Yes, that is the key.
I just setup to CentOS 6.0 x86_64 systems.
I installed OSSEC on each (post 2.6 source, but I don't think anything
has really changed in the auth stuff).
One system became an OSSEC server.
The other an agent.
I setup ossec-authd, and then ran agent-auth (copy & pasted most of it
from dcid's blog post).
No errors so far.
So the problem seems to either be your systems, or the atomic RPMs.
It doesn't seem to work for me with atomic RPMs either, but I don't
get any errors. Just no connection.
I do not. See the email I sent earlier. It worked fine for me when I
compiled the source.
'any' is supposed to mean any. So any ip will match.
Do you know if the rpm spec files will be updated anytime soon?
Yes. I've notified them (via IRC) that there is an issue.
> Do you know if the rpm spec files will be updated anytime soon?
>
In the OSSEC source or Atomic's spec files? If you mean the OSSEC
ones, probably whenever someone sends in an update.
They're not something that's high on the priority list, especially
since they're in the "contrib" directory.
I am kind of looking at them though. :P
What do you mean you're on your own?
I created 2 virtual Centos 6 systems to test them.
1 system got the -server, and the other -client. This combination did not work.
The server side does not even seem to recognize the client.
list_agents -a didn't show the agent until I changed the any to an IP.
I was also getting the not allowed error.
Using manage_agents to extract the key and import it into the agent
did not solve the issue.
I then used an lxc installed debian with ossec installed via source.
The agent-auth worked just fine, the agent connected with no errors.
So the issue seems to be in the RPM's agent-auth?
Thoughts? Ideas?
I mean, it's up to us to figure it out why the RPMs don't work. I said
that because no one at Atomic has been able to assist up to this
point. The only response I got was to 'look at the the spec file' and
"I'm in the dark on this one too". Was I incorrect? Were you able to
muster some support from Atomic?
Beyond reporting it to them, I haven't really tried.