ravindrags24
04/24/2020, 9:50 AMsudo /usr/bin/osqueryd --enroll_secret_path=/var/osquery/enroll_secret --tls_server_certs=/var/osquery/kolide.pem --tls_hostname=<http://kolide-test.abc.com|kolide-test.abc.com> --host_identifier=hostname --enroll_tls_endpoint=/api/v1/osquery/enroll --config_plugin=tls --config_tls_endpoint=/api/v1/osquery/config --config_refresh=10 --disable_distributed=false --distributed_plugin=tls --distributed_interval=3 --distributed_tls_max_attempts=3 --distributed_tls_read_endpoint=/api/v1/osquery/distributed/read --distributed_tls_write_endpoint=/api/v1/osquery/distributed/write --logger_plugin=tls --logger_tls_endpoint=/api/v1/osquery/log --logger_tls_period=10
Windows commands.
PS C:\Program Files\osquery> .\manage-osqueryd.ps1 -install --enroll_secret_path=C:\Program Files\osquery\secret.txt --tls_hostname=<http://kolide-test.abc.com|kolide-test.abc.com> --tls_server_certs=\Program Files\osquery\certs\kolide.pem --enroll_tls_endpoint=/api/v1/osquery/enroll --config_plugin=tls --config_tls_endpoint=/api/v1/osquery/config --config_refresh=10 --disable_distributed=false --distributed_plugin=tls --distributed_interval=3 --distributed_tls_max_attempts=3 --distributed_tls_read_endpoint=/api/v1/osquery/distributed/read --distributed_tls_write_endpoint=/api/v1/osquery/distributed/write --logger_plugin=tls --logger_tls_endpoint=/api/v1/osquery/log --logger_tls_period=10
Can some help on this.Alexandr Ivanov
04/24/2020, 11:01 AMravindrags24
04/24/2020, 11:03 AM'\Program Files\osquery\secret.txt'
its not working. No idea what was missing here.Alexandr Ivanov
04/24/2020, 11:11 AMravindrags24
04/24/2020, 11:13 AM--enroll_secret_path=C:\Program Files\osquery\secret.txt
--tls_hostname=<http://abc.com|abc.com>
--tls_server_certs=C:\Program Files\osquery\certs\<http://abc.com|abc.com>.pem
--host_identifier=hostname
--enroll_tls_endpoint=/api/v1/osquery/enroll
--config_plugin=tls
--config_tls_endpoint=/api/v1/osquery/config
--config_refresh=10
--logger_plugin=tls
--disable_distributed=false
--distributed_plugin=tls
--distributed_interval=3
--distributed_tls_max_attempts=3
--distributed_tls_read_endpoint=/api/v1/osquery/distributed/read
--distributed_tls_write_endpoint=/api/v1/osquery/distributed/write
--logger_plugin=tls --logger_tls_endpoint=/api/v1/osquery/log
--debug
--logger_tls_period=10
But getting error as below while executing the command.
.\osqueryd.exe --flagfile='C:\Program Files\osquery\osquery.flags'
Thrift: Sat Apr 25 13:52:04 2020 Client connected.
Thrift: Sat Apr 25 13:52:04 2020 TPipe ::GetOverlappedResult errored GLE=errno = 109
Thrift: Sat Apr 25 13:52:04 2020 Client connected.
Thrift: Sat Apr 25 13:52:04 2020 TConnectedClient died: TPipe: GetOverlappedResult failed
Thrift: Sat Apr 25 13:52:04 2020 TPipe ::GetOverlappedResult errored GLE=errno = 109
Thrift: Sat Apr 25 13:52:04 2020 TConnectedClient died: TPipe: GetOverlappedResult failed
W0425 13:52:06.597894 2140 tls_enroll.cpp:76] Failed enrollment request to <https://abc.com/api/v1/osquery/enroll> (No node key returned from TLS enroll plugin) retrying...
Alexandr Ivanov
04/27/2020, 10:45 AMravindrags24
04/27/2020, 10:46 AMAlexandr Ivanov
04/27/2020, 10:46 AMravindrags24
04/28/2020, 10:25 AMW0425 13:52:06.597894 2140 tls_enroll.cpp:76] Failed enrollment request to <https://abc.com/api/v1/osquery/enroll> (No node key returned from TLS enroll plugin) retrying...
How ever its wildcard certificate working from Ubuntu host and getting error in Windows.