pirxthepilot
07/09/2019, 5:05 PM(No node key returned from TLS enroll plugin)
. we are able to fix it by refreshing /var/osquery/db
, but i was wondering if there is a way to just reset the node key without "factory-resetting" osqueryd on the host?jason swierk
09/27/2019, 8:42 PMpirxthepilot
10/04/2019, 6:57 PM/var/osquery.db
. in our case osquery stopped running queries entirely. on existing hosts, we just pretty much purged that dir so osquery starts fresh. we fixed it at the source by adding a step in our provisioning scripts to remove the directory (apparently generated when the OS images are being built).
though i still see that error pop up occasionally but the affected hosts are otherwise fine. we just ignore it for now /shrugjason swierk
10/07/2019, 5:32 PM--disable_database=true
so osquery.db doesn't exist. I've also attempted --disable_reenrollment=true
but I'm still seeing the error message, although as you see also, it seems to have no effect.