LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-08-2011, 06:02 AM   #1
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Rep: Reputation: 22
Error on CentOS Server after applying the latest updates


I just put the latest updates onto My CentOS 5.6 server. It started life as a 5.4 Server, then the upgrades took it to 5.6.

The latest updates did a Kernel Update and the server sent me two messages : -

-----BEGIN MESSAGE-----
[2011-06-08T12:37:17+0200] centos54.xxx.yyyyy.com
ALERT : [2011-06-08T12:37:17+0200] msg=<START>, program=<Samhain>, userid=<0>, path=</etc/samhainrc>, hash=<256A548F71A768CC1E054F0C1E90E8674D36A09BDF9E5D13>, path=</var/lib/samhain/samhain_file>, hash=<9366451EB106619E8AE1B4AEC305EA2B83140A789888EF43>
-----BEGIN SIGNATURE-----
20AA642365713EA58F73A1637F61DA1C26FC3E2E4ACA2233
000000 1307529480::centos54.xxx.yyyyy.com
-----END MESSAGE-----

and

-----BEGIN MESSAGE-----
[2011-06-08T12:38:00+0200] centos54.xxx.yyyyy.com
ALERT : [2011-06-08T12:38:00+0200] msg=<LOGKEY>, program=<Samhain>, hash=<2A3F91D5C3968ABE724481B245E91B984E55F98AC30A0561>
-----BEGIN LOGKEY-----
2A3F91D5C3968ABE724481B245E91B984E55F98AC30A0561[2011-06-08T12:38:00+0200]
-----BEGIN SIGNATURE-----
F6F1BD576F38C9015D18FCE059B2C33AED8A50498714D768
000001 1307529480::centos54.xxx.yyyyy.com
-----END MESSAGE-----

Can anyone tell me what's going on and how to fix this?
 
Old 06-08-2011, 07:04 AM   #2
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
what's the problem ?
 
Old 06-08-2011, 07:19 AM   #3
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Original Poster
Rep: Reputation: 22
The problem is - there's an error! Errors never get better on their own - only worse, so best to fix it BEFORE it gets worse, not so?

I regard it as abnormal when a server sends you two error messages by email every time you reboot it. Not even Windows does that!
 
Old 06-08-2011, 08:30 AM   #4
AlucardZero
Senior Member
 
Registered: May 2006
Location: USA
Distribution: Debian
Posts: 4,824

Rep: Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615Reputation: 615
Oh, you didn't mention that this happens every time you reboot it, and it's not obvious from those messages that there is a problem.

I did some Googling for you ("BEGIN LOGKEY") and searched the manual. The first one is Samhain starting up. The second one is Samhain's key which is required to verify further messages you receive from Samhain. Neither indicate a problem.

If you don't want the messages you can turn down Samhain's log level (not recommended if you use it) or uninstall it.
 
Old 06-08-2011, 11:18 AM   #5
baldur2630
Member
 
Registered: Jan 2007
Location: Belgium
Distribution: CentOS & Ubuntu
Posts: 173

Original Poster
Rep: Reputation: 22
What exactly IS Samhain? Why should I use it? How does one turn it off if I decide I don't need it anf how do I turn down the Log Level if I do?
 
0 members found this post helpful.
Old 06-08-2011, 06:09 PM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Quote:
Originally Posted by baldur2630 View Post
What exactly IS Samhain? Why should I use it? How does one turn it off if I decide I don't need it anf how do I turn down the Log Level if I do?
That post just signifies the fact you didn't even bother to read the manual AlucardZero presented you with. Please at least try to make an effort.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Debian sid serious proxy error after latest updates! jackgu1988 Linux - Software 12 12-08-2009 11:53 AM
Ethernet wont work after applying updates theacerguy Linux - Networking 3 07-11-2009 10:38 AM
Please help me install latest JDK & JRE on my CentOS server xNuManx Linux - General 5 10-04-2008 04:49 AM
Applying Updates salmanucit Linux - Software 2 01-29-2006 06:05 AM
Need Help Applying updates in Redhat 9 jleakey77 Linux - Newbie 4 10-27-2003 02:22 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:23 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration