Any views expressed within media held on this service are those of the contributors, should not be taken as approved or endorsed by the University, and do not necessarily reflect the views of the University in respect of any particular issue.

LCFG Project

LCFG Project

Recent Activity for the LCFG project

Weekly Changes – 15/11/2021

There are no major changes this week just a few useful new features added to the systemd and auditd components. Here are the full details…

Systemd presets

As noted last week the LCFG systemd component has now gained support for configuring service presets. This week see the introduction of the new schema and the upgrade of the component package on Ubuntu Focal. Currently there are no standard presets in the LCFG configuration, we will discuss the addition of default settings at a future LCFG monthly meeting.

Linux audit daemon

The auditd component has gained support for specifying additional files which should be monitored for any access (either read, write, execute or changes to attributes). This is done like:

!auditd.watch_files               mADD(ssh)
!auditd.watch_path_ssh            mSET(/usr/bin/ssh)
!auditd.watch_perms_ssh           mSET(aw)
!auditd.watch_key_ssh             mSET(CMD_ssh)

This example would cause the audit daeamon to monitor the ssh client binary for any changes to the contents or attributes.

The key is a simple string which is used to tag any matching events. The permissions are one or more of: r – read of the file, w – write to the file, x – execute the file, a – change in the file’s attribute. See the audit.rules(7) manual page for full details.

Support for this new feature will be completed next week when the new component package is added.

AFS scripts dependencies

There is a new dice/options/afs-scripts.h header which can be used to include all the Perl dependencies for our local AFS scripts. These packages were previously only included on CO desktop machines. The new header makes it possible to include the packages on any DICE machine.

tcsh

Fans of the ancient C shell will be pleased to hear that tcsh is now available on DICE Ubuntu machines.

Leave a reply

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>

css.php

Report this page

To report inappropriate content on this page, please use the form below. Upon receiving your report, we will be in touch as per the Take Down Policy of the service.

Please note that personal data collected through this form is used and stored for the purposes of processing this report and communication with you.

If you are unable to report a concern about content via this form please contact the Service Owner.

Please enter an email address you wish to be contacted on. Please describe the unacceptable content in sufficient detail to allow us to locate it, and why you consider it to be unacceptable.
By submitting this report, you accept that it is accurate and that fraudulent or nuisance complaints may result in action by the University.

  Cancel