As I recall, they recommended putting the expected values on a floppy disk and setting the ‘write protect’ tab, so the checksums couldn’t be changed.
As I recall, they recommended putting the expected values on a floppy disk and setting the ‘write protect’ tab, so the checksums couldn’t be changed.
Had some drawbacks compared to using offline media of course, but in day to day operation on an air-gapped network it had its uses.
Also worth knowing is the "-V" (for very parameter) of rpm.
[1] https://docs.redhat.com/en/documentation/red_hat_enterprise_...
If tinkering with OSSEC one of the first steps should be to configure whitelisting for IP ranges and CIDR blocks used by your company, SNAT addresses and bastion IP's so that someone does not lock everyone out. It does a lot more than checksums.
[1] - https://www.ossec.net/
The alternative (tho not practical in many cases) would be RO media like RW-DVD.
Though yes, two USB ports would definitely work; it's just that the concept might be better served by providing two different connectors (e.g. USB-A & USB-C), as is common nowadays.