Re: [Prelude Hybrid IDS] #299: TLS error with OSSEC
"Prelude Hybrid IDS" <[email protected]>
| Newsgroups | gmane.comp.security.ids.prelude.devel |
|---|---|
| Message-ID | <[email protected]> |
#299: TLS error with OSSEC
-----------------------------+----------------------------------------------
Reporter: atdt911 | Owner:
Type: defect | Status: new
Priority: normal | Milestone:
Component: prelude-manager | Version: 0.9
Severity: normal | Resolution:
Keywords: |
-----------------------------+----------------------------------------------
Comment(by yoann):
Thanks for the feedback! I'm suspecting a potential conflict problem
between GnuTLS (which depend on libz), and OSSEC which seems to make use
of it to.
One more things you can do to debug the problem, is to start both OSSEC
and Prelude-Manager in the foreground with the following environment
variable set:
{{{
LIBPRELUDE_TLS_DEBUG=10 prelude-manager >& /tmp/prelude-manager.debug
}}}
{{{
LIBPRELUDE_TLS_DEBUG=10 ossec >& /tmp/ossec.debug
}}}
Then provide us with both generated file (I'd advise to regenerate all
your sensor profile once you'll be doing that, since the debug log might
contain sensitive certificate information - or you can send me the log by
mail privately).
Additionally, is the Prelude-Manager side GnuTLS version 2.0.4 too?
--
Ticket URL: <https://trac.prelude-ids.org/ticket/299#comment:13>
Prelude Hybrid IDS <http://www.prelude-ids.org>
The Prelude Hybrid Intrusion Detection System suite
_______________________________________________
Prelude-devel site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-devel