Skip to content
Snippets Groups Projects
Commit b4324107 authored by Bob Mottram's avatar Bob Mottram
Browse files

Fixing tripwire policy

parent b7f63f6f
No related branches found
No related tags found
No related merge requests found
......@@ -120,43 +120,9 @@ function install_tripwire {
if ! grep -q '!/etc/share/tt-rss/lock' /etc/tripwire/twpol.txt; then
sed -i '\|/etc\t\t->.*|a\ !/etc/share/tt-rss/lock ;' /etc/tripwire/twpol.txt
fi
# Ignore additional install files
if ! grep -q '!/usr/local/bin/freedombone' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/freedombone* ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!=/usr/local/bin' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !=/usr/local/bin ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/addremove' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/addremove ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/backup' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/backup ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/backup2friends' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/backup2friends ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/batman' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/batman ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/control' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/control ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/controluser' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/controluser ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/cronic' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/cronic ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/meshavahi' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/meshavahi ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/restore' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/restore ;' /etc/tripwire/twpol.txt
fi
if ! grep -q '!/usr/local/bin/restorefromfriend' /etc/tripwire/twpol.txt; then
sed -i '\|/usr/local/sbin.*|a\ !/usr/local/bin/restorefromfriend ;' /etc/tripwire/twpol.txt
fi
# Not much is in /usr/local/bin other than project commands and avoiding it removes
# problems with updates. This is a tradeoff, but not by much.
sed -i '/\/usr\/local\/bin/d' /etc/tripwire/twpol.txt
# Avoid logging the changed database
sed -i 's|$(TWETC)/tw.pol.*||g' /etc/tripwire/twpol.txt
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment