Agent Authentication Key

59 views
Skip to first unread message

Thaynara Soares

unread,
Sep 19, 2024, 5:44:10 PM9/19/24
to Wazuh | Mailing List
In the nano file /var/ossec/etc/client. Some numbers appear in the agent's Authentication Key, others appear, do they need to have the same numbers?

Pedro Nicolás Gomez

unread,
Sep 19, 2024, 6:02:33 PM9/19/24
to Wazuh | Mailing List
Hi  Thaynara Soares,

The client.keys file stores the data used to authenticate secure agents. This file contains one line per each agent entry. In the case of agents, only one line is allowed, and this line must match exactly one entry in the client.keys file at manager, otherwise the agent will be rejected.

Format: 
<ID> <Name> <Address> <Password>

Examples:

001 server1 any bb8a28997c6c3964eacb3d32308072f6661f567a41105b2b0b09f1a82331b937 
002 dbserver 10.0.1.2 363a99a6e9c9a8b6bb766d676453538e0cb20162f84b36472d99cfbef4928440


For the agent to communicate with the manager the agent's client.keys must match the corresponding entry in the manager's client.keys.


I hope it helps.
Best regards,
Pedro Nicolas

Thaynara Soares

unread,
Sep 20, 2024, 1:24:37 PM9/20/24
to Wazuh | Mailing List
Screenshot_16.png

For example, the Authentication key has numbers and letters, but in my file it is different. Do they have to be different or the same numbers?


Pedro Nicolás Gomez

unread,
Sep 23, 2024, 8:16:19 PM9/23/24
to Wazuh | Mailing List
Yes, they must be different. When stored in the client.keys file it is stored in “raw format”, while the one displayed in the UI is a hash of the stored key.

Thaynara Soares

unread,
Sep 24, 2024, 1:50:20 PM9/24/24
to Wazuh | Mailing List
I understand, thank you very much for the information
Reply all
Reply to author
Forward
0 new messages