Hello,

Currently I work with a group (cant give the name) that is trying to deploy 
OSSEC across a large environment (about 3 data centers and over 1000+ 
Solaris Zones). The idea behind it is we don't really have a need for the 
agents but we would like to implement OSSEC's AgentLess function to help 
improve the security of are infrastructure. We currently use a PKI system 
for authentication and also have a pretty big OpenLDAP / NFS environment. 

The problem we were running in to was this, we had a OSSEC server setup 
with analogi in are test lab and we were able to get a LDAP account / PKI 
authentication ID for a user called "OSSECAGENT" setup, however when we 
would try to use the ssh_generic_diff it would timeout on connection. The 
idea was we would have the SSH account instead of being root or ossec be 
the OSSECAGENT and just have the ossec chroot'ed user run on the server. 

so for example

OSSEC_SERVER  ----------> (Using SSH - and user ID OSSECAGENT) ---------- > 
TESTBOX1

after debugging and working with it we identified the issue to be the OSSEC 
SSH key is not currently on the TESTBOX1 machine, there for when we try to 
SSH it will not identity the user connecting and eventually time out. 

When we run:    /opt/ossec/agentless/ssh_generic_diff ossecagent@testbox1 
echo "hello"   - (from root) it works fine (connects - runs the command - 
Disconnects - all with out a issue). However when we restart the OSSEC 
service via the OSSEC-CONTROL restart, it ends up timing out in the logs. 
The password is being prompted due to the issue we talked about above.  

What we would like it to do is this, we would love for the OSSEC user to be 
tied in to LDAP with a home directory in "/home/ossec" instead of the 
chroot'ed "/opt/ossec" (cant use /var in are environment). This way we can 
create a SSL key for the user and have it utilize the PKI system we already 
have in place. 

We originally just tried following the setups in: 
http://ossec-docs.readthedocs.org/en/latest/manual/agent/agentless-monitoring.html
 
and were unable to switch users in to the OSSEC account. 

The entry in the /etc/passwd file was: 
"ossec:x:######:####::/opt/ossec:/bin/false"    -   we changed it to 
"ossec:x:######:####::/opt/ossec:/bin/bash" and were able to "su - ossec" 
(how we have to change users) and get a bash shell, but since the user 
would not be tied in to a NFS based home directory we would have to put the 
SSL cert on every single box and we don't want to have to do that. 

We created a snapshot of the working OSSEC server and through tinkering got 
a OSSEC user created in LDAP and on the box via a NIS group and deleted the 
original user from the /etc/passwd file. Created a SSL key, and mapped the 
home directory on all the boxes we currently have. However due to the 
chroot'ed process we are noticing this will not work because ossec wont be 
able to start. The biggest issue was OSSEC connecting to the socket : 
"/opt/ossec/queue/ossec/queue" - this is the log file entries for it: 

ossec-syscheckd(1210): ERROR: Queue '/opt/ossec/queue/ossec/queue' not 
accessible: 'Destination address required'.

We were wanting to know if anybody had run in to something like this and 
had a easy method of getting this setup and configured. Any help would be 
appreciated. we would like to avoid having to use the chroot'ed ossec user 
if possible because we an create a SSH Key but getting the key on several 
thousand servers on multiple networks will be painful. 

Let me know of any questions 
thanks again

-- 

--- 
You received this message because you are subscribed to the Google Groups 
"ossec-list" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Reply via email to