store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Thu Jun 20, 2013 5:15 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 
Author Message
 Post subject: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Sun Feb 22, 2009 6:18 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
This is announcing the ASL 2.1 alpha with the stand-alone ASL-Web interface to the [asl-2.0-bleeding] channel. As this is an alpha release, and therefore unsupported code. Please send feedback to support@atomicorp.com rather than post to the forums.

Changelog

- Added ASL Web, stand alone GUI (default account: admin, password: setup)
- First new-architecture module rewrite, kernel_check is now written in C
- Added logic to configure and install the default ASL Web databases
- Added asl-web init script, /etc/init.d/asl-httpd
- Added asl-web sysconfig, /etc/sysconfig/asl-httpd


To install:

yum --enablerepo=asl-2.0-bleeding upgrade asl
yum --enablerepo=asl-2.0-bleeding install asl-web


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Sun Feb 22, 2009 6:41 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Scott,

No Fedora 8 packages (i386) :(
No Fedora 10 packages (i386) :(


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Sun Feb 22, 2009 7:08 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
thats weird, they did get built for it. I'll do another run here shortly, see if they get populated correctly.

Update: They should be available now


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Mon Feb 23, 2009 6:34 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Thanks Scott that worked!

Can you supply the source of just the new kernel_check in srpms/asl ?

I assume all the tests / checks plan to go to C which is great, but can the source be supplied for anyone wanting to do their own custom checks / mods?

Especially anyone on 'unsupported' distributions :)

Thanks!


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Mon Feb 23, 2009 6:40 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
No, Im afraid not. Thats where all the license manager stuff is going. I made a note about you being able to create your own modules though, thats a good feature idea.


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Mon Feb 23, 2009 7:42 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Hi Scott,

That is good feature :)

Can we get control over some of the checks in the compiled binaries? I know it may then stop you getting warnings for certain issues, but these can be documented in the compliance report.

It just bugs me being warned about the kernel and some other checks when I know these. For me then after editing these, when I see red I know something needs my attention fast!

It would be good to be able to turn on / off the warning for any test in the compiled binary, just like php features in asl config.

That is my feature addition / suggestion.

Thanks for listening.

Thanks!


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Mon Feb 23, 2009 9:15 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
We're following the NIST standards in reference to that, what you'd do in that context is document the risks in your System Security Plan as "Accepted", however you *do* still see them reported. In some cases, depending on the data you're handling, you're not even permitted to accept the risk (PCI DSS, or HIPAA for example). Check out NIST-800-53 if you're interested in the methodology we're following.


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Mon Feb 23, 2009 11:16 pm 
Offline
Forum Regular
Forum Regular

Joined: Thu Oct 26, 2006 11:56 pm
Posts: 665
Hi Scott,

What about still running kernel and checks as shell scripts, but incorporating the license management into asl itself?

This way you are still able to customize reports if you desire, but you maintain license control :) ?

As this is alpha it's good to discuss and decide in a path.

It's just taking the users ability to control the kernel check in situations you can't run a asl kernel like a vds or you run xwindows.

I don't need to be told that I have no GRC that's obvious :)

That is my one and only critism of the new ASL, if a regular kernel_check.sh can be deployed I am happy :) or the ability to remove the critical alerts telling me what I know :)


Top
 Profile  
 
 Post subject: Re: ASL 2.1-0.svn090220.1 Alpha (Featuring ASL Web)
Unread postPosted: Mon Feb 23, 2009 11:38 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin

Joined: Wed Dec 31, 1969 8:00 pm
Posts: 7460
Location: earth
Hey it all comes down to the number of licenses ya wanna buy right? :P


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 9 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 0 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group