1、下載并安裝
- [root@ipython ~]# wget http://nchc.dl.sourceforge.net/project/tripwire/tripwire-src/tripwire-2.4.2.2/tripwire-2.4.2.2-src.tar.bz2[root@ipython ~]# tar jxf tripwire-2.4.2.2-src.tar.bz2
- [root@ipython ~]# cd tripwire-2.4.2.2-src
-
- [root@ipython tripwire-2.4.2.2-src]#./configure --prefix=/software/tripwire
- [root@ipython tripwire-2.4.2.2-src]# make
- [root@ipython tripwire-2.4.2.2-src]# make install
-
- ############INSTALL 交互#################
- Press ENTER to view the LicenseAgreement. ###回車(chē)閱讀協(xié)議
- license agreement.[donot accept] accept ###同意協(xié)議
- Continuewith installation?[y/n] y ###確認(rèn)繼續(xù)安裝
- Enter the site keyfile passphrase: ###需要記住的keyfile
- Verify the site keyfile passphrase: ###重復(fù)
- Enter the local keyfile passphrase: ###需要記住的local keyfile
- Verify the local keyfile passphrase: ###重復(fù)
- Please enter your site passphrase: ###輸入
- Please enter your site passphrase: ###輸入
- ############交互結(jié)束,完成安裝#################
- [root@ipython tripwire-2.4.2.2-src]# ls /software/tripwire/etc/| sort
- ipython.me-local.key ####加密本地密鑰文件
- site.key ####加密站點(diǎn)密鑰文件
- tw.cfg ####加密配置變量文件
- tw.pol ####加密策略文件
- twcfg.txt ####定義數(shù)據(jù)庫(kù)、策略文件和Tripwire可執(zhí)行文件的位置
- twpol.txt ####定義檢測(cè)的對(duì)象及違規(guī)時(shí)采取的行為
2、初始化(生成基準(zhǔn)數(shù)據(jù)庫(kù))
- [root@ipython ~]#/software/tripwire/sbin/tripwire --init
- Please enter your local passphrase:###鍵入密碼,后面省略此交互
- ...
- ...
- Wrote database file:/software/tripwire/lib/tripwire/ipython.me.twd
- The database was successfully generated.
3、***次完整性檢查,和常用檢查參數(shù)
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check
-
- ##默認(rèn)檢查報(bào)告存放路徑##/software/tripwire/lib/tripwire/report/
- ##指定存放路徑##
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --twrfile ./test.twr
- ###Email 發(fā)送報(bào)告###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --email-report
- ###指定Email 報(bào)告的級(jí)別###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --email-report --email-report-level 2
- ###使用指定嚴(yán)重性等級(jí)的規(guī)則進(jìn)行檢查###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --severity 80
- ###使用指定的規(guī)則名檢查##
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --rule-name rulename
- ###只檢查指定的文件或目錄
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check object1 object2 object3
- ###檢查是忽略某屬性###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --ignore "property, property, property, property"
- ###獲取幫助
- [root@ipython ~]#/software/tripwire/sbin/tripwire --help all
-
- ##檢視報(bào)告##
- [root@ipython ~]#/software/tripwire/sbin/twprint --print-report --twrfile ./test.twr
-
- ##重定向加密報(bào)告的內(nèi)容##
- [root@ipython ~]#/software/tripwire/sbin/twprint --print-report --twrfile ./test.twr > output.text
-
- ##指定報(bào)告輸出時(shí)的級(jí)別##
- [root@ipython ~]#/software/tripwire/sbin/twprint --print-report --report-level 4--twrfile ./test.twr > output.text
4、升級(jí)基準(zhǔn)數(shù)據(jù)庫(kù)文件
- ###升級(jí)的目的是很正常的,因?yàn)閏heck 是基于基準(zhǔn)數(shù)據(jù)的###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --update --twrfile ./test.twr
- ###檢測(cè)后立即自動(dòng)update###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --check --interactive
5、升級(jí)策略文件
- ###更新策略穩(wěn)健,需要修改策略的規(guī)則,先將策略重定向出來(lái)###
- [root@ipython ~]#/software/tripwire/sbin/twadmin --print-polfile > twpol.txt
- ###照貓畫(huà)虎修改吧,然后update###
- [root@ipython ~]#/software/tripwire/sbin/tripwire --update-policy twpol.txt
- Parsing policy file:/root/twpol.txt
- Please enter your local passphrase:Please enter your site passphrase:
6、修改site key 和 local key
- ###修改前記得備份下###
- [root@ipython ~]#/software/tripwire/sbin/twadmin --generate-keys --site-keyfile /software/tripwire/etc/site.key
-
- [root@ipython ~]#/software/tripwire/sbin/twadmin --generate-keys --local-keyfile /software/tripwire/etc/site.key
-
- #配置文件通過(guò)site key 假面,數(shù)據(jù)文件和報(bào)告文件用local key 加密#
- [root@ipython ~]#/software/tripwire/sbin/twadmin --encrypt --site-keyfile /software/tripwire/etc/site.key
-
- [root@ipython ~]#/software/tripwire/sbin/twadmin --encrypt --local-keyfile /software/tripwire/etc/ipython.me-local.key
原文鏈接:http://www.ipython.me/centos/tripwire-file-md5.html |