K
klose
I am trying to create a GP certificate rule for to prevent a software
package from being installed.
I tried the HASH method, which does not work on all digitally signed
programs.
Senerio:
Block install of Norton SS V7.0 (2004) exceutable is signed by Symantec
Corporation.
SYMSETUP.EXE
I imported the cer into my test machine, then exported in all three formats.
The software restriction cert rule was pointed to each of these at one test
or another.
Each was tried but the install still worked.
I noticed an article by
http://www.rtfm-ed.co.uk/microsoft/tips/windows/win2003.htm
that mentions the software rest cert rules don't work unless you enable
Computer Config\windows settings\security settings\local policies\security
options\system settings: Use Certificate Rules on Windows Exec for Sofware
Restrictio polices and enable this policy.
I do not see this option any place.
Has any done this successfully yet?
Tom
package from being installed.
I tried the HASH method, which does not work on all digitally signed
programs.
Senerio:
Block install of Norton SS V7.0 (2004) exceutable is signed by Symantec
Corporation.
SYMSETUP.EXE
I imported the cer into my test machine, then exported in all three formats.
The software restriction cert rule was pointed to each of these at one test
or another.
Each was tried but the install still worked.
I noticed an article by
http://www.rtfm-ed.co.uk/microsoft/tips/windows/win2003.htm
that mentions the software rest cert rules don't work unless you enable
Computer Config\windows settings\security settings\local policies\security
options\system settings: Use Certificate Rules on Windows Exec for Sofware
Restrictio polices and enable this policy.
I do not see this option any place.
Has any done this successfully yet?
Tom