Describes how restricted shell access invokes the Consent Token workflow and permits a single direct interactive root shell instance on a supported platform.
The process occurs when a user restricts direct interactive shell access on a platform that supports the Consent Token infrastructure.
Summary
When a user restricts shell access, the system records the restriction state in the HWTAM Secure Object. Subsequent supported direct, interactive root shell access attempts check this state and are denied while the restriction is active.
Workflow
These stages describe the gated shell access workflow:
-
A user restricts shell access or requests access to a direct, interactive root shell.
-
The system stores the restricted-shell access state in the HWTAM Secure Object and applies the restriction to supported direct, interactive root shell access.
-
The user must complete the consent token response challenge handshake.
-
The user enters the Consent Token response. When the response succeeds, the system permits one root shell instance for that user session.
-
A user starts the unrestriction authorization flow, submits the response, and the system returns to the default non-gated root shell behavior after successful authorization.