Hi there,
Unfortunately I have to report the exact same issue on our servers.
asl -l runs as a nightly cron job on our servers and last nights (Australian Time) update produced the same error poppy reported: Apache failed to restart after update!
Luckily one of techs was still up and was able to fix the issue. The temp solution was to comment line 46 of 10_asl_rules.conf out.
Here is our error, similar to the one form poppy:
Quote:
root@xxxxxxxxxxxx [~]# service httpd start
Syntax error on line 46 of /usr/local/apache/conf/modsec_rules/10_asl_rules.conf:
Error creating rule: Unknown variable: REQBODY_ERROR
Also our cron daemon reported the following:
Quote:
Syntax error on line 46 of /usr/local/apache/conf/modsec_rules/10_asl_rules.conf:
Error creating rule: Unknown variable: REQBODY_ERROR
Checking for updates..
ASL version is current: package asl is not installed
[60G[[1;32mOK[0m]
APPINV rule updates are available: 201107281511 [60G[[1;33mINFO[0m]
CLAMAV rule updates are available: 201108091005 [60G[[1;33mINFO[0m]
GEOMAP rule updates are available: 201108090859 [60G[[1;33mINFO[0m]
Updating MODSEC to 201108100957: updated [60G[[1;32mOK[0m]
OSSEC rule updates are available: 201108021559 [60G[[1;33mINFO[0m]
Can anyone from atomicorp give a statement please? We do pay for the licence and I just want to make sure if that was an error on atomicorps site or if something is wrong with our ModSec configuration. To be honest, we are no ModSec Experts, but thats the reason why we use the ASL service.
Btw: Because of the issue around 1000 websites we host were offline for about an hour. Since it was in the middle of the night, damage was minimal, but still ...
Cheers from Oz
Bjorn