
Chapter 12. Installing and Configuring Tripwire 157
For example, if you would like two administrators, Sam and Bob, notified if a networking program is
modified, change the Networking Programs rule directive in the policy file to look like this:
(
rulename = "Networking Programs",
severity = $(SIG_HI),
)
Once a new signed policy file is generated from the /etc/tripwire/twpol.txt file, the specified
email addresses will be notified upon violations of that particular rule. For instructions on signing
your policy file, see Section 12.11.
12.12.1. Sending Test Email Messages
To make sure that Tripwire’s email notification configuration can actually send email correctly, use
the following command:
A test email will immediately be sent to the email address by the tripwire program.
12.13. Additional Resources
Tripwire can do more than what is covered in this chapter. Refer to these additional sources of infor-
mation to learn more about Tripwire.
12.13.1. Installed Documentation
• /usr/share/doc/tripwire-
version-number — An excellent starting point for learning
about how to customize the configuration and policy files in the /etc/tripwire directory.
• Also, refer to the man pages for tripwire, twadmin and twprint for help using those utilities.
12.13.2. Useful Websites
• http://www.tripwire.org — The home of the Tripwire Open Source Project, where you can find the
latest news on the application, including an FAQ list.
Commenti su questo manuale