Oh, okay.  I was under the impression that shield-purge could be used to
purge the database regardless of the quarantine time.  Perhaps a --force
option would be helpful.  I suppose the man page indicates that I
shouldn't execute it manually.  :)

Does shield-purge compute the time difference between the trigger time and
the current time, or does it assume that it is executed once per day?  The
later would explain the behavior I was experiencing.  I would prefer
computing the actual time difference for a more predictable operation.

There should be an option to re-trigger based on the database.  This
option is useful when recomputing the firewall rules after a reboot, etc.

Excellent program though.  I've been looking for this type of solution for
a long time.  pam_tally works great, but it doesn't block the remote host.
 Now I use both.

-Paul

> Hi,
> Please don't file another bug for the same thing, just replay.
> Check out last line of /etc/security/shield.conf which defines for how
> long entries should be kept. Cron job does it when quarantine time is
> reached. Default is 1w (1 week).
> If this is what You were looking for I will close those bugs.
>
> --
> Mateusz Kaduk <[EMAIL PROTECTED]>
>
>





-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Reply via email to