Novell LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009 Manual page 128

Hide thumbs Also See for LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009:
Table of Contents

Advertisement

To tell AIDE which attributes of which files should be checked, a configuration file
must be created. Find an example configuration at /etc/aide.conf. This file is
also a template and may be modified to create the actually used configuration. The first
section of the configuration handles general configuration parameters like the location
of the AIDE database file. More interesting for your local configurations are the Custom
Rules and the Directories and Files sections. A typical rule looks like the
following:
Binlib
After defining the variable Binlib, the respective checking options are used in the
files section. Important options include the following:
Table 13.1
Option
p
i
n
u
g
s
b
m
c
md5
sha1
116
Security Guide
= p+i+n+u+g+s+b+m+c+md5+sha1
Important AIDE Checking Options
Description
Check for the file permissions of the selected files or directories.
Check for the inode number. Every filename has a unique inode
number that should not change.
Check for the number of links pointing to the respective file.
Check if the owner of the file changed.
Check if the group of the file changed.
Check if the file size changed.
Check if the block count used by the file changed.
Check if the modification time of the file changed.
Check if the files access time changed.
Check if the md5 checksum of the file changed.
Check if the sha1 (160 Bit) checksum of the file changed.

Advertisement

Table of Contents
loading

This manual is also suitable for:

Suse linux enterprise desktop 11

Table of Contents