HP Z620 HP Remote Graphics Software 5.4.7 - Page 148

C:\Program Files\Hewlett-Packard\Remote Graphics Sender\hprUsbAcl.xsd

Page 148 highlights

9. Serial Number USB device mounting can also be allowed/denied based on the following two parameters: 10. IP address of the Local Computer 11. The domain group of the local user The ACL file supports two rule types: "allow" and "deny". The rules are evaluated by the Remote Computer for each USB connection request from a Local Computer as follows: ● If any rule indicates the USB connection should be denied, the connection is denied, regardless of any other rule. ● If any rule indicates the USB connection should be allowed, and if there are no rules that deny the connection, the connection is allowed. ● If no rules match at all, the connection is denied. Therefore, a deny rule takes precedence over an allow rule. The ACL file is implemented as an XML (Extensible Markup Language) file. The ACL schema file is located at: C:\Program Files\Hewlett-Packard\Remote Graphics Sender\hprUsbAcl.xsd For backwards compatibility, the following default ACL file(installed during Sender installation) allows all USB connections to be made: C:\Program Files\Hewlett-Packard\Remote Graphics Sender \hprDefaultUsbAcl.xml The names for these files can be changed using the properties described in Sender USB access control list properties on page 192. The default ACL file contains the following contents, which allows all USB connections to be made: rule type="allow"> Allow all USB devices (HP default) The following example ACL file denies all remote USB attachment requests: Rules may contain filters based on the 11 parameters listed previously. These parameters are repeated below along with the name of the filter element. 1. Device Class- bDeviceClass 2. Device Subclass- bDeviceSubclass 3. Device Protocol- bDeviceProtocol 4. Vendor ID- idVendor 5. Product ID- idProduct 6. Device BCD- bcdDevice 7. Manufacturer- manufacturer 8. Product Type- product 132 Chapter 6 Advanced capabilities

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247

9.
Serial Number
USB device mounting can also be allowed/denied based on the following two parameters:
10.
IP address of the Local Computer
11.
The domain group of the local user
The ACL file supports two rule types: “allow” and “deny”. The rules are evaluated by the Remote
Computer for each USB connection request from a Local Computer as follows:
If any rule indicates the USB connection should be denied, the connection is denied, regardless of
any other rule.
If any rule indicates the USB connection should be allowed, and if there are no rules that deny the
connection, the connection is allowed.
If no rules match at all, the connection is denied.
Therefore, a deny rule takes precedence over an allow rule. The ACL file is implemented as an XML
(Extensible Markup Language) file. The ACL schema file is located at:
C:\Program Files\Hewlett-Packard\Remote Graphics Sender\hprUsbAcl.xsd
For backwards compatibility, the following default ACL file(installed during Sender installation) allows
all USB connections to be made:
C:\Program Files\Hewlett-Packard\Remote Graphics Sender
\hprDefaultUsbAcl.xml
The names for these files can be changed using the properties described in
Sender USB access control
list properties
on page
192
. The default ACL file contains the following contents, which allows all USB
connections to be made:
<?xml version="1.0" encoding="ISO-8859-1" standalone="no"?> <hprUsbAcl>
rule type="allow"> <name>Allow all USB devices (HP default)</name> </
rule> </ruleset> </hprUsbAcl>
The following example ACL file denies all remote USB attachment requests:
<hprUsbAcl> <ruleset> <rule type="deny"/> </ruleset> </hprUsbAcl>
Rules may contain filters based on the 11 parameters listed previously. These parameters are repeated
below along with the name of the filter element.
1.
Device Class— bDeviceClass
2.
Device Subclass— bDeviceSubclass
3.
Device Protocol— bDeviceProtocol
4.
Vendor ID— idVendor
5.
Product ID— idProduct
6.
Device BCD— bcdDevice
7.
Manufacturer— manufacturer
8.
Product Type— product
132
Chapter 6
Advanced capabilities