Re: Tripwire

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wednesday 15 January 2003 07:30 pm, Tom Diehl wrote:
> On Wed, 15 Jan 2003, James Francis wrote:
> > Go to your /var/lib/tripwire/report directory.  Do a ls -lrt.  The
> > last file displayed is the latest tripwire report.  Do a tripwire
> > --update --twrfile <filename> where filename is the file from the
> > listing.  After a few seconds, the exceptions will be brought up in
> > vim, where you can look through them or edit them.  Do a :x when you
> > are satisfied and you are done. Pretty easy.
>
> But edit what?? I get a list like the following:
> 1.   File system error.
>      Filename: /usr/sbin/fixrmtab
>      No such file or directory
> 2.   File system error.
>      Filename: /sbin/accton
>      No such file or directory
> ...
> ...
>
> I do not understand what to do?? I have looked at the man pages and I
> am still confused.
>
> Please explain further.

The above method will update the database for changed files (violations) 
only. To the best of my knowledge, it is not possible to deal with the 
file system errors using this method. Files which simply don't exist must 
be edited manually in the policy file. Once you have a correct policy 
file, the method above is fine for approving file system modifications in 
the future.
When I get a report following a package upgrade (for example), I can 
review the changes, and then just run:
tripwire --update -a -r /path/to/twreportname
and enter the site pass phrase. Done.

However, if I remove a package....
The file system errors occur until I fix the policy file and update the 
database.

I'd be thrilled if someone proves me wrong... ;)

- -- 
- -Michael

pgp key:  http://www.tuxfan.homeip.net:8080/gpgkey.txt
Red Hat Linux 7.{2,3}|8.0 in 8M of RAM: http://www.rule-project.org/
- --
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.0.7 (GNU/Linux)

iD8DBQE+Jg4+n/07WoAb/SsRAlrNAKCS7YiHyM2VQjHx56HMf79EPLUwHgCfQeRs
Ao/nVQ33DL7w8z8xuo6rY1Y=
=QIrs
-----END PGP SIGNATURE-----



-- 
Psyche-list mailing list
Psyche-list@redhat.com
https://listman.redhat.com/mailman/listinfo/psyche-list

[Index of Archives]     [Fedora General Discussion]     [Red Hat General Discussion]     [Centos]     [Kernel]     [Red Hat Install]     [Red Hat Watch]     [Red Hat Development]     [Red Hat 9]     [Gimp]     [Yosemite News]

  Powered by Linux