
Chapter 12. Installing and Configuring Tripwire 149
information, see Section 12.7.
3. Run a Tripwire integrity check — Compare the newly-created Tripwire database with the actual
system files, looking for missing or altered files. For more information, see Section 12.8.
4. Examine the Tripwire report file — View the Tripwire report file using twprint to note integrity
violations. For more information, see Section 12.9.
5. Take appropriate security measures — If monitored files have been altered inappropriately, you
can either replace the originals from backups or reinstall the program.
6. Update the Tripwire database file — If the integrity violations are intentional and valid, such
as if you intentionally edited a file or replaced a particular program, you should tell Tripwire’s
database file to not report them as violations in future reports. For more information, see Section
12.10.
7. Update the Tripwire policy file — If you need to change the list of files Tripwire
monitors or how it treats integrity violations, you should update your sample policy file
(/etc/tripwire/twpol.txt), regenerate a signed copy (/etc/tripwire/tw.pol), and
update your Tripwire database. For more information, see Section 12.11.
Refer to the appropriate sections within this chapter for detailed instructions on these steps.
12.2. Installation Instructions
Once installed, Tripwire must also be correctly initialized to be able to keep a close watch on your
files. These sections detail how to install the program, if it is not already present on your system, and
then how to initialize the Tripwire database.
12.2.1. RPM Installation Instructions
The easiest way to install Tripwire is to install the tripwire RPM during the Red Hat Linux 7.3
installation process. However, if you have already installed Red Hat Linux 7.3, you can use RPM,
Gnome-RPM, or Kpackage to install the Tripwire RPM from the Red Hat Linux 7.3 CD-ROMs.
The following steps outline this process using RPM:
1. Locate the RedHat/RPMS directory on the Red Hat Linux 7.3 CD-ROM.
2. Locate the tripwire binary RPM by typing ls -l tripwire* in the RedHat/RPMS direc-
tory.
3. Type rpm -Uvh
name (where name is the name of the Tripwire RPM found in step 2)
4. After installing the tripwire RPM, follow the post-installation instructions outlined below.
Note
The release notes and README file are located in /usr/share/doc/tripwire- version-number .
These documents contain important information about the default policy file and other issues.
12.2.2. Post-Installation Instructions
The tripwire RPM installs the program files needed to run the software. After you have installed
Tripwire, you must configure it for your system as outlined in the following steps:
Commentaires sur ces manuels