File hal-policy.conf of Package hal
# HAL policy configuration
org.freedesktop.hal.killswitch.bluetooth auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.killswitch.wlan auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.killswitch.wwan auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.lock auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.storage.mount-fixed auth_admin_keep_always
org.freedesktop.hal.storage.mount-removable auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.storage.unmountothers auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.storage.eject auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.storage.crypto-setup-fixed auth_admin_keep_always
org.freedesktop.hal.storage.crypto-setup-removable auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.wol.enabled auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.wol.enable auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.wol.supported auth_admin_keep_always:auth_admin_keep_always:yes
# shutdown/reboot should be consistent with consolekit
org.freedesktop.hal.power-management.shutdown auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.shutdown-multiple-sessions auth_admin:auth_admin:yes
org.freedesktop.hal.power-management.reboot auth_admin:auth_admin:yes
org.freedesktop.hal.power-management.reboot-multiple-sessions auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.set-powersave auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.suspend auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.hibernate auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.standby auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.cpufreq auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.lcd-panel auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.light-sensor auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.power-management.keyboard-backlight auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.dockstation.undock auth_admin_keep_always:auth_admin_keep_always:yes
org.freedesktop.hal.leds.brightness auth_admin_keep_always:auth_admin_keep_always:yes
#
# device access
#
# we allow device access for both active and inactive sessions.
# Revoking device ACLs for inactive sessions would have no effect on
# already open file descriptors anyways. With a revoke system call
# it would be possible but would also mean that e.g. a sound playing
# appliction would have to be killed or would forcefully stop
# playing sound which is not what we want.
#
org.freedesktop.hal.device-access.sound auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.video4linux auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.cdrom auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.dvb auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.camera auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.scanner auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.audio-player auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.ieee1394-iidc auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.ieee1394-avc auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.pda auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.floppy auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.modem auth_admin_keep_always
org.freedesktop.hal.device-access.joystick auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.mouse auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.video auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.fingerprint-reader auth_admin_keep_always:yes:yes
org.freedesktop.hal.device-access.obex auth_admin_keep_always
org.freedesktop.hal.device-access.ppdev auth_admin_keep_always
org.freedesktop.hal.device-access.removable-block auth_admin_keep_always