Skip to content

suddenly i cannot use auto_ossec anymore.. #23

Description

@y0d4a

Dear,

i was using auto_ossec before without problem, and all was perfect.
Now, i reinstalled security onion and cannot add anymore new clients (tried on two instance and it is the same behavior).

On windows side after run i got:
auto_ossec.exe X.X.X.X [*] Connected to auto enrollment server at IP: X.X.X.X [*] Pulled hostname and IP, encrypted data, and now sending to server. [*] We received our new pairing key for OSSEC, closing server connection. [*] Something did not complete. Does this system have Internet access? Traceback (most recent call last): File "auto_ossec.py", line 369, in <module> NameError: name 'path' is not defined None

on linux/server side:
`root@so01:~/auto-ossec# python3 auto_server.py
[*] The auto enrollment OSSEC Server is now listening on 9654
Client connected with ('X.X.X.X', 50928)
Timeout exceeded.
<pexpect.pty_spawn.spawn object at 0x7fee78057dd8>
command: /var/ossec/bin/manage_agents
args: ['/var/ossec/bin/manage_agents']
searcher: None
buffer (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
before (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
after: <class 'pexpect.exceptions.TIMEOUT'>
match: None
match_index: None
exitstatus: None
flag_eof: False
pid: 26833
child_fd: 8
closed: False
timeout: 300
delimiter: <class 'pexpect.exceptions.EOF'>
logfile: None
logfile_read: None
logfile_send: None
maxread: 2000
ignorecase: False
searchwindowsize: None
delaybeforesend: 0.05
delayafterclose: 0.1
delayafterterminate: 0.1
Traceback (most recent call last):
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 97, in expect_loop
incoming = spawn.read_nonblocking(spawn.maxread, timeout)
File "/usr/lib/python3/dist-packages/pexpect/pty_spawn.py", line 452, in read_nonblocking
raise TIMEOUT('Timeout exceeded.')
pexpect.exceptions.TIMEOUT: Timeout exceeded.

During handling of the above exception, another exception occurred:

Traceback (most recent call last):
File "auto_server.py", line 224, in handle
provision_key(hostname, ipaddr)
File "auto_server.py", line 197, in provision_key
ossec_key = parse_client(hostname, ipaddr)
File "auto_server.py", line 81, in parse_client
child.expect("for the new agent")
File "/usr/lib/python3/dist-packages/pexpect/spawnbase.py", line 315, in expect
timeout, searchwindowsize, async)
File "/usr/lib/python3/dist-packages/pexpect/spawnbase.py", line 339, in expect_list
return exp.expect_loop(timeout)
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 104, in expect_loop
return self.timeout(e)
File "/usr/lib/python3/dist-packages/pexpect/expect.py", line 68, in timeout
raise TIMEOUT(msg)
pexpect.exceptions.TIMEOUT: Timeout exceeded.
<pexpect.pty_spawn.spawn object at 0x7fee78057dd8>
command: /var/ossec/bin/manage_agents
args: ['/var/ossec/bin/manage_agents']
searcher: None
buffer (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
before (last 100 chars): b': X.X.X.X\r\nConfirm adding it?(y/n): '
after: <class 'pexpect.exceptions.TIMEOUT'>
match: None
match_index: None
exitstatus: None
flag_eof: False
pid: 26833
child_fd: 8
closed: False
timeout: 300
delimiter: <class 'pexpect.exceptions.EOF'>
logfile: None
logfile_read: None
logfile_send: None
maxread: 2000
ignorecase: False
searchwindowsize: None
delaybeforesend: 0.05
delayafterclose: 0.1
delayafterterminate: 0.1
Pairing complete. Terminating connection to client.

is something with new version of security onion or windows (win10 1803)?

tnx.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions