Re: [ossec-list] Re: OSSEC - sudo

2016-10-04 Thread Kumar G
Thank you Victor/Dan. We tried these suggestion and implemented them on the systems. Looks good now with out list On 30 September 2016 at 17:21, Victor Fernandez wrote: > Hi Kumar, > > The ossec group is intended to access shared files and write only onto > logs and queues, but not on settings a

[ossec-list] Re: OSSEC - sudo

2016-09-30 Thread Victor Fernandez
Hi Kumar, The ossec group is intended to access shared files and write only onto logs and queues, but not on settings and rules files. Nevertheless, if you need to write those files, it's more secure to create a new user and add it to the ossec group and give it the needed permissions that run

[ossec-list] Re: OSSEC - sudo

2016-09-27 Thread Kumar G
Hi Dan, The main concern was we have to get the sudo command in place for maintaining ossec. With our setup the sudo commands started growing and increasing with any additional customizations. We are reluctant to change the permissions for files / directory, however checking if we are able to do t