Nah... I never figured it out. I ended up just going through and re-registering all the clients (what a pain). I think the best safeguard is to probably setup a cronjob that backs up the client.keys file on a consistent basis. That way if anything ever gets blown up on the server side, you can always roll back to the last known good client.keys file.
I really wish there was a way to retrieve the keys for each client though (i.e. via agent_control) On Mon, Nov 8, 2010 at 8:25 AM, Kacper Wysocki <[email protected]> wrote: > On Tue, Nov 2, 2010 at 11:48 PM, jplee3 <[email protected]> wrote: > > Hey guys, I need some help with this. I was playing around with the > > batch manager and ended up removing all my clients. Seems there's a > > bug in the script if the ID field doesn't include a "0" (if the ID is > > under "100"). In any case, I wiped out the list of clients and keys. > > Is there any way to "restore" things? > > > > Or is there a bulk way to grab all the clients and keys and add them > > back in on the server? I figured out how to populate everything but > > the keys are all different now. So if I restart the OSSEC server, all > > clients will get disconnected. > > > > Anybody have any ideas? Essentially, I would need to compile a list of > > all the current client keys and import them (unless I can somehow > > replace client.keys). So stupid, I should have backed up my > > client.keys file before messing around with this. > > Did you figure this one out? I'm guessing you might have been able to > grab the client keys off your clients and put them together into a new > client keys file and drop them into the server again before > restarting; haven't had to try this tho. I guess it's touch and go > > > -- > http://kacper.doesntexist.org > http://windows.dontexist.com > Employ no technique to gain supreme enlightment. > - Mar pa Chos kyi blos gros >
