IMPORTANT: When reverting to the configuration prior to the use of
3.5 Monitoring drift
The bastille_drift program creates
NOTE: When first run successfully,
You can use
•To save a baseline:
#bastille_drift
•To compare the current state of the system to a saved baseline:
#bastille_drift --from_baseline baseline
Run the bastille_drift utility when new software or patches are installed to check for changes in the system. The bastille_drift utility also identifies system changes when swverify is run using
For more information, see bastille_drift(1M).
3.6 Locating files
This section describes the location of important files.
The configuration file contains the answers to the most recently saved session.
/etc/opt/sec_mgmt/bastille/config
The error log contains any errors
The action log contains the specific steps that
The TODO.txt file list contains the tasks the must be completed to ensure the system is secure.
/var/opt/sec_mgmt/bastille/TODO.txt
The
The TOREVERT.txt file contains the tasks that must be completed to finish reverting the machine to the state it was in before
/var/opt/sec_mgmt/bastille/TOREVERT.txt
The assessment reports are available as HTML, text, and a configuration file.
3.5 Monitoring drift | 17 |