##############################################################################
#                                                                            #
#                     Policy file for BLFS 6.2                               #
#                                V 0.4.0                                     #
#                             March 8, 2007                                  #
#                                                                            #
##############################################################################

##############################################################################
#                                                                            #
# This is the example Tripwire Policy file.  It is intended as a place to    #
# start creating your own custom Tripwire Policy file.  Referring to it as   #
# well as the Tripwire Policy Guide should give you enough information to    #
# make a good custom Tripwire Policy file that better covers your            #
# configuration and security needs.  A text version of this policy file is   #
# called twpol.txt.                                                          #
#                                                                            #
# Note that this file is tuned to a custom install of BLFS 6.2               #
# It is impossible for there to be one policy file for all machines, so this #
# existing one errs on the side of security. Your Linux configuration will   #
# most likely differ from the one our policy file was tuned to, and will     #
# therefore require some editing of the default Tripwire Policy file.        #
#                                                                            #
# The example policy file is best run with 'Loose Directory Checking'        #
# enabled. Set LOOSEDIRECTORYCHECKING=true in the Tripwire Configuration     #
# file.                                                                      #
#                                                                            #
# Email support is not included and must be added to this file.              #
# Add the 'emailto=' to the rule directive section of each rule (add a comma #
# after the 'severity=' line and add an 'emailto=' and include the email     #
# addresses you want the violation reports to go to).  Addresses are         #
# semi-colon delimited.                                                      #
#                                                                            #
##############################################################################

##############################################################################
#                                                                            #
# Global Variable Definitions                                                #
#                                                                            #
# These are defined at install time by the installation script.  You may     #
# Manually edit these if you are using this file directly and not from the   #
# installation script itself.                                                #
#                                                                            #
##############################################################################

@@section GLOBAL
TWDOCS="/usr/doc/tripwire";
TWBIN="/usr/sbin";
TWPOL="/etc/tripwire";
TWDB="/var/lib/tripwire";
TWSKEY="/etc/tripwire";
TWLKEY="/etc/tripwire";
TWREPORT="/var/lib/tripwire/report";
HOSTNAME="supervisor";

@@section FS
SEC_CRIT      = $(IgnoreNone)-SHa ;  # Critical files that cannot change
SEC_SUID      = $(IgnoreNone)-SHa ;  # Binaries with the SUID or SGID flags set
SEC_BIN       = $(ReadOnly) ;        # Binaries that should not change
SEC_CONFIG    = $(Dynamic) ;         # Config files that are changed
SEC_LOG       = $(Growing) ;         # Files that grow, but that should never change ownership
SEC_INVARIANT = +tpug ;              # Directories that should never change permission or ownership
SIG_LOW       = 33 ;                 # Non-critical files that are of minimal security impact
SIG_MED       = 66 ;                 # Non-critical files that are of significant security impact
SIG_HI        = 100 ;                # Critical files that are significant points of vulnerability


# Tripwire Binaries
(
  rulename = "Tripwire Binaries",
  severity = $(SIG_HI)
)
{
  $(TWBIN)/siggen                      -> $(SEC_BIN) ;
  $(TWBIN)/tripwire                    -> $(SEC_BIN) ;
  $(TWBIN)/twadmin                     -> $(SEC_BIN) ;
  $(TWBIN)/twprint                     -> $(SEC_BIN) ;
}

# Tripwire Data Files - Configuration Files, Policy Files, Keys, Reports, Databases
(
  rulename = "Tripwire Data Files",
  severity = $(SIG_HI)
)
{
  # NOTE: We remove the inode attribute because when Tripwire creates a backup,
  # it does so by renaming the old file and creating a new one (which will
  # have a new inode number).  Inode is left turned on for keys, which shouldn't
  # ever change.

  # NOTE: The first integrity check triggers this rule and each integrity check
  # afterward triggers this rule until a database update is run, since the
  # database file does not exist before that point.

  $(TWDB)                              -> $(SEC_CONFIG) -i ;
  $(TWPOL)/tw.pol                      -> $(SEC_BIN) -i ;
  $(TWPOL)/tw.cfg                      -> $(SEC_BIN) -i ;
  $(TWLKEY)/$(HOSTNAME)-local.key      -> $(SEC_BIN) ;
  $(TWSKEY)/site.key                   -> $(SEC_BIN) ;

  #don't scan the individual reports
  $(TWREPORT)                          -> $(SEC_CONFIG) (recurse=0) ;
}


# Tripwire HQ Connector Binaries
#(
#  rulename = "Tripwire HQ Connector Binaries",
#  severity = $(SIG_HI)
#)
#{
#  $(TWBIN)/hqagent                     -> $(SEC_BIN) ;
#}
#
# Tripwire HQ Connector - Configuration Files, Keys, and Logs

############################################################################## #
#                                                                            # #
# Note: File locations here are different than in a stock HQ Connector       # #
# installation.  This is because Tripwire 2.3 uses a different path          # #
# structure than Tripwire 2.2.1.                                             # #
#                                                                            # #
# You may need to update your HQ Agent configuation file (or this policy     # #
# file) to correct the paths.  We have attempted to support the FHS standard # #
# here by placing the HQ Agent files similarly to the way Tripwire 2.3       # #
# places them.                                                               # #
#                                                                            ##
##############################################################################

#(
#  rulename = "Tripwire HQ Connector Data Files",
#  severity = $(SIG_HI)
#)
#{
#   #############################################################################
#  ##############################################################################
#  # NOTE: Removing the inode attribute because when Tripwire creates a backup ##
#  # it does so by renaming the old file and creating a new one (which will    ##
#  # have a new inode number).  Leaving inode turned on for keys, which        ##
#  # shouldn't ever change.                                                    ##
#  #############################################################################
#
#  $(TWBIN)/agent.cfg                   -> $(SEC_BIN) -i ;
#  $(TWLKEY)/authentication.key         -> $(SEC_BIN) ;
#  $(TWDB)/tasks.dat                    -> $(SEC_CONFIG) ;
#  $(TWDB)/schedule.dat                 -> $(SEC_CONFIG) ;
#
#  # Uncomment if you have agent logging enabled.
#  #/var/log/tripwire/agent.log      -> $(SEC_LOG) ;
#}



# Commonly accessed directories that should remain static with regards to owner and group
(
  rulename = "Invariant Directories",
  severity = $(SIG_MED)
)
{
  /                                    -> $(SEC_INVARIANT) (recurse = 0) ;
  /home                                -> $(SEC_INVARIANT) (recurse = 0) ;
  /etc                                 -> $(SEC_INVARIANT) (recurse = 0) ;
}

################################################
#                                              #
#               Critical Files                 #
#                                              #    
################################################

###### File System and Disk Administration Programs

(
  rulename = "File System and Disk Administraton Programs",
  severity = $(SIG_HI)
)
{
  /sbin/badblocks                      -> $(SEC_CRIT) ;
  # /sbin/dosfsck                        -> $(SEC_CRIT) ; # Not present
  /sbin/e2fsck                         -> $(SEC_CRIT) ;
  /sbin/debugfs                        -> $(SEC_CRIT) ;
  /sbin/debugreiserfs                  -> $(SEC_CRIT) ;
  /sbin/dumpe2fs                       -> $(SEC_CRIT) ;
  /sbin/e2label                        -> $(SEC_CRIT) ;
  /sbin/fdisk                          -> $(SEC_CRIT) ;
  /sbin/cfdisk                         -> $(SEC_CRIT) ;
  /sbin/fsck                           -> $(SEC_CRIT) ;
  /sbin/fsck.ext2                      -> $(SEC_CRIT) ;
  /sbin/fsck.ext3                      -> $(SEC_CRIT) ;
  /sbin/fsck.reiserfs                  -> $(SEC_CRIT) ;
  /sbin/fsck.xfs                       -> $(SEC_CRIT) ;
  /sbin/fsck.minix                     -> $(SEC_CRIT) ;
  # /sbin/fsck.msdos                     -> $(SEC_CRIT) ; # Not present
  # /sbin/ftl_check                      -> $(SEC_CRIT) ; # Not present
  # /sbin/ftl_format                     -> $(SEC_CRIT) ; # Not present
  /sbin/hdparm                         -> $(SEC_CRIT) ;
  # /sbin/mkdosfs                        -> $(SEC_CRIT) ; # Not present
  /sbin/mke2fs                         -> $(SEC_CRIT) ;
  /sbin/mkfs                           -> $(SEC_CRIT) ;
  /sbin/mkfs.ext2                      -> $(SEC_CRIT) ;
  /sbin/mkfs.minix                     -> $(SEC_CRIT) ;
  # /sbin/mkfs.msdos                     -> $(SEC_CRIT) ; # Not present
  # /sbin/mkpv                           -> $(SEC_CRIT) ; # Not present
  # /sbin/mkraid                         -> $(SEC_CRIT) ; # Not present
  /sbin/mkswap                         -> $(SEC_CRIT) ;
  # /sbin/parted                         -> $(SEC_CRIT) ; # Not present
  # /sbin/raidstart                      -> $(SEC_CRIT) ; # Not Present
  /sbin/reiserfsck                     -> $(SEC_CRIT) ;
  /sbin/resize2fs                      -> $(SEC_CRIT) ;
  /sbin/resize_reiserfs                -> $(SEC_CRIT) ;
  # /sbin/scsi_info                      -> $(SEC_CRIT) ; # Not Present
  /sbin/sfdisk                         -> $(SEC_CRIT) ;
  /sbin/tune2fs                        -> $(SEC_CRIT) ;
  # /sbin/update                         -> $(SEC_CRIT) ; # Not Present
  /bin/mount                           -> $(SEC_CRIT) ;
  /bin/umount                          -> $(SEC_CRIT) ;
  /usr/bin/touch                       -> $(SEC_CRIT) ;
  /bin/mkdir                           -> $(SEC_CRIT) ;
  /bin/mknod                           -> $(SEC_CRIT) ;
  /usr/bin/mktemp                      -> $(SEC_CRIT) ;
  /bin/rm                              -> $(SEC_CRIT) ;
  /bin/rmdir                           -> $(SEC_CRIT) ;
  /bin/chgrp                           -> $(SEC_CRIT) ;
  /bin/chmod                           -> $(SEC_CRIT) ;
  /bin/chown                           -> $(SEC_CRIT) ;
  /bin/cp                              -> $(SEC_CRIT) ;
  /bin/mv                              -> $(SEC_CRIT) ;
  /usr/bin/install                     -> $(SEC_CRIT) ;
  # /bin/cpio                            -> $(SEC_CRIT) ; # Not Present
}

###### Kernel Administration Programs

(
  rulename = "Kernel Administration Programs",
  severity = $(SIG_HI)
)
{
  /sbin/depmod                         -> $(SEC_CRIT) ;
  /sbin/ctrlaltdel                     -> $(SEC_CRIT) ;
  /sbin/insmod                         -> $(SEC_CRIT) ;
  /sbin/insmod.static                  -> $(SEC_CRIT) ;
  # /sbin/insmod_ksymoops_clean          -> $(SEC_CRIT) ; # Not Present
  /usr/sbin/klogd                      -> $(SEC_CRIT) ;
  /sbin/ldconfig                       -> $(SEC_CRIT) ;
  /sbin/modinfo                        -> $(SEC_CRIT) ;
  /sbin/sysctl                         -> $(SEC_CRIT) ;
}

###### Networking Programs

(
  rulename = "Networking Programs",
  severity = $(SIG_HI)
)
{
  /sbin/arp                            -> $(SEC_CRIT) ;
  # /sbin/dhcpcd                         -> $(SEC_CRIT) ; # Section 2
  /sbin/agetty                         -> $(SEC_CRIT) ;
  /sbin/ifconfig                       -> $(SEC_CRIT) ;
  /sbin/ip                             -> $(SEC_CRIT) ;
  # /sbin/ipfwadm                        -> $(SEC_CRIT) ;
  # /sbin/ipmaddr                        -> $(SEC_CRIT) ;
  /sbin/iptables                       -> $(SEC_CRIT) ;
  # /sbin/iptunnel                       -> $(SEC_CRIT) ;
  # /sbin/ipx_configure                  -> $(SEC_CRIT) ;
  # /sbin/ipx_interface                  -> $(SEC_CRIT) ;
  # /sbin/ipx_internal_net               -> $(SEC_CRIT) ;
  # /sbin/iwconfig                       -> $(SEC_CRIT) ;
  # /sbin/iwpriv                         -> $(SEC_CRIT) ;
  # /sbin/iwspy                          -> $(SEC_CRIT) ;
  # /sbin/netreport                      -> $(SEC_CRIT) ;
  /sbin/plipconfig                     -> $(SEC_CRIT) ;
  # /sbin/portmap                        -> $(SEC_CRIT) ;
  # /sbin/ppp-watch                      -> $(SEC_CRIT) ;
  /sbin/rarp                           -> $(SEC_CRIT) ;
  /sbin/route                          -> $(SEC_CRIT) ;
  /sbin/slattach                       -> $(SEC_CRIT) ;
  # /sbin/ypbind                         -> $(SEC_CRIT) ;
  /bin/ping                            -> $(SEC_CRIT) ;
}

###### System Administration Programs

(
  rulename = "System Administration Programs",
  severity = $(SIG_HI)
)
{
  # /sbin/chkconfig                      -> $(SEC_CRIT) ; # Not Present
  /sbin/halt                           -> $(SEC_CRIT) ;
  /sbin/init                           -> $(SEC_CRIT) ;
  /sbin/killall5                       -> $(SEC_CRIT) ;
  # /sbin/rpc.lockd                      -> $(SEC_CRIT) ; # Not Present
  # /sbin/rpc.statd                      -> $(SEC_CRIT) ; # Not Present
  /sbin/shutdown                       -> $(SEC_CRIT) ;
  /sbin/sulogin                        -> $(SEC_CRIT) ;
  /sbin/swapon                         -> $(SEC_CRIT) ;
  /sbin/swapoff                        -> $(SEC_CRIT) ;
  /usr/sbin/syslogd                    -> $(SEC_CRIT) ;
  # /sbin/unix_chkpwd                    -> $(SEC_CRIT) ; # Not Present
  /bin/pwd                             -> $(SEC_CRIT) ;
  /bin/uname                           -> $(SEC_CRIT) ;
}

##### Hardware and Device Control Programs

(
  rulename = "Hardware and Device Control Programs",
  severity = $(SIG_HI)
)
{
  # /sbin/cardctl                        -> $(SEC_CRIT) ; # Not Present
  # /sbin/cardmgr                        -> $(SEC_CRIT) ; # Not Present
  /sbin/hwclock                        -> $(SEC_CRIT) ;
  # /sbin/isapnp                         -> $(SEC_CRIT) ; # Not Present
  # /sbin/kbdrate                        -> $(SEC_CRIT) ; # Not Present
  /sbin/losetup                        -> $(SEC_CRIT) ;
  /usr/sbin/lspci                      -> $(SEC_CRIT) ;
  # /sbin/pnpdump                        -> $(SEC_CRIT) ; # Not Present
  # /sbin/probe                          -> $(SEC_CRIT) ; # Not Present
  /usr/sbin/setpci                     -> $(SEC_CRIT) ;
  # /sbin/shapecfg                       -> $(SEC_CRIT) ; # Not Present
}

##### Information Programs

(
  rulename = "Information Programs",
  severity = $(SIG_HI)
)
{
  # /sbin/genksyms                       -> $(SEC_CRIT) ; # Not Present
  # /sbin/kernelversion                  -> $(SEC_CRIT) ; # Not Present
  /sbin/runlevel                       -> $(SEC_CRIT) ;
  /sbin/sln                            -> $(SEC_CRIT) ;
}
 
##### OS Utilities

(
  rulename = "Operating System Utilities",
  severity = $(SIG_HI)
)
{
  /bin/cat                             -> $(SEC_CRIT) ;
  /bin/date                            -> $(SEC_CRIT) ;
  /bin/dd                              -> $(SEC_CRIT) ;
  /bin/df                              -> $(SEC_CRIT) ;
  /bin/echo                            -> $(SEC_CRIT) ;
  /bin/egrep                           -> $(SEC_CRIT) ;
  /bin/false                           -> $(SEC_CRIT) ;
  /bin/fgrep                           -> $(SEC_CRIT) ;
  /usr/bin/gawk                        -> $(SEC_CRIT) ;
  # /usr/bin/gawk-3.1.5                  -> $(SEC_CRIT) ;
  /bin/grep                            -> $(SEC_CRIT) ;
  /bin/true                            -> $(SEC_CRIT) ;
  /bin/arch                            -> $(SEC_CRIT) ;
  /usr/bin/basename                    -> $(SEC_CRIT) ;
  /bin/dmesg                           -> $(SEC_CRIT) ;
  /bin/ed                              -> $(SEC_CRIT) ;
  /bin/gunzip                          -> $(SEC_CRIT) ;
  /bin/gzip                            -> $(SEC_CRIT) ;
  /bin/hostname                        -> $(SEC_CRIT) ;
  /usr/bin/igawk                       -> $(SEC_CRIT) ;
  /bin/kill                            -> $(SEC_CRIT) ;
  /bin/ln                              -> $(SEC_CRIT) ;
  /bin/loadkeys                        -> $(SEC_CRIT) ;
  /bin/login                           -> $(SEC_CRIT) ;
  /bin/ls                              -> $(SEC_CRIT) ;
  /usr/bin/mail                        -> $(SEC_CRIT) ;
  /bin/more                            -> $(SEC_CRIT) ;
  /bin/mv                              -> $(SEC_CRIT) ;
  /bin/netstat                         -> $(SEC_CRIT) ;
  /bin/nice                            -> $(SEC_CRIT) ;
  /bin/ps                              -> $(SEC_CRIT) ;
  /bin/sed                             -> $(SEC_CRIT) ;
  # /bin/setserial                       -> $(SEC_CRIT) ; # Not Present
  # /bin/sfxload                         -> $(SEC_CRIT) ; # Not Present
  /bin/sleep                           -> $(SEC_CRIT) ;
  /usr/bin/sort                        -> $(SEC_CRIT) ;
  /bin/stty                            -> $(SEC_CRIT) ;
  /bin/su                              -> $(SEC_CRIT) ;
  /bin/sync                            -> $(SEC_CRIT) ;
  /bin/tar                             -> $(SEC_CRIT) ;
  # /bin/usleep                          -> $(SEC_CRIT) ; # Not Present
  /usr/bin/vi                          -> $(SEC_CRIT) ;
  /usr/bin/vimtutor                    -> $(SEC_CRIT) ;
  /bin/zcat                            -> $(SEC_CRIT) ;
}

##### Critical Utility Sym-Links

(
  rulename = "Critical Utility Sym-Links",
  severity = $(SIG_HI)
)
{
  # /sbin/clock                          -> $(SEC_CRIT) ; # Not Present
  # /sbin/ipfwadm-wrapper                -> $(SEC_CRIT) ; # Not Present
  # /sbin/kallsyms                       -> $(SEC_CRIT) ; # Not Present
  # /sbin/ksyms                          -> $(SEC_CRIT) ; # Not Present
  /bin/lsmod                           -> $(SEC_CRIT) ;
  /sbin/modprobe                       -> $(SEC_CRIT) ;
  /sbin/mount.smbfs                    -> $(SEC_CRIT) ;
  /bin/pidof                           -> $(SEC_CRIT) ;
  /sbin/poweroff                       -> $(SEC_CRIT) ;
  # /sbin/raid0run                       -> $(SEC_CRIT) ; # Not Present
  # /sbin/raidhotadd                     -> $(SEC_CRIT) ; # Not Present
  # /sbin/raidhotremove                  -> $(SEC_CRIT) ; # Not Present
  # /sbin/raidstop                       -> $(SEC_CRIT) ; # Not Present
  /sbin/swapoff                        -> $(SEC_CRIT) ;
  /sbin/reboot                         -> $(SEC_CRIT) ;
  /sbin/rmmod                          -> $(SEC_CRIT) ;
  /sbin/telinit                        -> $(SEC_CRIT) ;
  /bin/dnsdomainname                   -> $(SEC_CRIT) ;
  /bin/domainname                      -> $(SEC_CRIT) ;
  /bin/nisdomainname                   -> $(SEC_CRIT) ;
  /bin/red                             -> $(SEC_CRIT) ;
  /bin/ypdomainname                    -> $(SEC_CRIT) ;
  /usr/bin/awk                         -> $(SEC_CRIT) ;
  /usr/bin/ex                          -> $(SEC_CRIT) ;
  /usr/bin/rview                       -> $(SEC_CRIT) ;
  /usr/bin/view                        -> $(SEC_CRIT) ;
}


#########################
#                       #
# Temporary directories #
#                       #
#########################
(
  rulename = "Temporary directories",
  recurse = false,
  severity = $(SIG_LOW)
)
{
  # /usr/tmp                             -> $(SEC_INVARIANT) ; # Not Present
  /var/tmp                             -> $(SEC_INVARIANT) ;
  /tmp                                 -> $(SEC_INVARIANT) ;
}

###############
#             #
# Local files #
#             #
###############
(
  rulename = "User binaries",
  severity = $(SIG_MED)
)
{
  /sbin                                -> $(SEC_BIN) (recurse = 1) ;
  /usr/local/bin                       -> $(SEC_BIN) (recurse = 1) ;
  /usr/sbin                            -> $(SEC_BIN) (recurse = 1) ;
  /usr/bin                             -> $(SEC_BIN) (recurse = 1) ;
}

(
  rulename = "Shell Binaries & Scripts",
  severity = $(SIG_HI)
)
{
  /bin/sh                              -> $(SEC_BIN) ;
  /bin/bash                            -> $(SEC_BIN) ;
  /etc/profile                         -> $(SEC_BIN) ;
  /etc/rc.d                            -> $(SEC_BIN) ;
  /etc/rc.d/init.d                     -> $(SEC_BIN) ;
}

(
  rulename = "Security Control",
  severity = $(SIG_HI)
)
{
  /etc/group                           -> $(SEC_CRIT) ;
  #/var/spool/cron/crontabs             -> $(SEC_CRIT) ; # Uncomment when this file exists
}

###### Libraries
(
  rulename = "Libraries",
  severity = $(SIG_MED)
)
{
  /usr/lib                             -> $(SEC_BIN) ;
  /usr/local/lib                       -> $(SEC_BIN) ;
}

######################################################
#                                                    #
# Critical System Boot Files                         #
# These files are critical to a correct system boot. #
#                                                    #
######################################################

(
  rulename = "Critical system boot files",
  severity = $(SIG_HI)
)
{
     # /boot                             -> $(SEC_CRIT) ;
     /usr/sbin/grub                    -> $(SEC_CRIT) ;
     !/boot/System.map ;
     !/boot/module-info ;
}

  ###################################################
  # These files change every time the system boots ##
  ##################################################
(
  rulename = "System boot changes",
  severity = $(SIG_HI)
)
{
     # !/var/run/ftp.pids-all ; # Comes and goes on reboot.
     # !/root/.enlightenment ;
     /dev/log                          -> $(SEC_CONFIG) ;
     # /dev/cua0                         -> $(SEC_CONFIG) ; # Not Present
     # /dev/printer                      -> $(SEC_CONFIG) ; # Uncomment if you have a printer device
     /dev/console                      -> $(SEC_CONFIG) -u ; # User ID may change on console login/logout.
     /dev/tty2                         -> $(SEC_CONFIG) ; # tty devices
     /dev/tty3                         -> $(SEC_CONFIG) ; # are extremely
     /dev/tty4                         -> $(SEC_CONFIG) ; # variable
     /dev/tty5                         -> $(SEC_CONFIG) ;
     /dev/tty6                         -> $(SEC_CONFIG) ;
     /dev/urandom                      -> $(SEC_CONFIG) ;
     /dev/initctl                      -> $(SEC_CONFIG) ;
     # /var/run                          -> $(SEC_CONFIG) ; # daemon PIDs
     # /var/log                          -> $(SEC_CONFIG) ;
     # /etc/ioctl.save                   -> $(SEC_CONFIG) ; # Not Present
     /etc/issue                        -> $(SEC_CONFIG) ;
     /etc/.pwd.lock                    -> $(SEC_CONFIG) ;
     /etc/mtab                         -> $(SEC_CONFIG) -i ; # Inode number changes on any mount/unmount
     /lib/modules                      -> $(SEC_CONFIG) ;
}

# These files change the behavior of the root account
(
  rulename = "Root config files",
  severity = 100
)
{
     # /root                             -> $(SEC_CRIT) ; # Catch all additions
     # /root/mail                        -> $(SEC_CONFIG) ; # Not Present
     # /root/.xsession-errors            -> $(SEC_CONFIG) ; # Not Present
     # /root/.xauth                      -> $(SEC_CONFIG) ; # Not Present
     # /root/.sawfish                    -> $(SEC_CONFIG) ; # Not Present
     # /root/.pinerc                     -> $(SEC_CONFIG) ; # Not Present
     # /root/.gnome_private              -> $(SEC_CONFIG) ; # Not Present
     # /root/.gnome-desktop              -> $(SEC_CONFIG) ; # Not Present
     # /root/.gnome                      -> $(SEC_CONFIG) ; # Not Present
     /root/.bash_profile               -> $(SEC_CONFIG) ;
     # /root/.bash_history               -> $(SEC_CONFIG) ;
     # /root/.Xresources                 -> $(SEC_CONFIG) ; # Not Present
     # /root/.Xauthority                 -> $(SEC_CONFIG) -i ; # Changes Inode number on login
}

################################
#                              #
# Critical configuration files #
#                              #
################################
(
  rulename = "Critical configuration files",
  severity = $(SIG_HI)
)
{
     # /etc/crontab                      -> $(SEC_BIN) ; # Not Present
     /etc/cron.hourly                  -> $(SEC_BIN) ;
     /etc/cron.daily                   -> $(SEC_BIN) ;
     /etc/cron.weekly                  -> $(SEC_BIN) ;
     /etc/cron.monthly                 -> $(SEC_BIN) ;
     /etc/default                      -> $(SEC_BIN) ;
     /etc/fstab                        -> $(SEC_BIN) ;
     # /etc/exports                      -> $(SEC_BIN) ; # Not Present
     /etc/group-                       -> $(SEC_BIN) ;
     # /etc/host.conf                    -> $(SEC_BIN) ; # Not Present
     /etc/hosts.allow                  -> $(SEC_BIN) ;
     /etc/hosts.deny                   -> $(SEC_BIN) ;
     /etc/protocols                    -> $(SEC_BIN) ;
     /etc/services                     -> $(SEC_BIN) ;
     # /etc/mail.rc                      -> $(SEC_BIN) ; # Not Present
     # /etc/motd                         -> $(SEC_BIN) ; # Not Present
     # /etc/named.boot                   -> $(SEC_BIN) ; # Not Present
     /etc/passwd                       -> $(SEC_CONFIG) ;
     /etc/passwd-                      -> $(SEC_CONFIG) ;
     /etc/profile.d                    -> $(SEC_BIN) ;
     # /var/lib/nfs/rmtab                -> $(SEC_BIN) ; # Not Present
     /etc/rpc                          -> $(SEC_BIN) ;
     /etc/sysconfig                    -> $(SEC_BIN) ;
     /etc/samba/smb.conf               -> $(SEC_CONFIG) ;
     /etc/nsswitch.conf                -> $(SEC_BIN) ;
     # /etc/yp.conf                      -> $(SEC_BIN) ; # Not Present
     /etc/hosts                        -> $(SEC_CONFIG) ;
     /etc/inittab                      -> $(SEC_CONFIG) ;
     /etc/syslog.conf                  -> $(SEC_CONFIG) ;

}

####################
#                  #
# Critical devices #
#                  #
####################
(
  rulename = "Critical devices",
  severity = $(SIG_HI),
  recurse = false
)
{
     /dev/kmem                         -> $(Device) ;
     /dev/mem                          -> $(Device) ;
     /dev/null                         -> $(Device) ;
     /dev/zero                         -> $(Device) ;
     /proc/devices                     -> $(Device) ;
     /proc/net                         -> $(Device) ;
     /proc/sys                         -> $(Device) ;
     /proc/cpuinfo                     -> $(Device) ;
     /proc/modules                     -> $(Device) ;
     /proc/mounts                      -> $(Device) ;
     /proc/dma                         -> $(Device) ;
     /proc/filesystems                 -> $(Device) ;
     # /proc/pci                         -> $(Device) ; # Not Present
     /proc/bus/pci                     -> $(Device) ;
     /proc/interrupts                  -> $(Device) ;
     /proc/ioports                     -> $(Device) ;
     # /proc/scsi                        -> $(Device) ; # Not Present
     /proc/kcore                       -> $(Device) ;
     /proc/self                        -> $(Device) ;
     /proc/kmsg                        -> $(Device) ;
     /proc/stat                        -> $(Device) ;
     # /proc/ksyms                       -> $(Device) ; # Not Present
     /proc/loadavg                     -> $(Device) ;
     /proc/uptime                      -> $(Device) ;
     /proc/locks                       -> $(Device) ;
     /proc/version                     -> $(Device) ;
     /proc/meminfo                     -> $(Device) ;
     /proc/cmdline                     -> $(Device) ;
     /proc/misc                        -> $(Device) ;
}

# Rest of critical system binaries
(
  rulename = "OS executables and libraries",
  severity = $(SIG_HI)
)
{
     /bin                              -> $(SEC_BIN) ;
     /lib                              -> $(SEC_BIN) ;
}

#=============================================================================
#
# Copyright 2000 Tripwire, Inc. Tripwire is a registered trademark of Tripwire,
# Inc. in the United States and other countries. All rights reserved.
#
# Linux is a registered trademark of Linus Torvalds.
#
# UNIX is a registered trademark of The Open Group.
#
#=============================================================================
#
# Permission is granted to make and distribute verbatim copies of this document
# provided the copyright notice and this permission notice are preserved on all
# copies.
#
# Permission is granted to copy and distribute modified versions of this
# document under the conditions for verbatim copying, provided that the entire
# resulting derived work is distributed under the terms of a permission notice
# identical to this one.
#
# Permission is granted to copy and distribute translations of this document
# into another language, under the above conditions for modified versions,
# except that this permission notice may be stated in a translation approved by
# Tripwire, Inc.
#
# DCM
