List Info

Thread: Re: Error with Fedora package installation => phpgacl !!!




Re: Error with Fedora package installation => phpgacl !!!
country flaguser name
United States
2007-05-28 04:55:43
Hello Dominique,

Thanks for your help.

The symptoms are the following :
When I go to the URL http://MyHost/ossim/  I've got the following message :
 ;       You need to setup default acls
        Click here to enter setup

So I click on here and I've got the following message :
Setting up domain access...

Setting up Main Menu & Top frame ...
Setting up Control Panel -> Metrics ...
Setting up Control Panel -> Alarms ...
Setting up Control Panel -> Alerts ...
Setting up Control Panel -> Vulnerabilities ...
Setting up Policy -> Policy ...
Setting up Policy -> Hosts ...
Setting up Policy -> Networks ...
Setting up Policy -> Sensors ...
Setting up Policy -> PolicySignatures ...
Setting up Policy -> Ports ...
Setting up Reports -> HostReport ...
Setting up Reports -> SecurityReport ...
Setting up Reports -> PDFReport ...
Setting up Reports -> Anomalies ...
Setting up Reports -> Incidents ...
Setting up Monitors -> Session ...
Setting up Monitors -> Network ...
Setting up Monitors -> Availability ...
Setting up Monitors -> Sensors ...
Setting up Monitors -> Riskmeter ...
Setting up Correlation -> Directives ...
Setting up Correlation -> Cross Correlation ...
Setting up Correlation -> Backlog ...
Setting up Configuration -> Main ...
Setting up Configuration -> Users ...
Setting up Configuration -> Plugins ...
Setting up Configuration -> RRD Config ...
Setting up Configuration -> Host Scan ...
Setting up Tools -> Scan ...
Setting up Tools -> RuleViewer ...
Setting up Tools -> Backup ...

Setting up default admin user...


Back
 
That's why I configure debug mode on phpgacl to try to understand what's happening.
Do you know what I have to do ?

Regards,

Sébastien.



Dominique Karg wrote:
ossim.net" type="cite">Hello Sébastien,

the phpgacl debug output doesn't seem very helpful, could you please briefly explain the symptoms without debug ?

Did you try to:

- Setup phpgacl stuff on a different database (create an empty one, change entries where needed)
- Check README.phpgacl for some hints. 
- Check the phpgacl config files ? Since you're installing on fedora I'm not sure where everything is located but depending on the phpgacl version it may have one or two files which both need to have correct values set.

Good luck,

Dominique

Am 25.05.2007 um 17:07 schrieb Sébastien Thomelin:

Hello,

I succeed to solve my pb, there were information which missed in files.
But now, I've got a pb with the phpgacl.
I select the debug option, and I've got the following page (almost the same I think) http://myhost/phpgacl/setup.php :
http://permalink.gmane.org/gmane.comp.security.ossim.support/66

I'm reading the PHP code, but it take time to understand everything.

Could you help me please ?

Regards,

Sébastien.


Sébastien Thomelin wrote:
alcatel-lucent.fr" type="cite"> Hello,

I have a RedHat EL4 with the OSSIM ; Fedora Core 3 packages.
I followed the wiki instruction  ( http://www.ossim.net/dokuwiki/doku.php?id=installation:fedora ) but I have an error when I run the ossim-agent.

The/etc/ossim/server/config.xml is the following :

<?xml version='1.0' encoding='UTF-8' ?>

<config>
&nbsp;   ; &nbsp;  <log filename="/var/log/ossim/server.log"/>
 &nbsp; &nbsp; &nbsp;  <sensor name="server" ip="127.0.0.1" interface="eth0"/>
 &nbsp; &nbsp;   ; <datasources>
 &nbsp; &nbsp; &nbsp; &nbsp;   ; &nbsp; &nbsp; <datasource name="ossimDS" provider="MySQL" dsn="PORT=3306;USER=root;PASSWORD=XXXXXX;DATABASE=ossim;HOST=localhost"/>
&nbsp;   ; &nbsp; &nbsp; &nbsp; &nbsp;   ; <datasource name="snortDS" provider="MySQL" dsn="PORT=3306;USER=root;PASSWORD=XXXXXX;DATABASE=snort;HOST=localhost"/>
&nbsp;   ; &nbsp;  </datasources>
 &nbsp; &nbsp; &nbsp;  <directive filename="/etc/ossim/server/directives.xml"/>
&nbsp; &nbsp; &nbsp;   <scheduler interval="15"/>
  ; &nbsp; &nbsp;  <server port="40001"/>
&lt;/config&gt;

When I startossim-server -d -c /etc/ossim/server/config.xml I don't have any error.

The/etc/ossim/agent/config.xml is the following :

<?xml version="1.0" encoding='UTF-8' standalone="no" ?>

<!DOCTYPE  config [

 &nbsp;  <!-- Replace 127.0.0.1 with your sensor Ip -->
&nbsp;   <!ENTITY &nbsp; sensor&nbsp; &nbsp;  "127.0.0.1" >

 &nbsp;  <!-- Default network interface -->
&nbsp;   <!ENTITY &nbsp;  interface&nbsp; "eth0" >

 &nbsp;  <!-- Default OSSIM database connection (db:host:dbname:user:pass) -->
&nbsp;   <!ENTITY &nbsp;  ossim_db&nbsp;  "mysql:localhost:ossim:root:XXXXXX" >

 &nbsp;  <!-- Replace localhost with your server Ip -->
&nbsp;   <!ENTITY &nbsp;  serverip&nbsp;  "localhost" >

 &nbsp;  <!-- Log directory -->
&nbsp;   <!ENTITY &nbsp;  logdir&nbsp; &nbsp;  "/var/log/ossim" >

 &nbsp;  <!-- plugins -->
&nbsp;   <!ENTITY &nbsp;  apache&nbsp; &nbsp; &nbsp; SYSTEM '/etc/ossim/agent/plugins/apache.xml'>
&nbsp; &nbsp; ........
 &nbsp;  <!ENTITY &nbsp;  tcptrack&nbsp; &nbsp; SYSTEM '/etc/ossim/agent/plugins/tcptrack.xml'>
]>
<;config>

When I run ossim-agent -d -c /etc/ossim/agent/config.xml I have the following error :
DBI connect('ossim:localhost:3306:','root',...) failed: Access denied for user 'root''localhost' (using password: NO) at /usr/lib/perl5/site_perl/5.8.5/i386-linux-thread-multi/ossim_conf.pm line 34
Can't connect to Database


I wanted to know :
In /etc/ossim/server/config.xml
 &nbsp;  What does datasource name="xxx" mean ?

In /etc/ossim/agent/config.xml the line ossim_db&nbsp;  "mysql:localhost:ossim:root:XXXXXX" >
What do ossim_db and mysql mean ?

I just change the mysql password in these two files.
Is there an other thing I have to do ?

Thanks for your response.

Regards,

S&eacute;bastien Thomelin.



--



Sébastien THOMELIN
Security Team
Data Center
Security - Infrastructure Management
Alcatel-Lucent ICT Services - Massy, FRANCE
Phone: +33 (0) 1.69.76.94.93 / Alcatel-Lucent : 2107.9493
Mailto: alcatel-lucent.fr">sebastien.thomelinalcatel-lucent.fr






Email analys&eacute; par PC Tools Spyware Doctor (5.0.0.169)
Version de la base de donn&eacute;es : 5.06871
http://www.pctools.com/fr/spyware-doctor/
-------------------------------------------------------------------------
This SF.net email is sponsored by DB2 Express
Download DB2 Express C - the FREE version of DB2 express and take
control of your XML. No limits. Just data. Click to get it now.
Os-sim-support mailing list



--



Sébastien THOMELIN
Security Team
Data Center
Security - Infrastructure Management
Alcatel-Lucent ICT Services - Massy, FRANCE
Phone: +33 (0) 1.69.76.94.93 / Alcatel-Lucent : 2107.9493
Mailto: sebastien.thomelinalcatel-lucent.fr">sebastien.thomelinalcatel-lucent.fr






Email analysé par PC Tools Spyware Doctor (5.0.0.169)
Version de la base de données : 5.06871
http://www.pctools.com/fr/spyware-doctor/
[1]

about | contact  Other archives ( Real Estate discussion Medical topics )