snort / prelude-manager certificate trust

Robert Vineyard <[email protected]> Fri, 20 Nov 2009 14:17:49 -0500
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
I ended up having to rebuild part of my snort/prelude setup, and now I'm 
having trouble getting snort to register itself with prelude-manager. Snort 
and prelude-manager are running on different machines, and I've run the 
commands recommended by snort and prelude-admin to setup the trust 
relationship. This time I double-checked the profile ownership and 
permissions and they match those of my snort process.

When running prelude-manager with the --debug option, I see the following 
errors whenever my snort daemon tries to connect:

20 Nov 13:57:12 (process:21688) WARNING: [xxx.xxx.xxx.148:58700]: error 
verifying certificate: The peer did not send any certificate..
20 Nov 13:57:12 (process:21688) INFO: [xxx.xxx.xxx.148:58700]: closing 
connection.

On the other machine, I get this message from snort:

20 Nov 13:58:43 (process:909) INFO: Connecting to xxx.xxx.xxx.149:4690 
prelude Manager server.
ERROR: prelude-client: Unable to initialize prelude client: TLS server 
certificate is NOT trusted.

In order to register this sensor, please run:
prelude-admin register snort "idmef:w" xxx.xxx.xxx.149 --uid 1001 --gid 1001

Profile 'snort' does not exist. In order to create it, please run:
prelude-admin register "snort" "idmef:w" <manager address> --uid 1001 --gid 
1001.
Fatal Error, Quitting..

I've run the prescribed commands with no success. How should I go about 
troubleshooting this problem?

Thanks!

-- 
[ Robert Vineyard | RHCE, Security+ ]    [ [email protected]  ]
[ Information Security Engineer III ]    [ 404.385.6900 | FAX 404.894.4690 ]
[Finding a needle in a haystack isn't hard when every straw is computerized]
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user