On Wed, 27 Oct 2010 14:25:25 -0400
"dan (ddp)" <[email protected]> wrote:

> What's the worst that will happen if you try it?

I can give it a try :) I'm just afraid that it may break OSSEC system.
 
> You're using an ancient version, in a strange configuration. I'm not
> sure how many people will be able to test something like this and
> get back to you. Give it a shot. If it breaks, you should know how
> to fix it. ;)

When I use the latest version of OSSEC (2.5.1) I have the same problem. My 
system is too old: it's Debian Lenny and it is running on Amazon platform 
(http://aws.amazon.com/). That's why I can't upgrade my FUSE module :(

Thank you for your helps.

> 
> On Tue, Oct 26, 2010 at 8:41 PM, Anh K. Huynh <[email protected]>
> wrote:
> > Hi,
> >
> > I am using ossec-1.6.5 on a distributed file system which doesn't
> > support group (actually, this is due to an old version of FUSE
> > module.) Therefore the file "/queue/alerts/execq" is accessible
> > by its group:
> >
> > /======================================================
> > cd /opt/ossec.agent.osxcad0/queue/alerts  && ls -ltr
> > total 0
> > srw-rw---- 1 root ossec 0 2010-10-25 02:57 execq=
> > \======================================================
> >
> > On agents, there's only "ossec" user. Can I update the owner of
> > that file, by "chown ossec:ossec execq"? If "yes", can the same
> > method be applied on Ossec's master?
> >
> > Thank your for your helps,
> >
> > --
> > Anh Ky Huynh
> >


-- 
Anh Ky Huynh

Reply via email to