Reference Guide

Manage Policies
276
PNPDeviceID. Using the previous PNPDeviceID as an example, a space before
and after the semicolon would cause neither of the substrings to be matched,
because the space character is not part of the PNPDeviceID.
Instructions...
1. Insert USB removable media.
2. Open System Profiler.
3. Under Hardware, select the USB device and find the Product ID and
Vendor ID, as follows:
Capacity:2.06 GB (2,055,019,008 bytes)
Removable Media:Yes
Detachable Drive:Yes
BSD Name:disk2
Product ID:0x5406
Vendor ID:0x0781 (SanDisk Corporation)
Version: 0.10
Serial Number:0000188C36725BC8
Speed:Up to 480 Mb/sec
Manufacturer:SanDisk
Location ID:0x24100000
Current Available (mA):500
Current Required (mA):200
Partition Map Type:MBR (Master Boot Record)
S.M.A.R.T. status:Not Supported
4. The following Whitelist Rules can be used:
USBVendorName=abc
USBVendorNum=0x02
USBVendorNum=2,USBProductNum=3
USBVendorNum=2,USBProdName=abc
For this example, in the Security Management Server, add the
following key/pair string to the EMS Device Whitelist policy, as shown
below:
"USBVendorNum=0x0781,USBProductNum=0x05406"
(including quotes)
5. When satisfied with the EMS Device Whitelist rules, save and commit
the policy.
EMS Trust for Unsupported
File Systems
Ignore
Ignore, Provisioning Rejected, Unshieldable
Specifies how media are handled when formatted by file systems that are not
supported with Encryption External Media.
Restricted user list for
access to unencrypted
media
Dictionary
Users matching this dictionary are restricted from unencrypted media use.
Example:
<key>AccessUnencryptedMediaRestrictionUsers</key>
<dict>
<key>dsAttrTypeStandard:AuthenticationAuthority</key>
<array>
<string>;Kerberosv5;;username1@domainName.com;domainName.com*</string>
<string>;Kerberosv5;;@domainName.org;domainName.org</string>
</array>
</dict>
Restrict Access to
Unencrypted Media
Full
Full, Read Only, Block
Specify how media encrypted with Encryption External Media is handled for
users matching unencrypted media restriction.
See basic settings