store | blogs | forums | twitter | facebook | wiki | mailing lists | downloads | support portal
Atomic Secure Linux
It is currently Wed Jun 19, 2013 11:56 am

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]




Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 
Author Message
 Post subject: ASL supported in Parallels HSphere.
Unread postPosted: Thu Nov 17, 2011 12:57 pm 
Offline
New Forum User
New Forum User

Joined: Thu Nov 17, 2011 12:49 pm
Posts: 3
Location: London
Is ASL subscription rules supported for use in Parallels HSphere http://hsphere.parallels.com/docs/3.5.0 ... /16878.htm they refer to the gotroot mod_security rules which I presume are the free ones, but installing ASL is this the same thing as the mod_sec rules they refer to hence supported or not?

Sorry if I am unclear.

Thanks in advance.

Mark


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Thu Nov 17, 2011 2:18 pm 
Offline
Forum Regular
Forum Regular

Joined: Mon Apr 10, 2006 12:55 pm
Posts: 656
gotroot is the free ruleset, derived from ASL. They are 90 days delayed.

_________________
"Its not a mac. I run linux... I'm actually cool." - scott


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Thu Nov 17, 2011 6:53 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
That looks like Apache 1.x. Is that what hsphere uses, Apache 1? Or does it support Apache 2?

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Fri Nov 18, 2011 7:33 am 
Offline
New Forum User
New Forum User

Joined: Thu Nov 17, 2011 12:49 pm
Posts: 3
Location: London
Hi Mike,

Thanks for the reply. Yes - it does support both Apache 1.x and 2.x - my particular web servers are running 2.x as Hsphere can cater for different configs on different servers given its a cluster solution.

As per the HSphere documentation:

"At the moment, the following Gotroot rules are supported (the list may differ for Apache 1.x and 2.x, modsecurity 1.9 and 2.0-2.1 versions):
•apache2-rules
•badips
•blacklist2
•blacklist
•exclude
•jitp
•proxy
•recons
•rootkits
•rules
•useragents"


Kind Regards,

Mark


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Fri Nov 18, 2011 3:31 pm 
Offline
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
User avatar

Joined: Thu Feb 07, 2008 7:49 pm
Posts: 3264
Location: Chantilly, VA
Thank you for the clarification. So for Apache 2.x the rules should work just fine. ASL should work as well with Hsphere (provided you are using Apache 2.x), but we havent tested hsphere with ASL.

Apache 1.x isnt supported anymore as modsecurity for Apache 1.x was end of lifed many years ago - so I wouldnt recommend anyone use Apache 1.x and modsecurity.

With that said, if you want to just use the gotroot rules, make sure you follow the process for configuring your system at the URL below:

https://www.atomicorp.com/wiki/index.ph ... rity_Rules

Third party implementations/configurations are not supported.

Or, just install ASL:

https://www.atomicorp.com/products/asl.html

_________________
Michael Shinn
Atomicorp - Security For Everyone

Co-Author of Troubleshooting Linux Firewalls.


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Fri Nov 18, 2011 3:57 pm 
Offline
New Forum User
New Forum User

Joined: Thu Nov 17, 2011 12:49 pm
Posts: 3
Location: London
Hi Mike,

I'll try it out on my dev cluster - which is basically RHEL with Apache 2.x and let you know how I go.

thanks,

Mark


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Tue Jul 10, 2012 5:18 pm 
Offline
Forum User
Forum User
User avatar

Joined: Wed Jul 04, 2012 7:44 am
Posts: 23
Location: Costa Rica
Any news on this?
I'm also interested in ASL for our HSphere servers.
Thanks,

_________________
Rodrigo Fernández
Image
http://www.crservers.com


Top
 Profile  
 
 Post subject: Re: ASL supported in Parallels HSphere.
Unread postPosted: Sun Aug 05, 2012 10:28 am 
Offline
Forum User
Forum User
User avatar

Joined: Wed Jul 04, 2012 7:44 am
Posts: 23
Location: Costa Rica
Hello,
We have 4 Hsphere Web/MySQL servers so we were very interested in finding out if we could run ASL on them.

We implemented a Hsphere test server so that the ASL staff could make the necessary tests on it to see if ASL would run in HSphere servers.

The ASL tech staff determined that Hsphere is incompatible with ASL due to the MySQL server version that Hsphere uses.

This is their answer after completing the tests:
"Just wrapped up the test, it does not look like Hsphere is going to be compatible with ASL. They're using a non-standard mysql install. That would need to be replaced by the one from either centos, or atomic in order to proceed. "

It seems Hsphere allows to change the MySQL server as it is mentioned here:
http://kb.parallels.com/en/111959
But we decided not to go ahead with the change in MySQL version for fear of breaking our servers.

Hope this helps,

Regards,

Rodrigo
CRServers.com

_________________
Rodrigo Fernández
Image
http://www.crservers.com


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic Share/Bookmark  [ 8 posts ] 

» Feed - Atomicorp

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group