Description of problem: /etc/init.d/snortd starts snort with -c /etc/snort/snort.conf but snort.conf is located in /etc/. 'service snortd start' fails to start snort as a result even though [OK] is printed. Version-Release number of selected component (if applicable): snort-2.4.3-1.fc4 How reproducible: Always Steps to Reproduce: 1. service snortd start 2. pgrep snort Actual results: snort is terminated with a fatal error logged in /var/log/messages. Step (2) prints nothing. Expected results: snort running and step (2) would reveal its PID Additional info: None
Created attachment 125692 [details] Patch to change config file path
I just noticed 2 more disturbing problems. a. snort.conf includes several rules files that do not exist and are not distributed with the RPM. b. snort.conf refers to unicode.map under the configuration of http_inspect. That file does not exist and is not installed either.
I need to add a README file you have to download the rules from snort.org they do not license them under GPL and we can not redistribute them. thnaks for the patch
Ah interesting, I didn't notice they were licensed separately.
fixed package to put files in /etc/snort/