Modify

Ticket #1943 (closed enhancement: fixed)

Opened 3 years ago

Last modified 3 years ago

Security audit support

Reported by: ejhernandez@… Owned by: ejhernandez@…
Milestone: 2.0 Component: control center
Severity: major Keywords:
Cc:

Description

Add password cracker for eBox CC.

Attachments

Change History

comment:1 Changed 3 years ago by ejhernandez@…

(In [17706]) Branching to starting the development for audit refs #1943

comment:2 Changed 3 years ago by ejhernandez@…

(In [17707]) Branching packaging as well refs #1943

comment:3 Changed 3 years ago by ejhernandez@…

(In [17778]) Starting with password checker refs #1943

comment:4 Changed 3 years ago by ejhernandez@…

(In [17794]) Alerts are sent to eBox CC when weak passwords were found refs #1943

comment:5 Changed 3 years ago by ejhernandez@…

(In [17795]) Send event even if we did not find any weak password refs #1943

comment:6 Changed 3 years ago by ejhernandez@…

(In [17828]) Merging [17787:17889] from trunk to own branch refs #1943

comment:7 Changed 3 years ago by ejhernandez@…

(In [17829]) Report thingie is ready to send to eBox CC. We have generated the tables and so on... refs #1943

comment:8 Changed 3 years ago by ejhernandez@…

(In [17834]) Report info is sent and gathered correctly. Password strength check is done and reported refs #1943

comment:9 Changed 3 years ago by ejhernandez@…

(In [17839]) The audit is performed just weekly instead of daily refs #1943

comment:10 Changed 3 years ago by ejhernandez@…

(In [17844]) Perform the audit and the reporting separately. Run the audit once a week in a cron job refs #1943

comment:11 Changed 3 years ago by ejhernandez@…

(In [17847]) Support for level and origin in security audit refs #1943

comment:12 Changed 3 years ago by ejhernandez@…

(In [17952]) Using a wrapper to kill the process after 12h and use the final package version with proper ebox permissions instead of working as root refs #1943

comment:13 Changed 3 years ago by ejhernandez@…

(In [17962]) * Call john twice one per hash format

  • Alert for a user is sent according to the lowest strength level

All refs #1943

comment:14 Changed 3 years ago by ejhernandez@…

(In [17963]) Using SIGTERM instead of SIGKILL to ensure session recording is done refs #1943

comment:15 Changed 3 years ago by ejhernandez@…

(In [17964]) Establish dependency on john greater or equal than 1.7.6 refs #1943

comment:16 Changed 3 years ago by ejhernandez@…

(In [17979]) NN: Update the change log for security audit refs #1943

comment:17 Changed 3 years ago by ejhernandez@…

  • Status changed from new to closed
  • Resolution set to fixed

Merged and ready to be released.

View

Add a comment

Modify Ticket

Change Properties
<Author field>
Action
as closed
The resolution will be deleted. Next status will be 'reopened'
Author


E-mail address and user name can be saved in the Preferences.

 
Note: See TracTickets for help on using tickets.