Florian Schiessl
2004-Jul-11 09:20 UTC
[Logcheck-devel] Bug#258735: wrong permissions in /etc/logcheck
Package: logcheck-database Version: 1.2.22a Severity: normal -- System Information: Debian Release: testing/unstable APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Kernel: Linux 2.4.25-1-686 Locale: LANG=C, LC_CTYPE=C Versions of packages logcheck-database depends on: ii debconf [debconf-2.0] 1.4.29 Debian configuration management sy -- debconf information: * logcheck-database/conffile-cleanup: true * logcheck-database/rules-directories-note: * logcheck-database/security_level: server * logcheck-database/standard-rename-note: Hi, I wondered why some of my ignore rules didn't apply. Then I recognized that for example the file /etc/logcheck/ignore.d.server/spamd is owned by root.root and not readable by others. So the cronjob, which runs under the user logcheck, simply couldn't read this file. Only a few files have this rights, not all. A chown -R root.logcheck /etc/logcheck has helped. If it's interesting, I upgraded from woody, it was no install from beginning. Florian -- .''`. : :' : Florian Schie?l <olfi at debianhowto.de> `. `' Debianhowto.de Team - http://www.debianhowto.de/ `-
maks attems
2004-Jul-15 16:34 UTC
Bug#258735: [Logcheck-devel] Bug#258735: wrong permissions in /etc/logcheck
On Sun, 11 Jul 2004, Florian Schiessl wrote:> Package: logcheck-database > Version: 1.2.22a > Severity: normal > > -- System Information: > Debian Release: testing/unstable > APT prefers testing > APT policy: (500, 'testing') > Architecture: i386 (i686) > Kernel: Linux 2.4.25-1-686 > Locale: LANG=C, LC_CTYPE=C > > Versions of packages logcheck-database depends on: > ii debconf [debconf-2.0] 1.4.29 Debian configuration > management sy > > -- debconf information: > * logcheck-database/conffile-cleanup: true > * logcheck-database/rules-directories-note: > * logcheck-database/security_level: server > * logcheck-database/standard-rename-note: > > Hi, > > I wondered why some of my ignore rules didn't apply. Then I recognized > that for example the file /etc/logcheck/ignore.d.server/spamd is owned > by root.root and not readable by others. So the cronjob, which runs > under the user logcheck, simply couldn't read this file. > > Only a few files have this rights, not all. A chown -R root.logcheck > /etc/logcheck has helped. > > If it's interesting, I upgraded from woody, it was no install from > beginning. > > > Floriani can confirm that an upgrades from woody has permissions problems $ sudo ls -l /etc/logcheck/ total 12 drwxr-x--- 2 root root 1024 Jun 22 21:25 cracking.d drwxr-x--- 2 root root 1024 May 16 08:37 cracking.ignore.d -rw-r--r-- 1 root root 180 Apr 19 20:22 header.txt drwxr-x--- 2 root root 1024 Jun 22 21:25 ignore.d.paranoid drwxr-x--- 2 root root 2048 Jul 5 10:05 ignore.d.server drwxr-x--- 2 root root 1024 Jun 22 21:25 ignore.d.workstation -rw-r--r-- 1 root root 1931 Jun 10 10:20 logcheck.conf -rw-r--r-- 1 root root 131 May 16 08:37 logcheck.logfiles drwxr-x--- 2 root root 1024 Jun 22 21:25 violations.d drwxr-x--- 2 root root 1024 Jul 6 00:28 violations.ignore.d $ ls -ld /var/lib/logcheck/ drwxr-xr-x 2 root root 1024 May 16 08:37 /var/lib/logcheck/ $ ls -ld /var/state/logcheck/ drwxr-xr-x 2 root root 1024 Jun 10 10:20 /var/state/logcheck/ looks like when upgrading from woody the postinstall didn't do its job. did upgrade afterwards to 1.2.23 from sid and had the bad surprise: Setting up logcheck (1.2.23) ... chown: `logcheck:logcheck': invalid user chgrp: invalid group name `logcheck' no logcheck user in passwd! zut, that was my last woody box. we have a severy problem here!!! a++ maks -------------- next part -------------- A non-text attachment was scrubbed... Name: not available Type: application/pgp-signature Size: 189 bytes Desc: Digital signature Url : http://lists.alioth.debian.org/pipermail/logcheck-devel/attachments/20040715/080e9381/attachment.pgp
Debian Bug Tracking System
2004-Jul-24 02:18 UTC
[Logcheck-devel] Bug#258735: marked as done (wrong permissions in /etc/logcheck)
Your message dated Fri, 23 Jul 2004 22:02:11 -0400 with message-id <E1BoBrX-0003x2-00 at newraff.debian.org> and subject line Bug#258735: fixed in logcheck 1.2.24 has caused the attached Bug report to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what I am talking about this indicates a serious mail system misconfiguration somewhere. Please contact me immediately.) Debian bug tracking system administrator (administrator, Debian Bugs database) -------------------------------------- Received: (at submit) by bugs.debian.org; 11 Jul 2004 09:21:04 +0000>From olfi at debianhowto.de Sun Jul 11 02:21:04 2004Return-path: <olfi at debianhowto.de> Received: from debianhowto.de [213.146.173.13] by spohr.debian.org with smtp (Exim 3.35 1 (Debian)) id 1BjaW7-0002DC-00; Sun, 11 Jul 2004 02:21:03 -0700 Received: (qmail 12905 invoked from network); 11 Jul 2004 09:21:01 -0000 Received: from unknown (HELO ?192.168.0.4?) (olfi at debianhowto.de@80.128.91.248) by debianhowto.de with SMTP; 11 Jul 2004 09:21:01 -0000 Message-ID: <40F10661.7050502 at debianhowto.de> Date: Sun, 11 Jul 2004 11:20:33 +0200 From: Florian Schiessl <olfi at debianhowto.de> User-Agent: Mozilla Thunderbird 0.6 (X11/20040605) X-Accept-Language: en-us, en MIME-Version: 1.0 To: submit at bugs.debian.org Subject: wrong permissions in /etc/logcheck Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 8bit Delivered-To: submit at bugs.debian.org X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-8.0 required=4.0 tests=BAYES_00,HAS_PACKAGE autolearn=no version=2.60-bugs.debian.org_2004_03_25 X-Spam-Level: Package: logcheck-database Version: 1.2.22a Severity: normal -- System Information: Debian Release: testing/unstable APT prefers testing APT policy: (500, 'testing') Architecture: i386 (i686) Kernel: Linux 2.4.25-1-686 Locale: LANG=C, LC_CTYPE=C Versions of packages logcheck-database depends on: ii debconf [debconf-2.0] 1.4.29 Debian configuration management sy -- debconf information: * logcheck-database/conffile-cleanup: true * logcheck-database/rules-directories-note: * logcheck-database/security_level: server * logcheck-database/standard-rename-note: Hi, I wondered why some of my ignore rules didn't apply. Then I recognized that for example the file /etc/logcheck/ignore.d.server/spamd is owned by root.root and not readable by others. So the cronjob, which runs under the user logcheck, simply couldn't read this file. Only a few files have this rights, not all. A chown -R root.logcheck /etc/logcheck has helped. If it's interesting, I upgraded from woody, it was no install from beginning. Florian -- .''`. : :' : Florian Schie?l <olfi at debianhowto.de> `. `' Debianhowto.de Team - http://www.debianhowto.de/ `- --------------------------------------- Received: (at 258735-close) by bugs.debian.org; 24 Jul 2004 02:09:50 +0000>From katie at ftp-master.debian.org Fri Jul 23 19:09:50 2004Return-path: <katie at ftp-master.debian.org> Received: from newraff.debian.org [208.185.25.31] (mail) by spohr.debian.org with esmtp (Exim 3.35 1 (Debian)) id 1BoByw-0000mT-00; Fri, 23 Jul 2004 19:09:50 -0700 Received: from katie by newraff.debian.org with local (Exim 3.35 1 (Debian)) id 1BoBrX-0003x2-00; Fri, 23 Jul 2004 22:02:11 -0400 From: Todd Troxell <ttroxell at debian.org> To: 258735-close at bugs.debian.org X-Katie: $Revision: 1.51 $ Subject: Bug#258735: fixed in logcheck 1.2.24 Message-Id: <E1BoBrX-0003x2-00 at newraff.debian.org> Sender: Archive Administrator <katie at ftp-master.debian.org> Date: Fri, 23 Jul 2004 22:02:11 -0400 Delivered-To: 258735-close at bugs.debian.org X-Spam-Checker-Version: SpamAssassin 2.60-bugs.debian.org_2004_03_25 (1.212-2003-09-23-exp) on spohr.debian.org X-Spam-Status: No, hits=-6.0 required=4.0 tests=BAYES_00,HAS_BUG_NUMBER autolearn=no version=2.60-bugs.debian.org_2004_03_25 X-Spam-Level: X-CrossAssassin-Score: 4 Source: logcheck Source-Version: 1.2.24 We believe that the bug you reported is fixed in the latest version of logcheck, which is due to be installed in the Debian FTP archive: logcheck-database_1.2.24_all.deb to pool/main/l/logcheck/logcheck-database_1.2.24_all.deb logcheck_1.2.24.dsc to pool/main/l/logcheck/logcheck_1.2.24.dsc logcheck_1.2.24.tar.gz to pool/main/l/logcheck/logcheck_1.2.24.tar.gz logcheck_1.2.24_all.deb to pool/main/l/logcheck/logcheck_1.2.24_all.deb logtail_1.2.24_all.deb to pool/main/l/logcheck/logtail_1.2.24_all.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to 258735 at bugs.debian.org, and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Todd Troxell <ttroxell at debian.org> (supplier of updated logcheck package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing ftpmaster at debian.org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.7 Date: Friday, 23 Jul 2004 21:39:19 -0500 Source: logcheck Binary: logcheck logtail logcheck-database Architecture: source all Version: 1.2.24 Distribution: unstable Urgency: low Maintainer: Debian logcheck Team <logcheck-devel at lists.alioth.debian.org> Changed-By: Todd Troxell <ttroxell at debian.org> Description: logcheck - Mails anomalies in the system logfiles to the administrator logcheck-database - A database of system log rules for the use of log checkers logtail - Print log file lines that have not been read Closes: 206495 213711 257874 258735 258759 259092 259094 259371 259466 260096 260102 260103 260105 260330 260382 260810 Changes: logcheck (1.2.24) unstable; urgency=low . eevans: * Added violations ignore rule for squid (Closes: #257874) maks * Added dhcpd-client, kernel, ntp, postfix rules. (Closes: #259094) * Added lots of postfix rules at level workstation for those, who wants to include /var/log/mail.log. (Closes: #206495) * Generalize "nobody" to "[_[:alnum:]-]+" for su rule. * Update rules ignore.d.paranoid/cron, ignore.d.paranoid/postfix. New courier rules merged and simplified from imap, impd-ssl and pop3d-ssl. thanks to Bastian Blank <waldi at debian.org>. (Closes: #258759) * Fix pid regex in cyrus rules. (Closes: #259092) * Added cyrus rules for notifyd. (Closes: #259466) * Make sure logtail gets a logfile to read, if not exit soon. Documented -o switch in logtail(8). (Closes: #259371) * Added logcheck-devel mail to logtail(8) and copyright. * Added userv rules. (Closes: #260105) * Generalize user match in spamd rule. (Closes: #260103) * Added a ippl rule at level workstation. (Closes: #260102) * Updated logcheck help message to all existent switches. Corrected logcheck command line parsing, -T needs no args. Use 6 'X' for mktemp(1) template. Better lock handling. (Closes: #260330) * Do not create unused /var/state/logcheck and really get rid of it. (Closes: #260096) * Added cs Translation. thanks Jan Outrata. (Closes: #260382) * Remove duplicate postfix rules, fix for remote string add lmtp rule. (Closes: #260810) todd: * Added 2 kernel rules for sparc workstations. * Added nearly 50 squid rules. (Closes: #213711) * Fix anacron Normal exit rule. * Move adduser from preinst to postinst (Closes: #258735) * Update pump and dhclient rules. Files: b12f7f6e9f7ee1c1ab93c11d06197436 670 admin optional logcheck_1.2.24.dsc fac761afff4056f62d05e0b0a49a8941 78439 admin optional logcheck_1.2.24.tar.gz b42736deefef2c9cbb27e596fe3453ca 38306 admin optional logcheck_1.2.24_all.deb 544fe294c31535dae713ca94746030c4 45540 admin optional logcheck-database_1.2.24_all.deb ab277c25932c9ef600581ebb1aa8f68c 22412 admin optional logtail_1.2.24_all.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFBAb4/4u3oQ3FHP2YRAteqAKDC5u2SOudNtfjaZvMM1gFdFIE1AQCfXBAm nUk8s8a4rlxDrmTdK7SD5XI=XQO7 -----END PGP SIGNATURE-----