mtree vs tripwire

Garrett Wollman wollman at khavrinen.lcs.mit.edu
Wed Jan 14 13:56:31 PST 2004


<<On Wed, 14 Jan 2004 07:42:15 -0600, D J Hawkey Jr <hawkeyd at visi.com> said:

> What sort of pitfalls should I be aware of?

mtree files don't scale very well, and to make proper use of them for
this purpose requires a great deal more thought.  Tripwire is a bit
more "pre-thunk", and uses a database instead of a flat file, which
speeds updates.  (With mtree you'd have to rescan the entire
filesystem.)

-GAWollman



More information about the freebsd-security mailing list