option carefully because it makes sure that all executable files signed by the certificate acquire updater rights.