SV-208800r603263_rule
V-208800
SRG-OS-000480
OL6-00-000018
CAT II
10
Run the following command to generate a new database:
# /usr/sbin/aide --init
By default, the database will be written to the file "/var/lib/aide/aide.db.new.gz". Storing the database, the configuration file "/etc/aide.conf", and the binary "/usr/sbin/aide" (or hashes of these files), in a secure location (such as on read-only media) provides additional assurance about their integrity. The newly-generated database can be installed as follows:
# cp /var/lib/aide/aide.db.new.gz /var/lib/aide/aide.db.gz
To initiate a manual check, run the following command:
# /usr/sbin/aide --check
If this check produces any unexpected output, investigate.
To find the location of the AIDE database file, run the following command:
# grep DBDIR /etc/aide.conf
Using the defined values of the [DBDIR] and [database] variables, verify the existence of the AIDE database file:
# ls -l [DBDIR]/[database_file_name]
If there is no database file, this is a finding.
V-208800
False
OL6-00-000018
To find the location of the AIDE database file, run the following command:
# grep DBDIR /etc/aide.conf
Using the defined values of the [DBDIR] and [database] variables, verify the existence of the AIDE database file:
# ls -l [DBDIR]/[database_file_name]
If there is no database file, this is a finding.
M
2928