Skip to main content

Rkhunter Set Up in systemd : Revisited

I made a post about setting up rkhunter using systemd. And little did I know it's going to be a work in progress for weeks. But I have finally set up the service and timer units just right.

[donato@archdesktop ~]$ systemctl list-timers
NEXT                         LEFT        LAST                         PASSED       UNIT                         ACTIVATES
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       logrotate.timer              logrotate.service
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       man-db.timer                 man-db.service
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       shadow.timer                 shadow.service
Fri 2017-10-06 00:00:00 +08  16h left    Thu 2017-10-05 00:00:20 +08  7h ago       updatedb.timer               updatedb.service
Fri 2017-10-06 00:08:16 +08  16h left    Thu 2017-10-05 04:28:45 +08  3h 15min ago rkhunter.timer               rkhunter.service
Fri 2017-10-06 01:38:57 +08  17h left    Wed 2017-10-04 19:12:48 +08  12h ago      systemd-tmpfiles-clean.timer systemd-tmpfiles-clean.service
Mon 2017-10-09 08:46:49 +08  4 days left Mon 2017-10-02 19:37:22 +08  2 days ago   reflector.timer              reflector.service

7 timers listed.
Pass --all to see loaded but inactive timers, too.
[donato@archdesktop ~]$ systemctl status rkhunter.service
donato@archdesktop ~]$ systemctl status rkhunter.service
● rkhunter.service - rkhunter rootkit scan and malware detection
   Loaded: loaded (/etc/systemd/system/rkhunter.service; static; vendor preset: disabled)
   Active: inactive (dead)
     Docs: man:rkhunter
           man:systemd.service
[donato@archdesktop ~]$

If I want rkhunter to start scanning at boot, I should enable the service with:

$ systemctl enable rkhunter.service

Since I don't want that behavior I'm disabling the service. It won't start at boot but will start when its timer elapse. 

rkhunter update process fails in this instance, but the main process goes on at the elapse time set in the timer file. My tip with creating service and timer files in systemd is letting the default behavior take you where you want to go. So it's a given that you know what those defaults are.


My current rkhunter.service file is:
[donato@archdesktop ~]$ systemctl cat rkhunter.service
# /etc/systemd/system/rkhunter.service
[Unit]
Description=rkhunter rootkit scan and malware detection
Documentation=man:rkhunter man:systemd.service


[Service]
ExecStartPre=-/usr/bin/rkhunter --update
ExecStartPre=-/usr/bin/rkhunter --propupd
ExecStart=/usr/bin/rkhunter --check -sk
SuccessExitStatus=1 2 8 SIGKILL TERM


[Install]
WantedBy=multi-user.target

My current rkhunter.timer file is:
[donato@archdesktop ~]$ systemctl cat rkhunter.timer
# /etc/systemd/system/rkhunter.timer
[Unit]
Description=Run rkhunter daily
Documentation=man:rkhunter man:systemd.timer


[Timer]
OnCalendar=*-*-* 00:00:00
RandomizedDelaySec=5h
WakeSystem=true
Persistent=true


[Install]
WantedBy=timers.target

Comments

Popular posts from this blog

Mailvelope, Encryption for Webmail

Encryption is the topic of week. I wrote about it in a related post here. While encryption is a very good idea, doing it and doing it every day as part of your work flow is another thing. My view is that if you're already using an email client then it is easier, simpler and more convenient to adopt encryption. That is not the case if you're using a webmail service. If you are using the browser to check, compose and send your email, what are your options? The answer is: it's complicated. Looking for a way to do encryption with Google Chrome and Gmail, I found this. I also read that Google just released code for email encryption as open source. But it's a long way to being used by end users. The extension for Google Chrome works fine if the recipient also uses Google Chrome. But I went ahead and check this on Evolution.

Donald Trump Is The 45th President of the United States

     and he is preparing to move with his transition team into the Oval Office. His election is a shock to many political observers and the world in general. Donald Trump, the president-elect, ran against Hillary Clinton, former Secretary of State and for many the most qualified candidate for the presidency in many years. This has led to many post election analysis of how this upset happened. The numbers of votes for each candidate and the comparisons with previous presidential elections point to the fact that the white vote for Mr. Trump is solid all throughout but the minority and black votes did not come for Mrs. Clinton. This is what happened in crucial States like Michigan and Florida. The Republicans kept Congress and the Senate. It is quite notable that Russia and in particular, Vladimir Putin, is happy that they are going to talk to Mr. Trump rather than Mrs. Clinton. It is also a ...

Webapps in Unity

So it has been 4 months since Ubuntu 14.04 came out. This is LTS and supported for 6 years by Canonical. The first mobile device with Ubuntu pre-installed is promised to come out later this year, 2014. It's time to check out how the apps perform so far. It is a good idea. I use Gmail and Twitter and Facebook. Why not a webapp in a desktop? So I start the Twitter and Gmail webapp. So far it has crashed my computer 6 times. Not a very good sign. On the other hand it does work but not as stable as opening them in Firefox. -- Use my PGP key if you want to encrypt your replies/messages to me. You are invited to also send me your PGP keys so we can communicate in private.