[USB] USB devices getting blocked on reboot
So I implemented USB blocking and whitelisting in an environment following this guide. Now, when we reboot any machine that has these rules in place, all USB devices immediately get blocked. All of them, even the ones I've explicitly allowed by idVendor and idProduct. The USB root hubs (usb1 and usb2) both get authorized successfully, but nothing else does, even though the rules. So what gives? I've tried enabling debug logging in udev using
Code:
udevadm control --log-priority=debug |
Most of time I'd think some small edit is wrong or some sequence of what is OK versus what is not at boot.
Might look at usbguard also. |
Quote:
So it's definitely the rules and something about the way they're allowing/not allowing things during boot time. Any suggestions for how to trace this would be welcome. |
I agree with jefro - especially after your experiences in the previous thread.
I don't like the theory of that link for gross disabling. The whole idea of dropping through to a disable unless matched prior is just waiting for this scenario. I might be inclined to test a match and add a separate alias - that way you know what has "hit". If the alias(s) aren't there later, you know your tests (or logic) are wrong. |
Quote:
Maybe I can have the disable part create some sort of log. Like a RUN+= at the end that tells it to echo out the idProduct and idVendor (or other identifying attributes) to a text file for each thing that got disabled. |
Posted in the wrong thread
|
All times are GMT -5. The time now is 11:27 AM. |