Re: snort / prelude-manager certificate trust

ScottO <[email protected]> Fri, 20 Nov 2009 15:03:15 -0500
Newsgroups gmane.comp.security.ids.prelude.user
Message-ID <[email protected]>
On Fri, Nov 20, 2009 at 2:57 PM, Robert Vineyard <
[email protected]> wrote:

> Ok, I think I've got this figured out. This should really be more clear in
> the documentation.
>
> What I had to do was run the prelude-admin "register" command on my snort
> box referencing the "snort" profile, and then on the prelude-manager box
> the
> "registration-server" command referencing the "prelude-manager" profile. I
> would have expected the profile names to match on both sides, but
> apparently
> that's not how it works.
>
>
This link has some info on the agent registration process if you haven't
seen it:
https://dev.prelude-ids.com/wiki/prelude/InstallingAgentRegistration

At any rate, if you think about the process, you register the agent, in this
case your snort profile with the prelude manager - which has the
prelude-manager profile there.  You want all your agents registered and
communicating with a central manager or relay manager.  So the profiles are
for different distinct components, an agent and a manager - hence the
different names.

Hope that helps.

scotto
_______________________________________________
Prelude-user site list
[email protected]
http://lists.prelude-ids.org/mailman/listinfo/prelude-user