Bug 159254 - Arpwatch emails are empty.
Summary: Arpwatch emails are empty.
Keywords:
Status: CLOSED WORKSFORME
Alias: None
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: tcpdump
Version: 4.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
: ---
Assignee: Martin Stransky
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2005-05-31 21:30 UTC by Ali-Reza Anghaie
Modified: 2007-11-30 22:07 UTC (History)
0 users

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2005-07-21 11:17:49 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
One more time. (1.66 KB, text/plain)
2005-06-22 10:30 UTC, Ali-Reza Anghaie
no flags Details

Description Ali-Reza Anghaie 2005-05-31 21:30:17 UTC
Description of problem:

(I don't see arpwatch listed as a component, assigning to distribution for now.)

Arpwatch emails always end up empty although the syslog entry has the MAC address.

Version-Release number of selected component (if applicable):

arpwatch-2.1a13-9.RHEL4

How reproducible:

Always.

Steps to Reproduce:
1. Just enable arpwatch and wait.
2.
3.
  
Actual results:

Emails are empty.

Expected results:

Expect MAC addresses to be emailed.

Additional info:

I also putzed with the OPTIONS line of /etc/sysconfig/arpwatch to no avail. I
don't see any errors in the syslog regarding the email trying to be sent. It
just ends up empty.

Comment 1 Ali-Reza Anghaie 2005-06-21 11:24:23 UTC
For the record a ~change~ in MAC to IP actually triggers an email with
the proper data. It's just a new record that doesn't, I didn't notice
the change emails until recently. Cheers, -Ali

Comment 2 Martin Stransky 2005-06-21 14:38:14 UTC
Hm, have you made any changes? Sending mail works for me on fresh
installed RHEL4. Have you properly installed all mail programs? like
sendmail, procmail...

Comment 3 Ali-Reza Anghaie 2005-06-21 22:39:51 UTC
Yes, it works fine. Note that only the ~new~ MAC discoveries send
emtype emails but log fine. The changes, as I note in my last update,
work fine in the first place. This is a RHEL 4 up2date-d. Sendmail
works just fine, outbound emails and the local queue work fine.

arpwatch-2.1a13-10.RHEL4 currently and that exhibits the same problem.
Hrmm. -Ali

Comment 4 Martin Stransky 2005-06-22 07:47:25 UTC
Can you past here a part of logfile, when arpwatch writes log and does
not send correct email?

Comment 5 Ali-Reza Anghaie 2005-06-22 10:30:47 UTC
Created attachment 115802 [details]
One more time.

Comment 6 Ali-Reza Anghaie 2005-06-22 10:31:46 UTC
I added the attachment because Bugzilla generated an error (two times
it failed, first time with no message). The attachement has my update
plus the Bugzilla error. Cheers, -Ali

Comment 7 Martin Stransky 2005-06-27 10:30:09 UTC
Can you attach a mail which is generated by arpwatch? (With all headers)

Comment 8 Martin Stransky 2005-06-27 12:30:34 UTC
http://people.redhat.com/stransky/tcpdump/tcpdump-3.8.2-11.mail.src.rpm

Here is a testing version of arpwatch which doesn't delete
/tmp/arpwatch.XXXXX files. Those contains mail messages which are sent
by sendmail. You can send it manually by "sendmail -odi root
/tmp/arpwatch.XXXXX" and investigate if there are any errors...



Comment 9 Martin Stransky 2005-07-01 08:15:51 UTC
Any news?

Comment 10 Ali-Reza Anghaie 2005-07-01 08:55:28 UTC
I can work on this during the weekend, haven't had time. Sorry. I'll
pull the package and rpmbuild --rebuild it, etc. -Ali

Comment 11 Ali-Reza Anghaie 2005-07-01 09:35:02 UTC
Bloody Bugzilla keeps erroring out on the commit.

I rebuilt the SRPM but see no overlap between the tcpdump and
arpwatch. Are you sure this is what you want me to do or was posting
the SRPM for tcpdump a mistake?

Comment 12 Martin Stransky 2005-07-01 09:48:51 UTC
After rebuild, install only arpwatch-2.1a13-11.mail.i386.rpm package
which is included in tcpdump source rpm...

Comment 13 Ali-Reza Anghaie 2005-07-01 10:14:15 UTC
Yeah, I noticed that a bit too late. *sigh*

I did that but nada, the sendmail -odi root < arpwatch.foo works fine
without error and the email comes blank. Did you see my attachment
above? That strangeness in the header still appears though. It still
looks like the first line for 'hostname' is getting cutof as 'me:'...

I tried turning off all anti-spam features, etc. and that didn't help.
I thought perhaps mime defang was doing something.

No joy. :-/  I've gotta run, sorry for being brain dead this morning.
I'll check again later.

Comment 14 Martin Stransky 2005-07-21 11:17:49 UTC
Reopen it please, if you find anything new.


Note You need to log in before you can comment on or make changes to this bug.