Chris,

Agent / Client = 1 client.keys file with a single entry in it.
C:\Program Files (x86)\ossec-agent\client.keys = 1 entry

Server / Manager = 1 client.keys files with an entry for every agent that
is registered.
/var/ossec/etc/client.keys

If you are tying to copy the client.keys file from the server to every
agent, it will not work (only reads the first line).

If you need some scripting automation for installing/configuring OSSEC on
Windows and Linux, and can run powershell from your Windows Landesk
instance, I can help. Just need to come up with what "success" would look
like from requirements perspective and the scripting part is easy.

Jared



On Thu, Sep 19, 2013 at 10:19 AM, James M. Pulver <[email protected]>wrote:

>  Yes, each client has a unique client.keys.****
>
> ** **
>
> --****
>
> James Pulver****
>
> CLASSE Computer Group****
>
> Cornell University****
>
> ** **
>
> *From:* [email protected] [mailto:[email protected]] *On
> Behalf Of *Chris Lauritzen
> *Sent:* Thursday, September 19, 2013 9:46 AM
>
> *To:* [email protected]
> *Subject:* Re: [ossec-list] Client.keys****
>
> ** **
>
> James let get this straight, if I have 3500 pc's to push this out to I
> need 3500 client.keys files?
>
>
> On Wednesday, September 18, 2013 5:13:28 PM UTC-5, Michael Starks wrote:**
> **
>
> On 09/18/2013 04:08 PM, Chris Lauritzen wrote:
> > Yes the Key have been made. There is a new twist to this now. The
> > install is reading the client.keys but is only reading in the first key
> > listed. Every install is pulling only the first key. If I manually add
> > the key it works fine. When creating the key I see that the name is
> > optional but is it possible that it's looking for the device name and
> > when not finding it defaulting to the first entry?
>
> There should only be one key in the agent's client.keys file--the key
> for that agent. ****
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/groups/opt_out.****
>
> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to [email protected].
> For more options, visit https://groups.google.com/groups/opt_out.
>



-- 
Thank you,

Jared R. Greene

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/groups/opt_out.

Reply via email to