Bookmark this page

Summary

  • The USBGuard daemon protects your systems against suspicious USB devices by implementing allowlist and blocklist capabilities based on device attributes.

  • The USBGuard daemon allows a USB device based on the policy that a set of rules defines.

  • The usbguard command manages the USB device authorization rules.

  • The USBGuard daemon uses the /etc/usbguard/usbguard-daemon.conf configuration file to load rules that allow users and groups to use the IPC interface.

  • The USBGuard daemon authorizes specific devices, or classes of devices.

  • You can create policies that match multiple devices and that reject devices with a suspicious combination of interfaces.

Revision: rh415-9.2-a821299