store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Mon May 20, 2013 1:11 pm

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 
Author Message
 Post subject: RLIMIT_NOFILE
Unread postPosted: Mon May 07, 2012 2:33 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Hello All,

I have just noticed these grsec messages appearing in /var/log/message every 10 sec.

May 7 20:14:37 sa1 kernel: grsec: denied resource overstep by requesting 1024 for RLIMIT_NOFILE against limit 1024 for /var/ossec/bin/ossec-syscheckd[ossec-syscheckd:3135] uid/euid:0/0 gid/egid:0/0, parent /sbin/init[init:1] uid/euid:0/0 gid/egid:0/0
May 7 20:14:37 sa1 kernel: grsec: more alerts, logging disabled for 10 seconds

Any thoughts?

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
 Post subject: Re: RLIMIT_NOFILE
Unread postPosted: Mon May 07, 2012 3:12 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Thanks for the question. Unlike a vanilla kernel which will leave you guessing, the ASL kernel will report when an OS defined system has been exceeded. A vanilla kernel wouldnt tell you this was happening (it would still happen, you just would have a much harder time figuring that you hit that limit, why vanilla kernels dont tell you this is a mystery to me).

Anyway, neither the ASL nor a vanilla kernel sets these limits, not do they enforce them. The ASL kernel is just doing you a favor and just telling you that you have something exceeding that limit. RLIMIT_NOFILE, if memory serves, default is 1024 so just raise that.

With that said, check to make sure all your ASL components, and the kernel are up to date. Thats limiting the files that syscheckd can open, which normally wouldnt be that high. So that can either be a bug that was fixed some time ago, or syscheckd is checking a LOT of files on your system and the OS is constraining it, which may be a good thing - it could be misconfigured and is doing more work than it needs to.

So first, check to make sure everything is patched and up to date on the box. Whats the output of:

yum upgrade

(Dont hit y, just want to know what might be missing from the box)

What version of asl is installed

asl -v

And what kernel

uname -a

If its all up to date, then that sounds like there may be a configuration issue on your machine where syscheckd is doing too much work. We can tackle that next once we ensure everything is up to date.

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: RLIMIT_NOFILE
Unread postPosted: Mon May 07, 2012 3:32 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Hello Mike,

Thanks for the speedy reply.

yum upgrade
275 packages excluded due to repository priority protections
Setting up Upgrade Process
No Packages marked for Update

asl -v
ASL Version 3.0.22: CentOS 6 (SUPPORTED)

uname -a
Linux 2.6.32.59-17.art.x86_64 #1 SMP Mon Apr 9 17:25:09 EDT 2012 x86_64 x86_64 x86_64 GNU/Linux

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
 Post subject: Re: RLIMIT_NOFILE
Unread postPosted: Mon May 07, 2012 4:59 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3243
Location: Chantilly, VA
Hmm, that sounds like a configuration or local status issue. Can you send your ossec.log file to support?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: RLIMIT_NOFILE
Unread postPosted: Mon May 07, 2012 5:23 pm 
Offline
Forum Regular
Forum Regular

Joined: Sat Dec 11, 2004 2:33 pm
Posts: 195
Location: South Africa
Thanks Mike,

I have sent an email to support as requested.

_________________
Mark Brindley
2Large Networks - Web solutions that work


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 5 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group