This repository was archived by the owner on Apr 16, 2021. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 522
This repository was archived by the owner on Apr 16, 2021. It is now read-only.
Ubuntu 16.04 Xenial Support #1247
Copy link
Copy link
Closed
Description
-
Ubuntu 16.04 Xenial PPA
- rebuild tcl8.6 package - change
enable-threads
todisable-threads
and adjust symbols - rebuild ALL Security Onion packages for
xenial
EXCEPT the following:- prads
- securityonion-argus-clients
- securityonion-argus-server
- securityonion-elsa
- securityonion-elsa-extras
- securityonion-elsa-node-perl
- securityonion-elsa-perl
- securityonion-elsa-web-perl
- securityonion-http-agent
- securityonion-libdata-serializable
- securityonion-ndpi
- securityonion-passenger
- securityonion-passenger-conf
- securityonion-snorby
- securityonion-wkhtmltopdf
- sphinxsearch
- xplico
- rebuild tcl8.6 package - change
-
barnyard
-
data too long for column class
- adjust mysql mode in/etc/mysql/conf.d/securityonion-squert.cnf
-
-
securityonion-all
- change ELSA to Elastic
-
securityonion-capme
- move capme files from
securityonion-elastic
package tosecurityonion-capme
package - SSO auth
- update mysql calls to mysqli
- move capme files from
-
securityonion-client
- remove
securityonion-argus-clients
dependency
- remove
-
securityonion-desktop-gnome
- install
lightdm
andlightdm-gtk-greeter
- install
Gnome Classic
desktop and set as default - remove
compiz
environments - check to see if
glib-compile-schemas
is installed
- install
-
securityonion-elastic
- add
php-curl
andjq
to dependencies - variables must be quoted when comparing
- new syslog-ng includes SEQNUM and ISODATE fields, remove them in
1001_preprocess_syslogng.conf
-
so-elastic-download
may be incorrectly settingINSTALLED
when components haven't been installed - if user chose Evaluation mode, set LS heap to 1600m and ES heap to 1000m
- add so-sensor-VERB scripts
- add
-
securityonion-iso
- change ELSA to Elastic
- add
securityonion-samples-bro
andsecurityonion-desktop-gnome
dependencies - purge
open-vm-tools
- remove build user from
/etc/subuid
and/etc/subgid
- remove build user debconf using
debconf-set-selections
-
securityonion-nsmnow-admin-scripts
- add
/etc/systemd/system/securityonion.service
that callsso-start
- remove reference to
service nsm stop
- remove
so-snorby-wipe
- add
-
securityonion-onionsalt
- change defaults to avoid
file ignore glob
andhash_type
warnings
- change defaults to avoid
-
securityonion-ossec-rules
- move
securityonion_rules.xml
fromsecurityonion-elastic
package tosecurityonion-ossec-rules
package
- move
-
securityonion-sensor
- update dependencies
-
securityonion-server
- remove
imagemagick
dependency
- remove
-
securityonion-setup
- move so-allow scripts from
securityonion-elastic
package tosecurityonion-setup
package -
systemctl enable securityonion.service
- set timezone to UTC using
timedatectl
- update salt
minion_id
with hostname - update
sosetup.conf
files to reflect new network device naming convention - selecting
Forward Node
thenCustom
results inDo you want to enable Elastic?
- sosetup-forward.conf needs to set
Elastic
toNO
to replicate GUI - avoid duplicating
OSSEC_AGENT_ENABLED
on storage nodes
- move so-allow scripts from
-
securityonion-sguil
- move Sguil changes from
securityonion-elastic
package tosecurityonion-sguil
package - change Sguil fonts to
Liberation
- move Sguil changes from
-
securityonion-skel
- change Sguil fonts to
Liberation
- change Sguil fonts to
-
securityonion-sostat
- depend on
bc
- fix master
Cross Cluster Search
section - include
so-apt-check
and updatesostat
andsoup
to call it
- depend on
-
securityonion-squert
- move Squert files from
securityonion-elastic
package tosecurityonion-squert
package - change
php5
dependencies tophp
- update
mysql
calls tomysqli
- SSO auth
- level2 function needs to output strings so frontend can read properly
- disable mysql strict mode in
/etc/mysql/conf.d/securityonion-squert.cnf
- remove old web code from
ip2c.php
- move Squert files from
-
securityonion-web-page
- remove references to ELSA
- add
libapache2-mod-authnz-external
as dependency
-
so-* scripts
- so-VERB should call so-autossh-VERB as well
- so-autossh-VERB should check to see if it's running on a master server and, if so, do nothing
- so-autossh-start should wait on
DOCKER_INTERFACE
if trying to bind toDOCKER_INTERFACE
-
so-elastic-status
- fix incorrect formatting -
so-import-pcap
- broken due to different output format in newcapinfos
-
so-apache-auth-sguil
- change
php5
tophp
- change
-
soup
-
syslog-ng
- change syslog version in
/etc/syslog-ng/syslog-ng.conf
to reflect actual syslog-ng version - CANCELLING since we currently match syslog-ng.conf in the package
- change syslog version in
Metadata
Metadata
Assignees
Labels
No labels