LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 10-26-2012, 02:41 PM   #1
Izzmit
LQ Newbie
 
Registered: Feb 2012
Posts: 19

Rep: Reputation: Disabled
RHEL 6.1 Frequent updates to vaious %gconf.xml files


Hello.
I am setting up a new server, but I am running into an issue on my audit file. I have a strict list of items that must be audited, and I have copied that list from a working RHEL 6.1 server. Auditing should be identical, BUT...
I am seeing an excessive amount of entries in my audits, almost all stemming from ~me/.gconf/ folder. When this happens every few minutes, i get a spam of nearly 100 entries telling me that assorted files all have been changed.

.gconf/system/networking/connections/1/ipv4/%gconf.xml
.gconf/system/networking/connections/1/ipv4/%gconf.xml.new
.gconf/system/networking/connections/1/802-3-ethernet/%gconf.xml
.gconf/apps/nm-applet/ignore-ca-cert/%gconf.xml


It is set to report when files are chown, deleted, chmod, etc.
Whatever is going on here, it is done by the PID# of gconfd-2. I cannot disable this process -- I run gnome and weird things happen when i kill it.

If i kill the process and let it sit like that, these actions never show up in the audit. Once i start it again, it continues throwing these errors every few minutes.

These do not get thrown on a similarly configured server -- just this one. Any suggestions?

Edit:Quick update -- its every 5 minutes.

Last edited by Izzmit; 10-26-2012 at 02:58 PM.
 
Old 10-26-2012, 04:22 PM   #2
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
you are running Gnome on a server ?
the ~./gconf files are updated every time you log in as that user

so they will change

the ipv4 and 801 wireless are just updating
probably on the 350 sec. default cycle
 
Old 10-29-2012, 11:05 AM   #3
Izzmit
LQ Newbie
 
Registered: Feb 2012
Posts: 19

Original Poster
Rep: Reputation: Disabled
Yes, GNOME on a server. I have people logging in through thin clients, using it as a workstation.

I am sure hundreds of files are updated every minute or whatever on Linux. Any ideas what is making gconf special, as far as audits are concerned?
 
Old 10-31-2012, 10:26 AM   #4
Izzmit
LQ Newbie
 
Registered: Feb 2012
Posts: 19

Original Poster
Rep: Reputation: Disabled
I have a ton of entries in my audit list, but i got around to commenting them out, and waiting the 5 minutes and seeing if the error got pushed or not. I have limited it down to
"-a always,exit -F arch=b64 -S creat -S open -S openat -S truncate -S ftruncate -F exit=-EPERM -F auid>=500 -F auid!=<bignumber> -k access"

So, thats the line. It is on both redhat servers, but only 1 server is reporting the changes every 5 minutes.
Changes are reported for any logged in user -- if i have 3 terminal sessions open to 3 users, then all will get the messages every 5 min.
 
Old 11-09-2012, 11:26 AM   #5
Izzmit
LQ Newbie
 
Registered: Feb 2012
Posts: 19

Original Poster
Rep: Reputation: Disabled
Any ideas here?
I am getting it on a fresh install as well...just copied the audit rules across.
 
Old 11-09-2012, 12:52 PM   #6
John VV
LQ Muse
 
Registered: Aug 2005
Location: A2 area Mi.
Posts: 17,624

Rep: Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651Reputation: 2651
you could start by turning off the DESKTOP services
a server is not a desktop install

if you do not have a home wireless router or printer or mouse on the server rack then you can turn that off .

If no Bluetooth is being used on the rack ,turn off the desktop Bluetooth daemon
Turn off the gnome screensaver - not needed on a server .
Turn off the "personal file sharing " for the files in the ~/Downloads

open up " gnome-control-center" and disable the desktop programs
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
[SOLVED] VMware + Arch's frequent kernel updates kasl33 Arch 1 09-09-2011 12:41 AM
[SOLVED] Manually add keys to gconf XML files gusblake Linux - Desktop 1 06-18-2010 12:53 AM
[SOLVED] too many frequent updates causes some problems with Fedora 9 james2b Fedora 13 07-20-2009 02:10 AM
user login: could not resolve xml:readwrite: /home/.gconf flipwhy Linux - Newbie 4 08-20-2006 01:57 PM
xml? gconf? cant login as user flipwhy Linux - Newbie 1 08-20-2006 03:36 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 05:40 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration