[Snort-sigs] oinkmaster vs pulled port, round two:

Michael Scheidell michael.scheidell at ...1331...
Thu Feb 10 10:20:32 EST 2011

I think round one was a draw.
some people want the rules in their original files, some would like them 
in easier managed 'single file'

I can see with PP, how being able to disable a RULE in, say 
snort_lan.conf vs disabling a whole rule set would have its advantages.
I can see how you might want to manage your main distribution point with 

round 2: licensing, copyrights:
our situation:
we pull down VRT rules (licensed), run oinkmaster on them to set up 'our 
tweaks' to the rules, then create a tarball (./rules/*.rules)
each individual snort sensor BOX runs a local copy of oinkmaster, to 
pull down our tarball and add local oinkmaster.conf tweaks to it.

I assume that even if I go with PP on the individual sensors (which 
seems to give me more flexibility, see round 1), that I still would need 
oinkmaster for the first step.

Also, how would PP preserve the copyright and license agreements that 
are in each rule file?
I believe that, even though we are licensed to redistribute VRT rules 
(and pay for each sensor...), we are required to leave the license and 
copyright notices there.

this would apply to VRT rules, GPL(2,3,) lesser, apache, anything, right?

this still makes PP vs oinkmaster, round two a draw.  PP can't preserve 
the copyright/license, oinkmaster can. so, on main distribution point, 
we still would need oinkmaster.

Michael Scheidell, CTO
o: 561-999-5000
d: 561-948-2259
ISN: 1259*1300
 >*| *SECNAP Network Security Corporation

    * Certified SNORT Integrator
    * 2008-9 Hot Company Award Winner, World Executive Alliance
    * Five-Star Partner Program 2009, VARBusiness
    * Best in Email Security,2010: Network Products Guide
    * King of Spam Filters, SC Magazine 2008

This email has been scanned and certified safe by SpammerTrap(r). 
For Information please see http://www.secnap.com/products/spammertrap/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.snort.org/pipermail/snort-sigs/attachments/20110210/0867e38e/attachment.html>

More information about the Snort-sigs mailing list