Tripwire
1.Install
# dnf -y install tripwire
Installed:
tripwire-2.4.3.7-20.el10_2.x86_64
Complete!
2.Passphrase setting
Set site passphrase and local passphrase
# tripwire-setup-keyfiles
------------------------------------------------
The Tripwire site and local passphrases are used to sign a variety of
files, such as the configuration, policy, and database files.
Passphrases should be at least 8 characters in length and contain both
letters and numbers.
See the Tripwire manual for more information.
------------------------------------------------
Creating key files…
(When selecting a passphrase, keep in mind that good passphrases typically
have upper and lower case letters, digits and punctuation marks, and are
at least 8 characters in length.)
Enter the site keyfile passphrase: [site pass]
Verify the site keyfile passphrase: [site pass]
Generating key (this may take several minutes)…Key generation complete.
(When selecting a passphrase, keep in mind that good passphrases typically
have upper and lower case letters, digits and punctuation marks, and are
at least 8 characters in length.)
Enter the local keyfile passphrase: [local pass]
Verify the local keyfile passphrase: [local pass]
Generating key (this may take several minutes)…Key generation complete.
------------------------------------------------
Signing configuration file…
Please enter your site passphrase: [site pass]
Wrote configuration file: /etc/tripwire/tw.cfg
A clear-text version of the Tripwire configuration file:
/etc/tripwire/twcfg.txt
has been preserved for your inspection. It is recommended that you
move this file to a secure location and/or encrypt it in place (using a
tool such as GPG, for example) after you have examined it.
------------------------------------------------
Signing policy file…
Please enter your site passphrase: [site pass]
Wrote policy file: /etc/tripwire/tw.pol
A clear-text version of the Tripwire policy file:
/etc/tripwire/twpol.txt
has been preserved for your inspection. This implements a minimal
policy, intended only to test essential Tripwire functionality. You
should edit the policy file to describe your system, and then use
twadmin to generate a new signed copy of the Tripwire policy.
Once you have a satisfactory Tripwire policy file, you should move the
clear-text version to a secure location and/or encrypt it in place
(using a tool such as GPG, for example).
Now run "tripwire --init" to enter Database Initialization Mode. This
reads the policy file, generates a database based on its contents, and
then cryptographically signs the resulting database. Options can be
entered on the command line to specify which policy, configuration, and
key files are used to create the database. The filename for the
database can be specified as well. If no options are specified, the
default values from the current configuration file are used.
3.Tripwire Configuration
① Configuration File Edit
# vi /etc/tripwire/twcfg.txt
Line 9 : Change
LOOSEDIRECTORYCHECKING =true
Line 12 : Change(Setting the level to 4 will display the most detailed report out of the five levels ranging from "0" to "4.")
REPORTLEVEL =4
② Create a Tripwire configuration file (cryptographically signed version)
# twadmin -m F -c /etc/tripwire/tw.cfg -S /etc/tripwire/site.key /etc/tripwire/twcfg.txt
Please enter your site passphrase: ←site pass
Wrote configuration file: /etc/tripwire/tw.cfg
③ Delete Tripwire configuration file (text version)
# rm -f /etc/tripwire/twcfg.txt
④ Policy File Settings
# cd /etc/tripwire/
# vi twpolmake.pl
Contents of twpolmake.pl
#!/usr/bin/perl
#
$POLFILE=$ARGV[0];
open(POL,"$POLFILE") or die "open error: $POLFILE" ;
my($myhost,$thost) ;
my($sharp,$tpath,$cond) ;
my($INRULE) = 0 ;
while (<POL>) {
chomp;
if (($thost) = /^HOSTNAME\s*=\s*(.*)\s*;/) {
$myhost = `hostname` ; chomp($myhost) ;
if ($thost ne $myhost) {
$_="HOSTNAME=\"$myhost\";" ;
}
}
elsif ( /^{/ ) {
$INRULE=1 ;
}
elsif ( /^}/ ) {
$INRULE=0 ;
}
elsif ($INRULE == 1 and ($sharp,$tpath,$cond) = /^(\s*\#?\s*)(\/\S+)\b(\s+->\s+.+)$/) {
$ret = ($sharp =~ s/\#//g) ;
if ($tpath eq '/sbin/e2fsadm' ) {
$cond =~ s/;\s+(tune2fs.*)$/; \#$1/ ;
}
if (! -s $tpath) {
$_ = "$sharp#$tpath$cond" if ($ret == 0) ;
}
else {
$_ = "$sharp$tpath$cond" ;
}
}
print "$_\n" ;
}
close(POL) ;
⑤ Policy File Optimizations
# perl /etc/tripwire/twpolmake.pl /etc/tripwire/twpol.txt > /etc/tripwire/twpol.txt.new
⑥ Create policy file (cryptographically signed version) based on optimized policy file
# twadmin -m P -c /etc/tripwire/tw.cfg -p /etc/tripwire/tw.pol -S /etc/tripwire/site.key /etc/tripwire/twpol.txt.new
Please enter your site passphrase: ←site pass
⑦ Create database and check operation
# tripwire -m i -s -c /etc/tripwire/tw.cfg
Please enter your local passphrase: ←local pass
Create test files
# echo test > /root/test.txt
Check Tripwire operation
# tripwire -m c -s -c /etc/tripwire/tw.cfg
It is displayed as shown below
Open Source Tripwire(R) 2.4.3.7 Integrity Check Report
Report generated by: root
Report created on: Sun 19 Jul 2026 04:44:40 PM JST
Database last updated on: Never
===============================================================================
Report Summary:
===============================================================================
(Omitted)
-------------------------------------------------------------------------------
Added:
"/root/test.txt"
===============================================================================
Error Report:
===============================================================================
No Errors
-------------------------------------------------------------------------------
*** End of report ***
Open Source Tripwire 2.4 Portions copyright 2000-2018 Tripwire, Inc. Tripwire is a registered
trademark of Tripwire, Inc. This software comes with ABSOLUTELY NO WARRANTY;
for details use --version. This is free software which may be redistributed
or modified only under certain conditions; see COPYING for details.
All rights reserved.
Delete test files
# rm -f /root/test.txt
⑧ Creating a Tripwire Script for Reporting Results via Email
# cd /var/www/system
# vi tripwire.sh
Contents of tripwire.sh
#!/bin/bash
PATH=/usr/sbin:/usr/bin:/bin:/usr/local/tripwire/sbin
# Passphrase setting
LOCALPASS=xxxxx # local pass
SITEPASS=xxxxx # site pass
#Specify e-mail address for notification
MAIL="your mailaddress "
cd /etc/tripwire
# Tripwire check run
tripwire -m c -s -c tw.cfg|mail -s "Tripwire(R) Integrity Check Report in `hostname`" $MAIL
# Policy File Update
twadmin -m p -c tw.cfg -p tw.pol -S site.key > twpol.txt
perl twpolmake.pl twpol.txt > twpol.txt.new
twadmin -m P -c tw.cfg -p tw.pol -S site.key -Q $SITEPASS twpol.txt.new > /dev/null
rm -f twpol.txt* *.bak
# Database update
rm -f /usr/local/tripwire/lib/tripwire/*.twd*
tripwire -m i -s -c tw.cfg -P $LOCALPASS
# chmod 700 tripwire.sh
Set it up in cron to run periodically
# crontab -e
0 3 * * * /var/www/system/tripwire.sh
Confirmation that the results of the tripwire execution are notified to the specified e-mail address
# /var/www/system/tripwire.sh
Logwatch
Logwatch is a tool that analyzes various log files and presents the logs in an easy-to-read format.
Once installed, it will be registered as a Cron job and run daily. You can also have the results sent to you via email.
①Install
# dnf -y install logwatch
②Edit configuration file
# cat /usr/share/logwatch/default.conf/logwatch.conf >> /etc/logwatch/conf/logwatch.conf
# vi /etc/logwatch/conf/logwatch.conf
Per Line 77 : Add an email address to receive results notifications
#MailTo = root
MailTo = [mail address]
Per Line 116 : Set the log notification detail level
#Detail = Low
Detail = High
③Output Logwatch reports
# logwatch --output stdout
It will appear as follows
################### Logwatch 7.11 (07/22/24) ####################
Processing Initiated: Sun Jul 19 17:03:26 2026
Date Range Processed: yesterday
( 2026-Jul-18 )
Period is day.
Detail Level of Output: 10
Type of Output/Format: stdout / text
Logfiles for Host: Lepard
##################################################################
--------------------- Kernel Audit Begin ------------------------
Number of audit daemon starts: 1
Number of audit initializations: 1
**Unmatched Entries**
auditd[1048]: audit dispatcher initialized with q_depth=2000 and 1 active plugins: 1 Time(s)
---------------------- Kernel Audit End -------------------------
----------------------------------(Omitted)--------------------------------------------
--------------------- Disk Space Begin ------------------------
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/ol-root 34G 9.0G 25G 27% /
efivarfs 256K 81K 171K 33% /sys/firmware/efi/efivars
/dev/nvme0n1p2 2.0G 434M 1.6G 22% /boot
/dev/nvme0n1p1 599M 9.1M 590M 2% /boot/efi
---------------------- Disk Space End -------------------------
--------------------- lm_sensors output Begin ------------------------
nvme-pci-0b00
Adapter: PCI adapter
Composite: +29.9 C
---------------------- lm_sensors output End -------------------------
###################### Logwatch End #########################
④Test to see if the report arrives at the address you set. Check if you receive a log report email like the one above.
# /etc/cron.daily/0logwatch
DNS Update
Each time the global IP changes, which happens when the network is disconnected or the router disconnects and reboots, the dynamic DNS must be accessed to inform the user that the global IP has changed.
DiCE used to handle that task automatically, but since Oracle Linux 10 no longer supports 32-bit software, I created a dedicated Python script and set it to run periodically via Cron (in this case, for DNS configuration on Valudomain).
# cd /var/www/system
# vi ddnsset.py
Contents of ddnsset.py
#setddns.py
import requests
import ipaddress
from datetime import datetime
from pathlib import Path
# SETTING DATA
MY_DOMAIN = "example.jp" ←your domain
MY_PASS = "xxxxxxxxxx" ←password
MY_HOSTNAME = "xxxx" ←host
OUT_FILE = Path("/tmp/ipadress") ←IP Address Log File
def time_msg():
now = datetime.now()
return now.strftime("%Y/%m/%d %H:%M:%S")
def is_valid_ip(ip_str):
try:
ipaddress.ip_address(ip_str)
return True
except ValueError:
return False
def main():
# Check Global IP Address
url_get_ip = "https://dyn.value-domain.com/cgi-bin/dyn.fcg?ip"
try:
response = requests.get(url_get_ip, timeout=10)
response.raise_for_status()
current_ip = response.text.strip()
except requests.RequestException as e:
print(f"{time_msg()} Failed to get IP: {e}")
return
# IP check
mssg = time_msg()
if not current_ip:
print(f"{mssg} invalid IP NULL")
return
if not is_valid_ip(current_ip):
print(f"{mssg} invalid IP={current_ip}")
return
# Read previous IP
previous_ip = ""
if OUT_FILE.exists():
with open(OUT_FILE, "r") as f:
previous_ip = f.read().strip()
if current_ip == previous_ip:
print(f"{time_msg()} no change IP={current_ip}")
return
else:
print(f"change IP from {previous_ip} to {current_ip}")
# Update DDNS
mssg = time_msg()
print(f"{mssg} access to value-domain")
url_set_ddns = (
f"https://dyn.value-domain.com/cgi-bin/dyn.fcg?"
f"d={MY_DOMAIN}&p={MY_PASS}&h={MY_HOSTNAME}"
)
try:
response = requests.get(url_set_ddns, timeout=10)
response.raise_for_status()
#Convert line breaks to spaces, and merge consecutive spaces into a single space
result = ' '.join(response.text.strip().split())
except requests.RequestException as e:
print(f"{time_msg()} Failed to update DDNS: {e}")
return
mssg = time_msg()
print(f"{mssg} {MY_HOSTNAME}.{MY_DOMAIN} {result} IP={current_ip}")
# Save the IP address only if the DDNS update is successful
if "status=0" in result:
with open(OUT_FILE, "w") as f:
f.write(current_ip)
print(f"{mssg} Successfully saved new IP: {current_ip}")
else:
print(f"{mssg} DDNS update failed, IP not saved")
if __name__ == "__main__":
main()
Creating an IP Address Log File
# touch /tmp/ipadress
Run periodically
# crontab -e
* 00 * * * /usr/bin/python3 /var/www/system/ddnsset.py >> /var/log/ddns_updater.log 2>&1
Introduce disk usage check script
1. Script Creation
# cd /var/www/system
# vi disk_capacity_check.sh
Contents of disk_capacity_check.sh
#!/bin/bash
#Designation of e-mail address to be notified
MAIL="your mailaddress"
DVAL=`/bin/df / | /usr/bin/tail -1 | /bin/sed 's/^.* \([0-9]*\)%.*$/\1/'`
if [ $DVAL -gt 80 ]; then
echo "Disk usage alert: $DVAL %" | mail -s "Disk Space Alert in `hostname`" $MAIL
fi
# chmod 700 disk_capacity_check.sh
2. Execution Confirmation
①Check current usage rates
# df -h
It appears as follows
Filesystem Size Used Avail Use% Mounted on
/dev/mapper/ol-root 34G 8.9G 25G 27% /
devtmpfs 4.0M 0 4.0M 0% /dev
tmpfs 1.7G 0 1.7G 0% /dev/shm
efivarfs 256K 81K 171K 33% /sys/firmware/efi/efivars
tmpfs 692M 9.2M 683M 2% /run
tmpfs 1.0M 0 1.0M 0% /run/credentials/systemd-journald.service
/dev/loop0 51M 51M 0 100% /var/lib/snapd/snap/snapd/27406
/dev/loop2 67M 67M 0 100% /var/lib/snapd/snap/core24/1643
/dev/loop1 74M 74M 0 100% /var/lib/snapd/snap/certbot/5758
/dev/nvme0n1p2 2.0G 434M 1.6G 22% /boot
/dev/nvme0n1p1 599M 9.1M 590M 2% /boot/efi
tmpfs 1.0M 0 1.0M 0% /run/credentials/getty@tty1.service
tmpfs 346M 16K 346M 1% /run/user/1000
②Create a dummy file to achieve at least 80% utilization(In the example, it is called "dummyfile" and is about 20G)
# dd if=/dev/zero of=dummyfile bs=1M count=20000
③check again
Confirm that it is above 80% by performing the following
# df -h
④Run check scripts
# /var/www/system/disk_capacity_check.sh
You will receive an email to the email address you have set up, stating something like "Disk usage alert: 86 %".
⑤Delete "dummyfile"
# rm -f dummyfile
⑥Periodic Execution Setting
# crontab -e
Add the following
30 2 * * * /var/www/system/disk_capacity_check.sh
