Three users what does each do? QSA for PCI is asking me to justify their accounts

140 views
Skip to first unread message

James Ruffer

unread,
Jul 10, 2014, 12:36:59 AM7/10/14
to ossec...@googlegroups.com
I am wondering why the three accounts and what does each do?
OSSEC
OSSECM
OSSECR

dan (ddp)

unread,
Jul 10, 2014, 7:47:02 AM7/10/14
to ossec...@googlegroups.com
On Thu, Jul 10, 2014 at 12:36 AM, James Ruffer <ja...@paay.co> wrote:
> I am wondering why the three accounts and what does each do?

Having multiple users is a security feature allowing OSSEC to better
limit access to information between the different OSSEC processes. I
think it's similar to why OSSEC uses multiple processes for the
various functions. This is probably something that could be added to
the documentation.

> OSSEC

I think most of the daemons run as the ossec user.

> OSSECM

ossec-maild runs as the ossecm user

> OSSECR
>

ossec-remoted runs as the ossecr user.

> --
>
> ---
> You received this message because you are subscribed to the Google Groups
> "ossec-list" group.
> To unsubscribe from this group and stop receiving emails from it, send an
> email to ossec-list+...@googlegroups.com.
> For more options, visit https://groups.google.com/d/optout.
Reply all
Reply to author
Forward
0 new messages