Re: [Freeipa-users] FreeIPA, rkhunter unknown rootkit

2012-08-17 Thread Anthony Messina
On Monday, July 23, 2012 04:08:25 AM Anthony Messina wrote: I have installed freeipa-server-2.2.0-1.fc17.x86_64 and it's running well. I have also installed rkhunter-1.4.0-1.fc17.noarch on the IPA server and each morning I receive the following report from rkhunter. I imagine/hope that

Re: [Freeipa-users] FreeIPA, rkhunter unknown rootkit

2012-08-17 Thread Stephen Gallagher
On Fri, 2012-08-17 at 13:42 -0500, Anthony Messina wrote: On Monday, July 23, 2012 04:08:25 AM Anthony Messina wrote: I have installed freeipa-server-2.2.0-1.fc17.x86_64 and it's running well. I have also installed rkhunter-1.4.0-1.fc17.noarch on the IPA server and each morning I receive

Re: [Freeipa-users] FreeIPA, rkhunter unknown rootkit

2012-08-17 Thread Mark St. Laurent
- From: Anthony Messina amess...@messinet.com To: freeipa-users@redhat.com Sent: Friday, August 17, 2012 2:42:07 PM Subject: Re: [Freeipa-users] FreeIPA, rkhunter unknown rootkit On Monday, July 23, 2012 04:08:25 AM Anthony Messina wrote: I have installed freeipa-server-2.2.0-1.fc17

Re: [Freeipa-users] FreeIPA, rkhunter unknown rootkit

2012-08-17 Thread Anthony Messina
On Friday, August 17, 2012 02:59:31 PM Mark St. Laurent wrote: Hi Anthony, I would start off by seeing what files the PID is opening to make sure it is truly being good: #lsof -p 1513 To avoid these warnings, you can reconfigure rkhunter to ignore these false positives by editing the

Re: [Freeipa-users] FreeIPA, rkhunter unknown rootkit

2012-08-17 Thread Anthony Messina
On Friday, August 17, 2012 03:25:45 PM Stephen Gallagher wrote: On Fri, 2012-08-17 at 13:42 -0500, Anthony Messina wrote: On Monday, July 23, 2012 04:08:25 AM Anthony Messina wrote: I have installed freeipa-server-2.2.0-1.fc17.x86_64 and it's running well. I have also installed

[Freeipa-users] FreeIPA, rkhunter unknown rootkit

2012-07-23 Thread Anthony Messina
I have installed freeipa-server-2.2.0-1.fc17.x86_64 and it's running well. I have also installed rkhunter-1.4.0-1.fc17.noarch on the IPA server and each morning I receive the following report from rkhunter. I imagine/hope that these are not actual rootkits and was wondering if anyone knew of a