業務用エアコン関連の技術情報、エラーコード、環境問題対策に関する別サイト「エアコンの安全な修理・適切なフロン回収」

OracleLinux9.8 : Tripwire , Logwatch , DNS Update, Disk Usage Check Script

Tripwire

1.Install

# dnf -y install tripwire
Installed:
  tripwire-2.4.3.7-16.el9.x86_64

Complete!

2.Passphrase setting

Set site passphrase and local passphrase

# tripwire-setup-keyfiles

------------------------------------------------
The Tripwire site and local passphrases are used to sign a variety of
files, such as the configuration, policy, and database files.

Passphrases should be at least 8 characters in length and contain both
letters and numbers.

See the Tripwire manual for more information.
------------------------------------------------
Creating key files…

(When selecting a passphrase, keep in mind that good passphrases typically
have upper and lower case letters, digits and punctuation marks, and are
at least 8 characters in length.)

Enter the site keyfile passphrase: [site pass]
Verify the site keyfile passphrase: [site pass]
Generating key (this may take several minutes)…Key generation complete.

(When selecting a passphrase, keep in mind that good passphrases typically
have upper and lower case letters, digits and punctuation marks, and are
at least 8 characters in length.)

Enter the local keyfile passphrase: [local pass]
Verify the local keyfile passphrase: [local pass]
Generating key (this may take several minutes)…Key generation complete.

------------------------------------------------
Signing configuration file…
Please enter your site passphrase: [site pass]
Wrote configuration file: /etc/tripwire/tw.cfg

A clear-text version of the Tripwire configuration file:
/etc/tripwire/twcfg.txt
has been preserved for your inspection. It is recommended that you
move this file to a secure location and/or encrypt it in place (using a
tool such as GPG, for example) after you have examined it.

------------------------------------------------
Signing policy file…
Please enter your site passphrase: [site pass]
Wrote policy file: /etc/tripwire/tw.pol

A clear-text version of the Tripwire policy file:
/etc/tripwire/twpol.txt
has been preserved for your inspection. This implements a minimal
policy, intended only to test essential Tripwire functionality. You
should edit the policy file to describe your system, and then use
twadmin to generate a new signed copy of the Tripwire policy.

Once you have a satisfactory Tripwire policy file, you should move the
clear-text version to a secure location and/or encrypt it in place
(using a tool such as GPG, for example).

Now run "tripwire --init" to enter Database Initialization Mode. This
reads the policy file, generates a database based on its contents, and
then cryptographically signs the resulting database. Options can be
entered on the command line to specify which policy, configuration, and
key files are used to create the database. The filename for the
database can be specified as well. If no options are specified, the
default values from the current configuration file are used.

3.Tripwire Configuration

Configuration File Edit

# vi /etc/tripwire/twcfg.txt

Line 9 :
Change to "LOOSEDIRECTORYCHECKING = true"

Line 12 : change
Level 4 provides the most detailed report of the five levels from "0" to "4".
REPORTLEVEL =4

Create a Tripwire configuration file (cryptographically signed version)

# twadmin -m F -c /etc/tripwire/tw.cfg -S /etc/tripwire/site.key /etc/tripwire/twcfg.txt
Please enter your site passphrase: ←site pass
Wrote configuration file: /etc/tripwire/tw.cfg

Delete Tripwire configuration file (text version)

# rm -f /etc/tripwire/twcfg.txt

Policy File Settings

# cd /etc/tripwire/
# vi twpolmake.pl

Contents of twpolmake.pl

#!/usr/bin/perl
#
$POLFILE=$ARGV[0];

open(POL,"$POLFILE") or die "open error: $POLFILE" ;
my($myhost,$thost) ;
my($sharp,$tpath,$cond) ;
my($INRULE) = 0 ;

while (<POL>) {
chomp;
if (($thost) = /^HOSTNAME\s*=\s*(.*)\s*;/) {
$myhost = `hostname` ; chomp($myhost) ;
if ($thost ne $myhost) {
$_="HOSTNAME=\"$myhost\";" ;
}
}
elsif ( /^{/ ) {
$INRULE=1 ;
}
elsif ( /^}/ ) {
$INRULE=0 ;
}
elsif ($INRULE == 1 and ($sharp,$tpath,$cond) = /^(\s*\#?\s*)(\/\S+)\b(\s+->\s+.+)$/) {
$ret = ($sharp =~ s/\#//g) ;
if ($tpath eq '/sbin/e2fsadm' ) {
$cond =~ s/;\s+(tune2fs.*)$/; \#$1/ ;
}
if (! -s $tpath) {
$_ = "$sharp#$tpath$cond" if ($ret == 0) ;
}
else {
$_ = "$sharp$tpath$cond" ;
}
}
print "$_\n" ;
}
close(POL) ;

Policy File Optimizations

# perl /etc/tripwire/twpolmake.pl /etc/tripwire/twpol.txt > /etc/tripwire/twpol.txt.new

Create policy file (cryptographically signed version) based on optimized policy file

# twadmin -m P -c /etc/tripwire/tw.cfg -p /etc/tripwire/tw.pol -S /etc/tripwire/site.key /etc/tripwire/twpol.txt.new

Please enter your site passphrase: ←site pass
Wrote policy file: /etc/tripwire/tw.pol

Create database and check operation

# tripwire -m i -s -c /etc/tripwire/tw.cfg
Please enter your local passphrase: ←local pass

Create test files

# echo test > /root/test.txt

Check Tripwire operation

# tripwire -m c -s -c /etc/tripwire/tw.cfg

If it displays as shown below, it's OK.

Open Source Tripwire(R) 2.4.3.7 Integrity Check Report

Report generated by:          root
Report created on:            Sat 22 Aug 2026 11:08:03 AM JST
Database last updated on:     Never

===============================================================================
Report Summary:
===============================================================================

Host name:                    Lepard
Host IP address:              192.168.11.83
Host ID:                      None
Policy file used:             /etc/tripwire/tw.pol
Configuration file used:      /etc/tripwire/tw.cfg
Database file used:           /var/lib/tripwire/Lepard.twd
Command line used:            tripwire -m c -s -c /etc/tripwire/tw.cfg

===============================================================================
Rule Summary:
===============================================================================

-------------------------------------------------------------------------------
  Section: Unix File System
-------------------------------------------------------------------------------

  Rule Name                       Severity Level    Added    Removed  Modified
  ---------                       --------------    -----    -------  --------
  User binaries                   66                0        0        0
  Tripwire Binaries               100               0        0        0
  Libraries                       66                0        0        0
  Operating System Utilities      100               0        0        0
  File System and Disk Administraton Programs
                                  100               0        0        0
  Kernel Administration Programs  100               0        0        0
  Networking Programs             100               0        0        0
  System Administration Programs  100               0        0        0
  Hardware and Device Control Programs
                                  100               0        0        0
  System Information Programs     100               0        0        0
  (/sbin/runlevel)
  Application Information Programs
                                  100               0        0        0
  (/sbin/rtmon)
  Critical Utility Sym-Links      100               0        0        0
  Shell Binaries                  100               0        0        0
  Critical system boot files      100               0        0        0
* Tripwire Data Files             100               1        0        0
  System boot changes             100               0        0        0
  OS executables and libraries    100               0        0        0
  Security Control                100               0        0        0
  Login Scripts                   100               0        0        0
  Critical configuration files    100               0        0        0
* Root config files               100               1        0        0
  Invariant Directories           66                0        0        0
  Temporary directories           33                0        0        0
  Critical devices                100               0        0        0

Total objects scanned:  73319
Total violations found:  2

===============================================================================
Object Summary:
===============================================================================

-------------------------------------------------------------------------------
# Section: Unix File System
-------------------------------------------------------------------------------

-------------------------------------------------------------------------------
Rule Name: Tripwire Data Files (/var/lib/tripwire)
Severity Level: 100
-------------------------------------------------------------------------------

Added:
"/var/lib/tripwire/Lepard.twd"

-------------------------------------------------------------------------------
Rule Name: Root config files (/root)
Severity Level: 100
-------------------------------------------------------------------------------

Added:
"/root/test.txt"

===============================================================================
Error Report:
===============================================================================

No Errors

-------------------------------------------------------------------------------
*** End of report ***

Open Source Tripwire 2.4 Portions copyright 2000-2018 Tripwire, Inc.  Tripwire is a registered
trademark of Tripwire, Inc. This software comes with ABSOLUTELY NO WARRANTY;
for details use --version. This is free software which may be redistributed
or modified only under certain conditions; see COPYING for details.
All rights reserved.

Delete test files

# rm -f /root/test.txt

Create a script for reporting results via email

# cd /var/www/system
# vi tripwire.sh
Contents of tripwire.sh

#!/bin/bash

PATH=/usr/sbin:/usr/bin:/bin:/usr/local/tripwire/sbin

#Passphrase Setup
LOCALPASS=xxxxx # local pass
SITEPASS=xxxxx # site pass

#Specify notification email address
MAIL="[your mail address] "

cd /etc/tripwire

#Tripwire Check Execution
tripwire -m c -s -c tw.cfg|mail -s "Tripwire(R) Integrity Check Report in `hostname`" $MAIL

#Policy File Update
twadmin -m p -c tw.cfg -p tw.pol -S site.key > twpol.txt
perl twpolmake.pl twpol.txt > twpol.txt.new
twadmin -m P -c tw.cfg -p tw.pol -S site.key -Q $SITEPASS twpol.txt.new > /dev/null
rm -f twpol.txt* *.bak

#Database Update
rm -f /usr/local/tripwire/lib/tripwire/*.twd*
tripwire -m i -s -c tw.cfg -P $LOCALPASS

# chmod 700 tripwire.sh

Add to cron
# crontab -e
0 3 * * * /var/www/system/tripwire.sh

Confirmation that the results of the tripwire execution are notified to the specified e-mail address

# /var/www/system/tripwire.sh

Logwatch

Install

# dnf -y install logwatch

Edit configuration file

# cat /usr/share/logwatch/default.conf/logwatch.conf >> /etc/logwatch/conf/logwatch.conf

# vi /etc/logwatch/conf/logwatch.conf

Line 51  : Comment
#MailTo = root

Line 52 : Add
MailTo = [mail address]

Per Line 84 : Set the level of detail for log notifications
#Detail = Low
Detail = High

Output Logwatch reports

# logwatch --output stdout

It will appear as follows

 ################### Logwatch 7.5.5 (01/22/21) ####################
        Processing Initiated: Sat Aug 22 11:15:45 2026
        Date Range Processed: yesterday
                              ( 2026-Aug-21 )
                              Period is day.
        Detail Level of Output: 10
        Type of Output/Format: stdout / text
        Logfiles for Host: Lepard
 ##################################################################

 --------------------- Kernel Audit Begin ------------------------

  Number of audit daemon starts: 2

  Number of audit initializations: 2

 **Unmatched Entries**
    auditd[811]: audit dispatcher initialized with q_depth=2000 and 1 active plugins: 2 Time(s)

 ---------------------- Kernel Audit End -------------------------

---------------------------------------------------omitted----------------------------------------------------

 --------------------- lm_sensors output Begin ------------------------

 nvme-pci-0b00
 Adapter: PCI adapter
 Composite:    +29.9 C


 ---------------------- lm_sensors output End -------------------------


 ###################### Logwatch End #########################

Test to see if the report arrives at the address you set. Check if you receive a log report email like the one above.

# /etc/cron.daily/0logwatch

DNS Update

Whenever the internet connection is lost or the router reboots, causing the global IP address to change, you must access the dynamic DNS service to notify it of the IP address change.

Create a dedicated Python file and schedule it for regular execution via Cron.
This time, it's about DNS settings on Valudomain.

# cd /var/www/system
# vi ddnsset.py

Contents of ddnset.py

#setddns.py
import requests
import ipaddress
from datetime import datetime
from pathlib import Path

# SETTING DATA
MY_DOMAIN = "example.jp"  ←Self-hosted domain
MY_PASS = "xxxxxxxxxx" ←Password
MY_HOSTNAME = "xxxx" ←Hostname
OUT_FILE = Path("/tmp/ipadress") ←IP Address Log File

def time_msg():
    now = datetime.now()
    return now.strftime("%Y/%m/%d %H:%M:%S")

def is_valid_ip(ip_str):
    try:
        ipaddress.ip_address(ip_str)
        return True
    except ValueError:
        return False

def main():
    # Check Global IP Address
    url_get_ip = "https://dyn.value-domain.com/cgi-bin/dyn.fcg?ip"
    try:
        response = requests.get(url_get_ip, timeout=10)
        response.raise_for_status()
        current_ip = response.text.strip()
    except requests.RequestException as e:
        print(f"{time_msg()} Failed to get IP: {e}")
        return

    # IP check
    mssg = time_msg()
    if not current_ip:
        print(f"{mssg} invalid IP NULL")
        return

    if not is_valid_ip(current_ip):
        print(f"{mssg} invalid IP={current_ip}")
        return

    # Read previous IP
    previous_ip = ""
    if OUT_FILE.exists():
        with open(OUT_FILE, "r") as f:
            previous_ip = f.read().strip()

    if current_ip == previous_ip:
        print(f"{time_msg()} no change IP={current_ip}")
        return
    else:
        print(f"change IP from {previous_ip} to {current_ip}")

    # Update DDNS
    mssg = time_msg()
    print(f"{mssg} access to value-domain")

    url_set_ddns = (
        f"https://dyn.value-domain.com/cgi-bin/dyn.fcg?"
        f"d={MY_DOMAIN}&p={MY_PASS}&h={MY_HOSTNAME}"
    )

    try:
        response = requests.get(url_set_ddns, timeout=10)
        response.raise_for_status()
        # Convert line breaks to spaces and consolidate consecutive spaces into a single space.
        result = ' '.join(response.text.strip().split())
    except requests.RequestException as e:
        print(f"{time_msg()} Failed to update DDNS: {e}")
        return

    mssg = time_msg()
    print(f"{mssg} {MY_HOSTNAME}.{MY_DOMAIN} {result} IP={current_ip}")

    # Only save the IP address if the DDNS update is successful.
    if "status=0" in result:
        with open(OUT_FILE, "w") as f:
            f.write(current_ip)
        print(f"{mssg} Successfully saved new IP: {current_ip}")
    else:
        print(f"{mssg} DDNS update failed, IP not saved")

if __name__ == "__main__":
    main()

IP Address Log File Creation

# touch /tmp/ipadress

Run periodically

# crontab -e

* 00 * * * /usr/bin/python3 /var/www/system/ddnsset.py >> /var/log/ddns_updater.log 2>&1

Introduce disk usage check script

1. Script Creation

# cd /var/www/system
# vi disk_capacity_check.sh

Contents of disk_capacity_check.sh

#!/bin/bash

#Designation of e-mail address to be notified
MAIL="<your mailaddress>"

DVAL=`/bin/df / | /usr/bin/tail -1 | /bin/sed 's/^.* \([0-9]*\)%.*$/\1/'`

if [ $DVAL -gt 80 ]; then
echo "Disk usage alert: $DVAL %" | mail -s "Disk Space Alert in `hostname`" $MAIL
fi
# chmod 700 disk_capacity_check.sh

2. Execution Confirmation

①Check current usage rates

# df -h

It appears as follows

Filesystem           Size  Used Avail Use% Mounted on
devtmpfs             4.0M     0  4.0M   0% /dev
tmpfs                1.7G     0  1.7G   0% /dev/shm
tmpfs                692M  9.2M  683M   2% /run
efivarfs             256K   81K  171K  33% /sys/firmware/efi/efivars
/dev/mapper/ol-root   35G   11G   25G  30% /
/dev/loop2           128K  128K     0 100% /var/lib/snapd/snap/hello-world/29
/dev/loop5            74M   74M     0 100% /var/lib/snapd/snap/core22/2437
/dev/loop4           106M  106M     0 100% /var/lib/snapd/snap/core/17292
/dev/loop3            74M   74M     0 100% /var/lib/snapd/snap/certbot/5781
/dev/loop0            51M   51M     0 100% /var/lib/snapd/snap/snapd/27710
/dev/loop1            67M   67M     0 100% /var/lib/snapd/snap/core24/1643
/dev/nvme0n1p2       960M  531M  430M  56% /boot
/dev/nvme0n1p1       599M  7.7M  592M   2% /boot/efi
tmpfs                346M  8.0K  346M   1% /run/user/1000

②Create a dummy file to achieve at least 80% utilization(In the example, a file named dummyfile with a size of about 19GB)

# dd if=/dev/zero of=dummyfile bs=1M count=19000

③check again
Verify that it is at least 80% by performing the following:

# df -h

④Run check scripts

# /var/www/system/disk_capacity_check.sh

You will receive an email to the email address you have set up, stating something like "Disk usage alert: 84 %".

⑤Delete "dummyfile"

# rm -f dummyfile

⑥Periodic Execution Setting

# crontab -e
Add the following
30 2 * * * /var/www/system/disk_capacity_check.sh