Do a find for known_hosts under your ossec directory. That information
should be kept somewhere.
Looking over the directions for agentless monitoring it doesn't look
like you need to set that up manually, so I'm guessing it's handled
automagically. Deleting the file (OR the entry if you have multiple
agentless entries) should do the trick.

On Wed, Mar 17, 2010 at 4:04 AM, Nino Ibrahim <[email protected]> wrote:
> @oscar : i have remove host from .passlist but nothing change. On
> ossec.log it still OSSEC-
> agentless:INFO:ssh_integrity_check_linux:[email protected] RSA
> host key for '[email protected] has change. Unable to access.
> @dan : i can't find any information from /var/ossec/.ssh/known_hosts
> (No such file or directory)
>
> Nino
>

Reply via email to