[prelude-user] snort / prelude-manager certificate trust
ScottO
skippylou at gmail.com
Fri Nov 20 21:19:30 CET 2009
>
> Right, I understand the different profiles for different components, but I
> guess I was failing to see the relationship between all of the components. I
> was expecting to register a "snort" profile on my snort sensor with a
> corresponding "snort" profile on the prelude-manager machine. I also had to
> register prelude-manager with itself (after adding the profile) to get
> things working properly. In the architecture diagram on the Prelude wiki, it
> appears to show several layers in a hierarchy of reporting from remote
> sensors to remote prelude-managers, which then in turn report back in to a
> centralized prelude-manager somewhere else. I'd like to explore that setup
> at some point (since I will eventually have some remote sensors) so I expect
> I'll have some further questions in the future. I'm guessing that in that
> case, I'd want to register the remote snort profile against the remote
> prelude-manager profile, and then register the remote prelude-manager
> profile with the central prelude-manager profile?
>
>
yep, that's exactly right. register each agent/manager with their direct
upstream manager.
scotto
More information about the Prelude-user
mailing list