Skip to content

Executables authorizations

The Executables authorizations module lets an administrator declare lists of allowed or forbidden programs, then attach them to user groups and targets (published applications or direct-access machines). It is used to enforce application control during CyberElements sessions: only the executables of a white list are allowed, or all except those of a black list.

The main screen presents three tabs, organised by control granularity.

This tab lists the existing executable lists, in a Name column. Each row is preceded by an icon showing its type: a green tick for a White list (approved executables) or a red forbidden sign for a Black list (banned executables). Expanding a row shows the executables the list is made of.

Action Details
Add + button: opens the Add a list of executables window (see the table below).
Properties Select a row then click the icon, or double-click it. The Edit a list of executables window is identical to the creation one — only the List name becomes read-only.
Delete Select one or several rows then click ×. Deletion asks for confirmation.
Search Search field at the top right. Filters by name substring. The search fires 700 ms after the last keystroke or immediately with Enter.
Pagination 15, 25 or 50 rows per page (default 15).

Fields of the add window:

Field Description
List name Mandatory. A whitespace-only string is rejected.
List type Radio buttons White (default) or Black.
Executable name Input field followed by the Add button: each executable joins the grid above, whose Name column lists the content. The Delete button removes the selected executable. While no executable has been entered, the grid reads No executable in the list.

This tab lists the authorization contracts, which attach one or more lists to user groups and to published applications (organised by category). The Name column is preceded by a padlock icon.

Expanding a contract shows the lists attached (green tick for white lists, red forbidden sign for black ones), the domains and groups concerned, then the target categories and applications.

The Add an authorization contract window carries a Name field — read-only when editing — and three tabs:

Tab Content
Groups A Domain drop-down, then two lists (available on the left, selected on the right) with search. Add everybody, Remove and Remove all buttons.
Authorizations lists Two drag-and-drop lists, each with Select All. When empty, the left-hand list reads No authorization list.
Applications Application tree by category; the selection can carry a whole category or a single application. With no category declared, the tree reads No Categories.

The Previous and Next buttons move between tabs. The Validate button only becomes enabled once the contract holds at least one group, one list and one target.

The Properties and Delete actions, the search and the pagination behave as in the first tab.

This tab lists the direct authorization contracts — the variant aimed at machines targeted directly rather than at published applications.

Expanding a contract shows the lists attached, the user groups by domain and the target machines.

The Add a direct authorization contract window carries the Name and Description fields, then three tabs:

Tab Content
Groups A Domain drop-down and two lists. The Manual entry button opens the Addition of a custom group window (Name and Microsoft Domain fields); a duplicate is rejected with This group is already in the list. Select All, Remove and Remove all buttons.
Authorizations lists Two drag-and-drop lists, as for a regular contract.
Machines Two drag-and-drop lists. When empty, the left-hand list reads No available machine.

Here too, Validate requires at least one group, one list and one machine.

White list / Black list

A White list only allows the executables it holds — every other program is blocked during the session. A Black list allows every executable except the ones it holds.