snort / prelude-manager certificate trust
Robert Vineyard <[email protected]> Fri, 20 Nov 2009 14:17:49 -0500
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <[email protected]> |
I ended up having to rebuild part of my snort/prelude setup, and now I'm having trouble getting snort to register itself with prelude-manager. Snort and prelude-manager are running on different machines, and I've run the commands recommended by snort and prelude-admin to setup the trust relationship. This time I double-checked the profile ownership and permissions and they match those of my snort process. When running prelude-manager with the --debug option, I see the following errors whenever my snort daemon tries to connect: 20 Nov 13:57:12 (process:21688) WARNING: [xxx.xxx.xxx.148:58700]: error verifying certificate: The peer did not send any certificate.. 20 Nov 13:57:12 (process:21688) INFO: [xxx.xxx.xxx.148:58700]: closing connection. On the other machine, I get this message from snort: 20 Nov 13:58:43 (process:909) INFO: Connecting to xxx.xxx.xxx.149:4690 prelude Manager server. ERROR: prelude-client: Unable to initialize prelude client: TLS server certificate is NOT trusted. In order to register this sensor, please run: prelude-admin register snort "idmef:w" xxx.xxx.xxx.149 --uid 1001 --gid 1001 Profile 'snort' does not exist. In order to create it, please run: prelude-admin register "snort" "idmef:w" <manager address> --uid 1001 --gid 1001. Fatal Error, Quitting.. I've run the prescribed commands with no success. How should I go about troubleshooting this problem? Thanks! -- [ Robert Vineyard | RHCE, Security+ ] [ [email protected] ] [ Information Security Engineer III ] [ 404.385.6900 | FAX 404.894.4690 ] [Finding a needle in a haystack isn't hard when every straw is computerized] _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-ids.org/mailman/listinfo/prelude-user