update checkpoint to openappsec

This commit is contained in:
davidga
2022-11-15 14:00:53 +02:00
parent c20a5bfeb7
commit 3d8351007d
5 changed files with 36 additions and 32 deletions

View File

@@ -278,7 +278,7 @@ usage()
printf "%s %s : Load configuration\n" "$load_config_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#load_config_option})))")"
printf "%s %s : Set proxy\n" "$proxy_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#proxy_option})))")"
printf "%s %s : Display configuration\n" "$display_config_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#display_config_option})))")"
printf "%s %s : Create Openappsec agent info\n" "$cp_agent_info_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#cp_agent_info_option})))")"
printf "%s %s : Create open-appsec agent info\n" "$cp_agent_info_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#cp_agent_info_option})))")"
printf "%s %s : Display current policy\n" "$display_policy_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#display_policy_option})))")"
printf "%s %s : Load gradual policy\n" "$set_gradual_policy_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#set_gradual_policy_option})))")"
printf "%s %s : Remove gradual policy\n" "$delete_gradual_policy_option" "$(printf "%s" "$line_padding" | cut -c 1-"$(max_num 1 $((${#line_padding} - ${#delete_gradual_policy_option})))")"
@@ -463,15 +463,15 @@ read_agent_run_status() # Initials - rars
rars_output=$(tail -n 1 /tmp/agent-status.txt)
if [ "$1" = "start" ]; then
if [ "$rars_output" = "running" ]; then
echo "Openappsec Nano Agent watchdog started successfully"
echo "open-appsec Nano Agent watchdog started successfully"
else
echo "Openappsec Nano Agent is already running"
echo "open-appsec Nano Agent is already running"
fi
else # "$1" = "stop"
if [ "$rars_output" = "down" ]; then
echo "Openappsec Nano Agent stopped successfully"
echo "open-appsec Nano Agent stopped successfully"
else
echo "Openappsec Nano Agent is not running"
echo "open-appsec Nano Agent is not running"
fi
fi
}
@@ -527,7 +527,7 @@ run_stop_agent()
uninstall_agent() # Initials - ua
{
printf "Are you sure you want to uninstall Openappsec Nano Agent? (Y/N): " && read -r ua_confirm
printf "Are you sure you want to uninstall open-appsec Nano Agent? (Y/N): " && read -r ua_confirm
case $ua_confirm in
[Yy] | [Yy][Ee][Ss]) ;;
*) exit 1 ;;
@@ -540,9 +540,9 @@ uninstall_agent() # Initials - ua
fi
${ua_uninstall_script}
if test "$?" = "0"; then
echo "Openappsec Nano Agent successfully uninstalled"
echo "open-appsec Nano Agent successfully uninstalled"
else
echo "Failed to uninstall Openappsec Nano Agent"
echo "Failed to uninstall open-appsec Nano Agent"
exit 1
fi
}
@@ -824,7 +824,7 @@ print_single_service_status() # Initials - psss
return
fi
echo "---- Openappsec $(format_nano_service_name "$psss_service_name") Nano Service ----"
echo "---- open-appsec $(format_nano_service_name "$psss_service_name") Nano Service ----"
psss_is_userspace_process_running=$(is_userspace_running "$psss_service_name")
@@ -900,7 +900,7 @@ run_status() # Initials - rs
rs_agent_version="Version $rs_agent_version"
fi
echo "---- Openappsec Nano Agent ----"
echo "---- open-appsec Nano Agent ----"
echo "$rs_agent_version"
if [ "$(is_userspace_running "watchdog")" = true ] || [ "$(is_userspace_running "agent")" = true ]; then
format_colored_status_line "Status: Running"
@@ -1434,16 +1434,16 @@ set_mode()
if [ "$mode" = "online_mode" ]; then
time_sleep=2
time_out=60
echo "Registering Openappsec Nano Agent to Fog.."
echo "Registering open-appsec Nano Agent to Fog.."
until $USR_SBIN_PATH/${CP_NANO_CTL} -s 2> /dev/null | grep -q "Registration status: Succeeded"; do
time_out=$(( time_out - time_sleep ))
if [ $time_out -le 0 ]; then
echo "Openappsec Nano Agent registration failed. Failed to register to Fog: $fog_address"
echo "open-appsec Nano Agent registration failed. Failed to register to Fog: $fog_address"
exit 1
fi
sleep ${time_sleep}
done
echo "Openappsec Nano Agent is registered to $fog_address"
echo "open-appsec Nano Agent is registered to $fog_address"
echo "Orchestration mode changed successfully"
else
echo "Orchestration mode was changed successfully"

View File

@@ -34,7 +34,7 @@ practices:
max-header-size-bytes: 102400
max-object-depth: 40
max-url-size-bytes: 32768
minimum-confidence: Transparent
minimum-confidence: critical
override-mode: detect-learn
protections:
csrf-protection: detect-learn

View File

@@ -833,7 +833,7 @@ install_orchestration()
exit 0
fi
cp_print "\nStarting installation of Check Point Nano Agent [$INSTALLATION_TIME]" ${FORCE_STDOUT}
cp_print "\nStarting installation of open-appsec Nano Agent [$INSTALLATION_TIME]" ${FORCE_STDOUT}
cp_exec "rm -rf ${FILESYSTEM_PATH}/${SERVICE_PATH}"
cp_exec "rm -rf ${FILESYSTEM_PATH}/${WATCHDOG_PATH}"
@@ -975,21 +975,21 @@ install_orchestration()
install_watchdog
cp_print "Note: in order for the agent to remain active and effective it must connect to the Fog/Cloud at least every 45 days" ${FORCE_STDOUT}
cp_print "Check Point Nano Agent installation completed successfully" ${FORCE_STDOUT}
cp_print "open-appsec Nano Agent installation completed successfully" ${FORCE_STDOUT}
if [ $var_hybrid_mode = false ] && [ $var_offline_mode = false ] && [ $var_no_otp = false ] && [ $var_skip_registration = false ]; then
time_sleep=2
time_out=60
cp_print "Registering Check Point Nano Agent to Fog.." ${FORCE_STDOUT}
cp_print "Registering open-appsec Nano Agent to Fog.." ${FORCE_STDOUT}
until $USR_SBIN_PATH/${CP_NANO_CTL} -s 2> /dev/null | grep -q "Registration status: Succeeded"; do
time_out=$(( time_out - time_sleep ))
if [ $time_out -le 0 ]; then
cp_print "Check Point Nano Agent registration failed. Failed to register to Fog: $var_fog_address" ${FORCE_STDOUT}
cp_print "open-appsec Nano Agent registration failed. Failed to register to Fog: $var_fog_address" ${FORCE_STDOUT}
exit 1
fi
sleep ${time_sleep}
done
cp_print "Check Point Nano Agent is registered to $var_fog_address" ${FORCE_STDOUT}
cp_print "open-appsec Nano Agent is registered to $var_fog_address" ${FORCE_STDOUT}
fi
}
@@ -1032,7 +1032,7 @@ uninstall_orchestration()
if [ ! -f "$uninstall_script" ]; then
cp_dir="${FILESYSTEM_PATH}"
if [ ! -d "$cp_dir" ]; then
echo "Check Point Nano Agent is not installed"
echo "open-appsec Nano Agent is not installed"
exit 1
fi
echo "Failed to uninstall Orchestration Nano Service, uninstall script was not found in: $uninstall_script "
@@ -1040,9 +1040,9 @@ uninstall_orchestration()
fi
cp_exec "${uninstall_script}"
if test "$?" = "0"; then
cp_print "Check Point Nano Agent successfully uninstalled" ${FORCE_STDOUT}
cp_print "open-appsec Nano Agent successfully uninstalled" ${FORCE_STDOUT}
else
cp_print "Check Point Nano Agent failed to uninstall" ${FORCE_STDOUT}
cp_print "open-appsec Nano Agent failed to uninstall" ${FORCE_STDOUT}
exit 1
fi
}