usbguard in Debian ================== 1. Policy generation -------------------- On first installation (or if /etc/usbguard/rules.conf has been deleted), usbguard will ask to run: # usbguard generate-policy to generate a rule set (policy) in /etc/usbguard/rules.conf which authorizes the currently connected USB devices. 2. Desaster recovery / unbricking --------------------------------- In extremly rare cases, generating the policy doesn't detect required input devices such as keyboards, which will disable them until stopping usbguard. In cases where no input is possible anymore, the system can be powered off and any one of the following boot paramters can be used to make usbguard not be started: > usbguard=0 > usbguard=false 3. Managing devices ------------------- All devices with the current active rules can be listed with: # usbguard list-devices Devices can be unblocked with: # usbguard allow-device ${id} where '${id}' is the id listed at the beginning of the line of the 'list-devices' command output. Devices can be blocked with: # usbguard block-device ${id} Devices can be permanently by allowed or blocked (i.e. written to rules.conf and thus allowed/blocked at the start of the system) with the '-p' option to the 'block-device' or 'allow-device' command. Permanet rules can be listed with: # usbguard list-rules 4. IPC interface ---------------- usbguard provides a public IPC interface. By default, /etc/usbguard/usbguard-daemon.conf allow the 'plugdev' group access to the IPC interface. -- Daniel Baumann Sun, 27 Sep 2026 02:13:31 +0200