DK 'Log


Upcoming Installer testing version
Sat, 28 Feb 2009

I'm proud to announce the availability of the first public testing release of the upcoming installer. We're in final stages of testing now, and tho there are still known issues it's time to get community feedback on it. Many many thanks to anybody willing to help test this iso. Please keep in mind that it's a testing version, not intended for production. We can't even ensure that at the end of the testing period there will be a seamless upgrade into the stable distribution ;-)

First a quick note on versioning. The new installer will have two versions, one for each architecture:

  • Installer 1.2: amd64 (that is, most of the 64bit capable processors out there, including Xeons).
  • Installer 1.1: i386 (old 32bit).
  • Our intention, right now, is to maintain the 1.1 as long as needed and focus on the 1.2(64bit). Functionality will be exactly the same (if it doesn't involve too much work, we've got limited resources. Jasper/Tomcat integration for example will be limited to 1.2) on both but our development platform is entirely 64bit based due to performance reasons, so there might be a slight delay.
    We're not excluding anyone tho, we're going to maintain updates for 32bit while there is a large enough user base on it and 32bit users can test the 64bit version on vmware without problems.

    The installer testing version can be found at http://data.alienvault.com/ossim-installer_1.2.beta1.iso. Next I'll list how to install it (along with update guidelines), known issues right now (and how to report new ones) and a short list of some of the stuff included in this release.


    Download it

    Highlighting the download: http://data.alienvault.com/ossim-installer_1.2.beta1.iso.


    Installing it

    Grab the iso, install it. After installation, in order to get a clean testing and updating environment (we're working on solving this right now) issue an:

    apt-get remove ossim-cd-setup
    
    This will erase the monstrous package we used before, leaving the files tho (since they're uncompressed from within a .tgz). More on this later.
    After this:
    apt-get update; apt-get upgrade
    
    You might get an gpg inoxious error; I'm working on getting the packages gpg signed, thanks Jonathan for the script when it arrives :-))


    Bugtracking/reporting

    We did setup a specific forum for this. Please post any discovered bugs in there, and please check the rest of the 1.2 forum in case somebody might have reported the issue before.
    Before reporting a bug please issue an "apt-get update; apt-get upgrade", your bug might have been fixed.


    Known issues

    There are several issues that I'm aware of right now, which I'm working on:

    • Jasperserver password change might break jasperserver.
    • SEM doesn't work out of the box (haven't commited the code to the cvs yet).
    • /home/ossim/dist/ doesn't get cleaned up.
    • Creating new tabs breaks existing tabs at executive panel.
    • Memory issues (adding tomcat to the mix didn't help the already large memory requirements)
    • Passwords doesn't get changed / adapted for everything.
    • the reconfig bug when passwords contain "&, ', ; or \"" is still present.
    • repository is missing gpg signatures


    Feature highlight

    There are many things we'll be proud of this new release, just to name a few (all of them will be provided before the final release via updates):

    1. Completely new forensics console. Based on ACID and BASE we decided to incorporate the code into our own cvs; we just have too many specific needs and need to cover them. Check out the following screenshots:
      • standard alert view
      • event trend
    2. Disk based event storage (a.k.a. SEM) (will be updating a screenshot asap)
    3. Interactive risk maps (seen them before)
    4. Reporting plugins using JasperServer. This will be a major breakthrough, allowing for easy to share reporting plugins, scheduled reports, auto-emailing of reports and much more.
    5. Shellcode interpretation plugin for forensics.
    6. OSSEC 2.0
    7. Many new plugins.
    8. Updated directives, cross correlation and inventory correlation tables.
    9. Complete debian package based update/upgrade mechanism, including offline updates. No more custom ossim-updates.
    10. Many more...

    We want this release to be as good as possible, and your feedback is crucial for that. Please download it, throw it into a VM, make your evil tests and report back on the forum thread mentioned above.

    Enjoy.

    posted at: 16:41 | path: /ossim | permanent link to this entry | 0 comments |
    Tags: alpha, beta, installer, ossim, 1.2, amd64



    Categories

    / (62)
        code/ (1)
        feed/ (1)
        friends/ (1)
        ossim/ (39)
            installer/ (3)
            plugins/ (2)
            tuning/ (3)
            tutorials/ (8)
        personal/ (19)
            campus/ (2)
            opinion/ (1)
            travel/ (1)
        rants/ (1)



    Dominique Karg
    (feel free to get in touch)
    • Mail (gpg key)
    • Linkedin
    • Twitter
    • Forums

    Friend's blogs:
    • /blog/jaime
    • /blog/juanma
    • /blog/santiago






    Certified Application Security Specialist




    RSS




    < February 2009 >
    MoTuWeThFrSaSu
           1
    2 3 4 5 6 7 8
    9101112131415
    16171819202122
    232425262728 




    Archives

    2009-Dec
    2009-Sep
    2009-Aug
    2009-Jul
    2009-Jun
    2009-May
    2009-Apr
    2009-Mar
    2009-Feb
    2009-Jan
    2008-Dec
    2008-Oct
    2008-Aug
    2008-Jul
    2008-May
    2008-Mar
    2008-Feb
    2008-Jan
    2007-Dec
    2007-Nov




    Tags

    installer ossim tutorial untagged




    Made with PyBlosxom