Skip to content

TripeWire Update Tripwire Database After OS Update

kurtcoke edited this page May 15, 2015 · 1 revision

Tripwire makes a hash checksum of each important file. On Ubuntu after an update some of the important files, might change and Tripwire will complain about it. It is important to update tripwire's database in order for tripwire to recognize these legitimate changes.

Tripwire is used to detect changes made by attackers on your machine.

The tripwire report file will be in the output of running tripwire --check. It will appear as follows below:

....
Wrote report file: /var/lib/tripwire/report/some-machine-20141006-100930.twr
...

Run tripwire check and write down the name of the tripwire report file .twr, you will need this to update the tripwire database.

$ sudo tripwire --check

Now update the tripwire database with the report file:

$ sudo tripwire --update --twrfile /var/lib/tripwire/report/some-machine-20141006-100930.twr

You will be prompted for your tripwire password.

If you run tripwire --check now, it will run with no errrors:

$ sudo tripwire --check


...

===============================================================================
Object Summary: 
===============================================================================

-------------------------------------------------------------------------------
# Section: Unix File System
-------------------------------------------------------------------------------

No violations.

===============================================================================
Error Report: 
===============================================================================

No Errors

-------------------------------------------------------------------------------
*** End of report ***

Clone this wiki locally