argh. the tribulations continue...
I'm still trying to deploy prelude with auditd on SLES10.2 s390x (in
guests under z/VM -- if that matters).
Thanks to Yoann's suggestion, i got past the ssh key generation problem
(using /dev/urandom works great!), but now there are errors in
registering with the prelude-manager:
:/root> #prelude-admin register auditd "idmef:w" 127.0.0.1 --uid 0
--gid 0
You now need to start "prelude-admin" registration-server on 127.0.0.1:
example: "prelude-admin registration-server prelude-manager"
Enter the one-shot password provided on 127.0.0.1:
Confirm the one-shot password provided on 127.0.0.1:
<ctrl-a n -- moved to the next gnu-screen session>
:/root> #prelude-admin registration-server prelude-manager
The "xxxxxxx" password will be requested by "prelude-admin register"
in order to connect. Please remove the quotes before using it.
Generating 1024 bits Diffie-Hellman key for anonymous authentication...
Waiting for peers install request on :::5553...
Waiting for peers install request on 0.0.0.0:5553...
<..ctrl-a n -- changing back to the previous session..>
Enter the one-shot password provided on 127.0.0.1:
Confirm the one-shot password provided on 127.0.0.1:
Connecting to registration server (127.0.0.1:5553)...
GnuTLS handshake failed: Error in the push function..
<..ctrl-a back to the prelude-manager session..>
Connection from ::ffff:127.0.0.1:49903...
GnuTLS handshake failed: A TLS packet with unexpected length was
received..
not very helpful errors.. at least not to me. So I ran an strace on the
manager side, in the hopes I can see a little clearer:
write(2, "Waiting for peers install reques"..., 48Waiting for peers
install requ
est on :::5553...
) = 48
socket(PF_INET6, SOCK_STREAM, IPPROTO_TCP) = 4
setsockopt(4, SOL_SOCKET, SO_REUSEADDR, [1], 4) = 0
bind(4, {sa_family=AF_INET6, sin6_port=htons(5553), inet_pton(AF_INET6,
"::", &s
in6_addr), sin6_flowinfo=0, sin6_scope_id=0}, 28) = 0
listen(4, 1) = 0
write(2, "Waiting for peers install reques"..., 53Waiting for peers
install requ
est on 0.0.0.0:5553...
) = 53
socket(PF_INET, SOCK_STREAM, IPPROTO_TCP) = 5
setsockopt(5, SOL_SOCKET, SO_REUSEADDR, [1], 4) = 0
bind(5, {sa_family=AF_INET, sin_port=htons(5553),
sin_addr=inet_addr("0.0.0.0")}
, 16) = -1 EADDRINUSE (Address already in use)
close(5) = 0
poll([{fd=4, events=POLLIN, revents=POLLIN}], 1, -1) = 1
accept(4, {sa_family=AF_INET6, sin6_port=htons(51354),
inet_pton(AF_INET6, "::ff
ff:127.0.0.1", &sin6_addr), sin6_flowinfo=0, sin6_scope_id=0},
[120259084288]) =
5
write(2, "\nConnection from ::ffff:127.0.0."..., 43
Connection from ::ffff:127.0.0.1:51354...
) = 43
gettimeofday({1221137921, 742482}, NULL) = 0
getrusage(RUSAGE_SELF, {ru_utime={0, 425115}, ru_stime={0, 3256}, ...})
= 0
gettimeofday({1221137921, 742580}, NULL) = 0
times({tms_utime=42, tms_stime=0, tms_cutime=0, tms_cstime=0}) =
4321136923
gettimeofday({1221137921, 742673}, NULL) = 0
getrusage(RUSAGE_SELF, {ru_utime={0, 425120}, ru_stime={0, 3268}, ...})
= 0
gettimeofday({1221137921, 742798}, NULL) = 0
times({tms_utime=42, tms_stime=0, tms_cutime=0, tms_cstime=0}) =
4321136923
recv(-7613696, 0x8004e9b0, 5, 0) = -1 EBADF (Bad file descriptor)
write(2, "GnuTLS handshake failed: A TLS p"..., 76GnuTLS handshake
failed: A TLS
packet with unexpected length was received..
) = 76
send(-7613696, "\25\3\1\0\2\2\26", 7, 0) = -1 EBADF (Bad file
descriptor)
close(5) = 0
poll(
Even though I see (Address already in use), I dont see 5553 already
in use in netstat output, nor does "ps" show any managers already
running...
on the registration side:
write(2, "\nConnecting to registration serv"..., 55
Connecting to registration server (127.0.0.1:5553)... ) = 55
connect(3, {sa_family=AF_INET, sin_port=htons(5553),
sin_addr=inet_addr("127.0.0
.1")}, 16) = 0
gettimeofday({1221141308, 453386}, NULL) = 0
gettimeofday({1221141308, 453442}, NULL) = 0
gettimeofday({1221141308, 453501}, NULL) = 0
access("/dev/random", R_OK) = 0
access("/dev/urandom", R_OK) = 0
open("/dev/urandom", O_RDONLY) = 4
select(5, [4], NULL, NULL, {3, 0}) = 1 (in [4], left {3, 0})
read(4, "\274\f\341\177S\303--d\361\372)A\2515X3\330p\237Df\211"...,
120) = 120
select(5, [4], NULL, NULL, {3, 0}) = 1 (in [4], left {3, 0})
read(4, "\316\246\305\257\177\302\315\344F \316\203\276F\207\10"...,
120) = 120
select(5, [4], NULL, NULL, {3, 0}) = 1 (in [4], left {3, 0})
read(4, "\231\250\203Gl\202\340`\230\305\267\224\262Tz\244\17\t"...,
120) = 120
select(5, [4], NULL, NULL, {3, 0}) = 1 (in [4], left {3, 0})
read(4, "\225r\2510\36\200V\332\266\261\217\341j[f\10/\303\356\324"...,
120) = 1
20
select(5, [4], NULL, NULL, {3, 0}) = 1 (in [4], left {3, 0})
read(4, "9\'\312\220\340\355\30\215B\341\376)\260%\275\26j\231\340"...,
120) = 1
20
gettimeofday({1221141308, 454521}, NULL) = 0
getrusage(RUSAGE_SELF, {ru_utime={0, 3539}, ru_stime={0, 2052}, ...}) =
0
gettimeofday({1221141308, 454647}, NULL) = 0
times({tms_utime=0, tms_stime=0, tms_cutime=0, tms_cstime=0}) =
4321475595
send(5553, "\26\3\1\0[\1\0\0W\3\1H\311#<\306\354\223\34\206\375}$9"...,
96, 0) =
-1 EBADF (Bad file descriptor)
write(2, "\nGnuTLS handshake failed: Error "..., 55
GnuTLS handshake failed: Error in the push function..
) = 55
exit_group(-1) = ?
..another "Bad file descriptor".. .well, at least they agree on
something.
I'm starting to wonder if I'm missing a file that GNUtls would like to
see, but I cant tell what it is. Am I missing something in my setup
here??
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user
lmpx.com only provides a reader for public news (NNTP) servers. It is not
affiliated with the servers or forums shown here and is not responsible for
the content of articles, which is written by their respective authors.