Skip to content

Watermark

The Accops Watermark Module enables administrators to display a low-contrast watermark over user sessions delivered through desktop and application virtualization environments. The watermark can contain images, text, or both, and is designed to discourage unauthorized sharing, screenshots, and misuse of sensitive organizational data.

The module can be deployed either:

  • On Virtual Desktop Infrastructure (VDI) servers to protect virtual desktops and applications.

  • On endpoint devices through the HySecure Client to secure access to business applications

Benefits of Using Watermarks

The Watermark Module is the foundation for the Accops Data Leakage Prevention (DLP) feature. This module empowers IT administrators to protect the organization’s data confidentiality.

A screen watermark deters unauthorized use of company data.

The standalone Watermark Module is readily accessible and can be effortlessly installed on any desktop or application virtualization system using Accops products.

Administrators can customize watermarks using images, logos, signatures, custom text, and user-specific information.

Features

Accops Watermark Configuration Manager provides the following features:

  • Image preview

  • Image resolution and quality control

  • Support for

  • PNG, JPG, and JPEG watermark images

  • Custom text-based watermarks

  • Watermark scaling

  • Opacity adjustment

  • Font and color customization

  • Watermark visibility controls

  • Password protection

  • Reset to get to the default settings

Supported Platforms

  • Windows 7-SP1 and above

  • Windows Server 2008 R2 SP1 or above

Prerequisites

Before installing the Watermark Module, ensure the following requirements are met:

  • The system on which the Accops watermark module is to be installed must have Microsoft .NET Framework 4.5 or later.

  • Image type supported for logo: PNG (recommended), JPG, and JPEG.

  • Accops Watermark modules download link: Watermark Latest Releases

  • A supported version of the Accops HySecure Client is available (recommended version: v5.2.3.8543)

Important

  • Make sure to use the recommended HySecure Client version. Some newer client versions may not include support for the Watermark Module. Contact Accops Support if you are unsure which version to use.

Accops Watermark Manager

The Watermark Manager is used to create and manage watermark configurations.

Installation

  1. Download and install the Watermark Manager using the links provided above.

  2. Install any available patches to ensure you have the latest fixes.

  3. The default installation directory is: C:\\Program Files (x86)\\Accops\\Watermark.

  4. Accops Watermark Manager must be run with Administrator privileges.

  5. Navigate to the installation directory.

  6. Right-click AccopsWatermarkManager.exe and select Run as administrator.

Accops Watermark Manager contains two sections:

  • Image and Text.

  • Watermark Settings.

Image and Text

This section allows administrators to configure watermark content and appearance.

  1. Show image: Enable this option to use an image as the watermark. The supported image formats are PNG (recommended), JPG, and JPEG. PNG format is recommended because JPG and JPEG formats may exhibit known rendering issues.

  2. Number of Squares: Configure to specify the number of watermark instances displayed across the screen.

  3. Full Screen: The administrator can apply the watermark image to the full screen by selecting this option.

  4. Maintain Aspect Ratio: If this option is enabled, the image’s Height and Width will be maintained, or the administrator can manually customize the aspect ratio.

    • If Full Screen is disabled, administrators can manually specify the option to maintain the aspect ratio, and specify the Height and Width.
  5. Alignment: Controls the watermark position on the screen. The watermark's alignment can be chosen from here. Following are the available positions:

    • Top Left
    • Top Center
    • Top Right
    • Middle Left
    • Middle Center
    • Middle Right
    • Bottom Left
    • Bottom Center
    • Bottom Right
  6. Additional information can also be displayed along with the logo in the watermark, such as:

    • User Name

    • Date

    • Hostname

    • IP address

  7. Text Message: Administrators can configure the text to display in the watermark as they choose. The position of this text within the logo image can be configured. The text’s Font style, Font size, and Font color, as well as text placement relative to the image, can also be configured here.

  8. At the bottom of Watermark Manager, the following actions are available:

    1. Apply: Click to apply the configurations. It can be selected here or on the Watermark Settings screen.

    2. Start: Click to commence the watermark service with all configured options, on the current system.

    3. Stop: Click to stop the watermark service if it is already running.

    4. Change Password: Click to change the Watermark Manager’s password.

    5. Reset to Default: Click to restore default configuration settings.

    6. Close: Click to dismiss the Watermark Manager after making the changes.

Watermark Settings

The administrator can configure when and how the watermark is displayed.

The following are the options:

  1. Angle: This option lets you adjust the watermark’s rotation angle on the screen. By default, the angle is 0.

  2. Opacity: Watermark transparency can be set from this option.

  3. Auto Start Mode: Determines whether the watermark starts automatically when users log in. Available options:

    1. None: Watermark does not start automatically.

    2. All users: Watermark settings will apply to all users.

    3. Current user: Watermark settings will only be applied to the users the administrator has logged in and configured.

  4. Session Type: With this option, the watermark will be applied to all session types or only to selected sessions when the user logs in on the system where the watermark module is installed and configured.

    1. All: Watermark will be applied to console and remote desktop system access.
    2. Console: Watermark will be applied to console access only.

    3. Remote Desktop: Watermark will be applied to remote desktop access only.

  5. Remote Launch Type: The administrator can control which application launch modes receive the watermark.

    1. All: Watermark will be applied when the session is in both Desktop/Shell mode and Remote App mode.

    2. Desktop: Watermark will be applied only when the session is taken with Desktop/Shell mode.

    3. Remote App: Watermark will be applied only when the session is in Remote App mode.

  6. Once all the configurations are done, the administrator can choose either one of the following options:

    1. Apply: Click to apply the configurations. Administrators can select it from this screen or the Watermark Settings screen.

    2. Start: Click to start the watermark service on the current system. Watermark will be displayed with the configured settings on the current system.

    3. Stop: Click to stop the watermark if it is already running.

    4. Change Password: Click to change the Watermark Manager’s password.

    5. Reset to Default: Click to reset all settings to default.

    6. Close: Click to dismiss the Watermark Manager after making the changes.

Config file

The Watermark Manager stores its configuration in a file located in the installation directory.

  • Changes made in the Watermark Manager GUI will be saved to the config file.

  • All settings are encrypted.

  • The configuration file is used by Watermark.exe to render the watermark.

  • If the file is deleted, a new configuration file containing default settings is automatically created.

Password Protection

Administrative actions require password authentication.

The default password is:

Watermark12!@

Administrators should change the default password immediately after installation.

Password protection prevents unauthorized users from:

  • Modifying watermark settings

  • Starting the watermark service

  • Stopping the watermark service

Deployment Scenarios

The Watermark Module can be deployed in two ways:

  1. Inside the VDI servers: Making any desktop or virtual application sessions safe.

  2. Using HySecure Client: On the end user’s system, and securing the usage of any applications via HySecure Client. This can include virtual desktops or applications.

Using Watermark on VDI Server

  1. Install Watermark Manager on the VDI server (Preferably on the source VM or the Gold Image).

  2. Configure Image Text and Watermark Settings as per requirements.

    • Change the password and do not keep the default password.
  3. Apply and start the watermark.

  4. Deploy virtual machines using the Gold Master prepared above, or follow the steps on all pre-deployed virtual machines.

  5. Log in with the end user and connect to assigned virtual desktops or virtual applications. A watermark should appear at the top of the session, thereby deterring any attempts at data theft.

Note

In step 4, install and configure the watermark on all session servers used in virtual desktops. The Gold Image can be prepared with all configurations for dynamically provisioned servers.

Using Watermark on Endpoints via HySecure Client

The Watermark Module can also be deployed on endpoint devices when users access business applications through the HySecure Client.

To use the Watermark Module with the HySecure Client, follow the steps below:

  1. Create Configuration File:

    1. Install Watermark Configuration Manager on a Windows machine to designate that server as a configuration server.

    2. Keep the appropriate watermark image file in .png (recommended) format at %appdata%\AccopsWatermark\logo.png (Give logo name as logo.png).

    3. Go to C:\Program Files (x86)\Accops\Watermark location and open the Watermark Service Manager as administrator (WatermarkManager.exe).

    4. Select Upload Image and browse to the location %appdata%\AccopsWatermark\logo.png to fetch the image.

      Note

      The application may display an error as the selected image not found; clicking Ok can safely ignore it.

    5. Apply the other necessary settings. Configure the Image, Text, and Watermark Settings as per requirements.

    6. Select the Apply button and then the Start button.

    7. Enter the default password used to configure the watermark (The default password is provided in this section).

      Note

      If the logo not found error is displayed, open Command Prompt and run the C:\Program Files (x86)\Accops\Watermark\EDCWatermark.exe 1 command.

    8. Copy the text/configuration from %appdata%\AccopsWatermark\Watermarksettings.conf.

  2. Upload Configurations on HySecure Server:

    1. Navigate to /home/fes/public on the gateway through PuTTY or WinSCP.

    2. Create a watermark.conf file at the location mentioned below, and paste the encrypted data copied from the WatermarkSettings.conf in the following format:

      • <WATERMARK_CONF> DATA_COPIED_FROM_WATERMARKSETTINGS.CONF </WATERMARK_CONF>

      Important

      The tags <WATERMARK_CONF> and </WATERMARK_CONF>d must be added exactly as shown above and must be written in uppercase letters.

      Note

      Spaces or any extra characters outside the configuration data and tags may cause the feature to fail.

    3. Copy the logo file with the name - watermark_logo.png (Keep the exact file name).

    4. Once both the logo and conf file are copied, change permissions and ownership of the file using the commands below:

      • Change permission: Run the command chmod 755 watermark*

      • Change ownership: Run the command: chown apache:fes watermark*

      • To validate the changes: Run the command: ls -lrth | grep -i watermark

    5. The .conf and watermark.conf files must be whitelisted on the gateway before access. This needs to be done while creating the file for the first time and not on configuration changes:

      1. Go to /etc/httpd/conf.

      2. Open httpd.conf file.

      3. Search for BrowserMatch and make the following changes:

        1. conf to be added in section <FilesMatch ".(js|csv|txt|conf)">

        2. watermark.conf to be added in the section as shown below:

      4. Save the conf file and restart the httpd service with the command systemctl restart httpd.

  3. Enable Watermark Feature on HySecure:

    1. Access the HySecure Management Console and navigate to Policies > Client Profiles.

    2. Edit the Default configuration settings and search for Watermark.

    3. Users can also specify the text to be displayed over the watermark in the gateway.

      Note

      If the text is specified in both the gateway and the configuration server, the gateway text will be overridden by the client text.

    4. Enable the settings and save the Configurations.

  4. Log in with the HySecure Client and verify the configurations.

Sample Images after Applying Watermark

Limitations and Troubleshooting

Watermark Manager Logs

In case of any issues, the administrator can check the log files.

  • The log files are located in the C:\\Users\\Public\\AccopsWatermark folder. This file contains logs of user activity related to the Watermark Module.

Error: Logo not found

An "error message: logo not found" is displayed on the screen when starting the watermark, even after the watermark setting is successfully applied.

The following process should be executed to run the watermark in the current user context:

  1. Open cmd with admin rights.

  2. Execute the below command to run the Watermark.exe in user mode:

    C:\Program Files (x86)\Accops\Watermark\EDCWatermark.exe 1

Error: Image not found

While applying configurations, the Watermark Manager usually displays the error “Selected image not found.”

  1. Make sure the logo image is correctly placed at the following location: %appdata%\AccopsWatermark\logo.png

  2. The file name is logo.png.

  3. The recommended format is .png.

Note

Even after correct configurations are in place, if the error is displayed, it can be safely ignored.

Verify Downloaded Files on the Client

After applying the configuration, the administrator can cross-verify the conf file and logo files on the Client's machine.

  1. Open the %appdata%\AccopsWatermark folder on the Client's machine after registering the gateway on the Client.

  2. Verify that:

    • The configuration file has been downloaded successfully.
    • The watermark image has been downloaded successfully.
  3. Compare the downloaded files with those uploaded to the gateway using PuTTY or WinSCP.