ClearFoundation Tracker - ClearCenter
View Issue Details
0002030ClearCenterapp-security-audit - Security Auditpublic2014-11-11 09:282014-11-11 09:36
marclaporte 
 
lowfeatureN/A
confirmedopen 
 
 
0002030: Security audit report should also indicate the software updates for the same time period
We get something like this:

AIDE found differences between database and filesystem!!
Summary:
  Total number of files: 18491
  Added files: 0
  Removed files: 0
  Changed files: 24

But how to know if those 24 changed files are legit?

It would be useful to have (in the same message) the info from https://example.org:81/app/software_updates [^]

So when I see:
changed: /usr/lib64/openssl/engines/libcapi.so
changed: /usr/lib64/openssl/engines/libchil.so

Along with this:
Nov 11 03:42:25 Updated openssl-1.0.1e-16.el6_5.15.x86_64

I can be confident that it's legit.

Thanks!
No tags attached.
Issue History
2014-11-11 09:28marclaporteNew Issue
2014-11-11 09:36user2Statusnew => confirmed

There are no notes attached to this issue.