Operating System - HP-UX
1845815 Members
4631 Online
110250 Solutions
New Discussion

Trusted system generated error...

 
SOLVED
Go to solution
Steven E. Protter
Exalted Contributor

Trusted system generated error...

I'm doing a test here. I'm not openning a support call, because I know this is not serious.

System is trusted.
I have moved the audit files from root fs to the /home fs

Following console error message:

Current audit filesize is 107271 kilobytes!!!
Must specify a backup file now !

contents of /.secure/etc/audfiles

/home/secure/adufile2,100000
*,0


I need a second entry here?

Thanks in advance. As always points awarded liberally.

Steve
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
9 REPLIES 9
Sridhar Bhaskarla
Honored Contributor

Re: Trusted system generated error...

Steve,

Yes. It is recommended to have a "next" audit file for auditing processes to switch. I feel it is reasonable?. What will it do if the first audit file is full?.

Look at -c and -x options of audsys to enable current and next audit files.

-Sri
You may be disappointed if you fail, but you are doomed if you don't try
Steven E. Protter
Exalted Contributor

Re: Trusted system generated error...

audsys -n -c /home/secure/audfile1 -s 10000 -x /home/secure/adufile2 -z 10000

was the command line I used. Should this not have handled it?

Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Sridhar Bhaskarla
Honored Contributor
Solution

Re: Trusted system generated error...

Yeah. When you ran this command, it should have created two files under /home/secure as audfile1 and audfile2 with the size you specified.

Check the file /.secure/etc/audnames to look for these entries. It should have been..

/home/security/audfile1,10000
/home/security/audfile2,10000

-Sri
You may be disappointed if you fail, but you are doomed if you don't try
Sridhar Bhaskarla
Honored Contributor

Re: Trusted system generated error...

small correction.. it should have created the files of zero size initally and will keep writing into them until they grow to the specified size in audnames and then will switch based on the audnames configuration.

Audomon actually monitors the size of the auditfiles and reports warnings.

-Sri
You may be disappointed if you fail, but you are doomed if you don't try
Steven E. Protter
Exalted Contributor

Re: Trusted system generated error...

easiest 25 points you ever earned?

I've re-run the command with the correct settings in the /.secure/etc/audnames configuration file.

We'll have too wait a while to see if it switches properly.

Thanks.
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Sridhar Bhaskarla
Honored Contributor

Re: Trusted system generated error...

Steve,

Thank you for being generous. I thought of saying not to assign points for the rest of the posts but I was in a hurry to post the correction.

Did you see those two files 'touched'?

You would need to wait until the audfile1 becomes 100MB. Then audomon should print a message that it is switching to audfile2 that time.

-Sri

PS: No more points pls.
You may be disappointed if you fail, but you are doomed if you don't try
Steven E. Protter
Exalted Contributor

Re: Trusted system generated error...

I appreciate your help.

I'm trying to see if I can wean myself from support a bit, because I'm courting a consulting client that doesn't have a contract. I think that's stupid, but I'd still be happy to spend their money.

I'll get to 100 MB in a few days, sooner since I'm playing with ssh public keys soon.

Thanks for your help. The files were always there, but the configuration was wrong.

Steve
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com
Sridhar Bhaskarla
Honored Contributor

Re: Trusted system generated error...

Hi Steve,

since you are playing with ssh, I would like to give you a hint that may help you a lot while troubleshooting various problems.

'sshd' can be run in debug mode if run with sshd -d. Try connecting to it from a client and see the messages out of sshd and they will tell|teach you a lot.

Install ethereal. Run ftp session through normal ftp and sftp. Watch the TCP stream in both the cases.

openssh is very easy to configure.

Enjoy encrypting.

-Sri

PS: I am only trying to see how I can make up for the extra points you gave me :-)
You may be disappointed if you fail, but you are doomed if you don't try
Steven E. Protter
Exalted Contributor

Re: Trusted system generated error...

You're a trip. In my opinion, you've earned the points and a beer or preferable substitute, should we ever meet.

Steve
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com