Device Guard: using catalog files
hello!
the following article says must create temporary policy before creating catalog file:
https://technet.microsoft.com/itpro/windows/keep-secure/getting-apps-to-run-on-device-guard-protected-devices
the final step in article copy catalog file windows folder:
q1: should result of such copying - in other words how catalog file alone can increase security (as remember ci policy running in audit mode)?
this article says:
https://technet.microsoft.com/en-us/itpro/windows/manage/add-unsigned-app-to-code-integrity-policyq2: don't understand how policies need when creating catalog files: article above says 1) "code integrity policy", 2) "create catalog files" - means creating second temporary code integrity policy 3) "default policy" , 4) "existing ci policies" - how of these policies relates each other?
q2-1: why can't create catalog file using code integrity policy (already created , running in audit mode)?
zhttps://technet.microsoft.com/en-us/itpro/windows/keep-secure/creating-a-device-guard-policy-for-signed-apps?f=255&mspperror=-2147217396
q3: doesn't hash keyword means can add unsigned apps code integrity policies without catalog files?
this webinar (in russian, ~at 25:40) - https://channel9.msdn.com/series/windows-10-device-protection-with-device-guard/01 - explains following command:
new-cipolicy -level pcacertificate -filepath $initialcipolicy -userpes -fallback hash
...will add policy both signed (by pcacertificate rule) , unsigned (hash rule) applications.
in case why need catalog files?
thank in advance,
michael
hi mf47,
as known windows server tp has not been released, suggest upgrade version latest see if helps or waiting official released version.
please check if following link helpful:
besides, seems issue more related win10, better help, suggest post on forum below:
https://social.technet.microsoft.com/forums/en-us/home?category=winpreview2014
andy_pan
Windows Server > Windows Server Technical Preview
Comments
Post a Comment