[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: prelink cron script



Adam,
    Below are Jakub's comments on this tripwire vs prelink 
issue...
                                    Jack
-----------------------------------------------------------
On Fri, Oct 04, 2002 at 05:05:21PM -0400, Jack Howarth wrote:
> Jakub,
>    Have you thought through how something like tripwire will
> be able to verify the chksums without becoming very slow?

They have the choice. If they are paraniod enough to run rpm -V
or tripwire 10 times a day, prelinking is not a good idea for them.
Or tripwire or whatever they use could save md5sum of the prelinked
program if it verifies using prelink --verify and compare that as
alternative to the original md5sum (and only prelink --verify
if md5sum of the file matches neither of the sums).

As for requiring write access, prelink --verify doesn't require
write access to the program (it doesn't modify it in any way).
prelink -a needs access to all programs/libraries though, of course.

        Jakub
------------------------------------------------------------



Reply to: