๐Ÿ“‹ GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROCโ€ฆSaaS discovery for data governanceFree enriched web chat widget๐Ÿš€ Enriched remote support without your laptop

Elevation Publishers

Review the software publishers whose signed programs have asked for administrator rights, and mark each one as trusted, watched or blocked.

Where to find it
Devices โ€บ Application Elevation โ€บ Publishers
Who can use it
Anyone who can see the page can review it; saving a verdict is checked when you save (elevation Rules or Admin permission expected)
Plan
Application Elevation (Application Control + PAM)
For
Everyone

What the page is for

Most business software is digitally signed by its publisher. Lavawall keeps a catalogue of the code-signing certificates it has seen on your computers. This page lists them with the publisher name, certificate fingerprint, issuer, expiry date, and how many of your devices have seen it.

For each publisher you can record your company's verdict. That verdict feeds the reputation shown on elevation requests, so a request from a trusted vendor reads differently from one signed by a publisher you have never reviewed. A block from Lavawall always wins over a company verdict.

What you see

The Elevation Publishers page, with the verdict filter, search, code-signing publishers table and set publisher verdict dialog numbered 1 to 4.
The Elevation Publishers page. Numbers match the list below.
  1. Verdict filter: All, Unreviewed, Trusted, Watch and Blocked.
  2. Search: by publisher, organization or thumbprint.
  3. Code-signing publishers table: Publisher (with organization and an EV badge where applicable), Thumbprint, Issuer, Expires, Here (devices in this company), Verdict and Set.
  4. Set publisher verdict dialog: Verdict and Note (kept with the decision).

How to use Elevation Publishers

How to trust a publisher

  1. Search for the publisher.
  2. Check the thumbprint against the vendor's own published value.
  3. Select Set, choose Trusted: we know this vendor, and add a Note such as "verified against the vendor's published thumbprint".
  4. Select Save.

How to block a publisher

  1. Select Set on the publisher's row.
  2. Choose Blocked: never elevate anything it signs and add a note.
  3. Select Save.

How to flag a publisher for attention

  1. Select Set and choose Watch: show it, but flag it.
  2. Select Save.

How to find publishers nobody has reviewed

  1. Select Unreviewed in the verdict filter.
  2. Sort or search, and work through the list.

Tips

  • A name is not an identity. Two certificates can carry the same company name; the thumbprint is what identifies the certificate.
  • An EV badge means an extended-validation certificate, which requires stronger identity checks by the issuer.
  • When your verdict differs from Lavawall's, the Verdict column shows both, for example "Trusted (platform: watch)".
  • A verdict here does not create an allow rule. To auto-approve a publisher's programs, create a publisher rule on the Rules page or from Audit Review.

Troubleshooting

  • "This publisher is blocked platform-wide. A company verdict will not override that.": Lavawall has blocked this certificate for everyone. Your verdict is recorded but cannot unblock it.
  • "No publishers match.": Clear the filter and search.
  • "The publisher catalogue could not be read." or "Could not load the catalogue.": Try again later.
  • "That verdict could not be saved.": You may not have permission to set verdicts, or the request was refused.

Still need help?

Search the support centre, or contact our support team and tell us which page you were on.

Names, companies, devices and figures in the pictures are examples. Other product and company names are trademarks of their respective owners.