rkhunter With A Clean First Check And Tamper Reports
rkhunter from EPEL, set up so the first daily check is clean: data files fetched, file properties recorded, passwd and group copies made, file installed, the kernel-module test off only where modules are missing. The live test runs the package's daily job: exit 0 as left, exit 1 naming the binary once a byte of sha256sum changes. Original role, live-tested on Rocky Linux 10.
Verification
Live-testedReally deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.
Conformance
- Static validation (yamllint · ansible-lint)
Provenance
- SHA-256 checksum
- Signature (pending)
Functional
- Live-tested - applied, verified, destroyed
Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify
Cite it in your README
badge · attributionPaste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.
[](https://www.iac-bazaar.com/catalog/ansible-rkhunter?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
Ansible role 1.0.0, live-tested on IaC Bazaar: [rkhunter With A Clean First Check And Tamper Reports](https://www.iac-bazaar.com/catalog/ansible-rkhunter?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)
```yaml
# rkhunter With A Clean First Check And Tamper Reports: https://www.iac-bazaar.com/catalog/ansible-rkhunter (download from your IaC Bazaar account)
```Preview:
Documentation
rkhunter
rkhunter from EPEL, set up so its first daily check is clean: the data
files the package lists but does not ship fetched, the file properties
recorded, its copies of passwd and group made, the file command it needs
installed, and the one test that cannot work without kernel modules switched
off only where they are missing - then the package's own daily job left to run
it. Original role for EL 10, live-tested with podman on Rocky Linux 10.
No download, and no version to pin. EL 10 packages rkhunter in EPEL, so the
role installs it by name and takes what the distribution ships: a new rkhunter
arrives through dnf, not through a new release of this role. What the role
owns is the configuration, the first run, and the proof that the check works.
The package's daily job, kept. rkhunter ships /etc/cron.daily/rkhunter,
which updates the data files, runs the check and mails a failed one to
MAILTO; the package pulls in cronie for it, and the install enables crond
without starting it (measured). The role starts crond, sets MAILTO, and leaves
the job as the package wrote it. The mail needs a mail transfer agent - with
none, s-nail keeps the report in /root/dead.letter (measured) - so pair this
role with one (this catalogue's postfix role), or watch
/var/log/rkhunter/rkhunter.log, which gets every run.
A clean first check, on purpose. On a fresh EL 10 host a check warns
four ways before anything is wrong: the file command is missing ("all script
replacement checks will be skipped"), the backdoor-ports file is empty (the
package lists it but does not install it), no copy of passwd or group exists
yet, and in a container there is no /lib/modules/<kernel>. The role installs
file, runs --update (exit 2 means it fetched something), records the file
properties with --propupd, makes the passwd and group copies with a
two-test check that takes seconds, and switches avail_modules off only where
the modules directory is missing. rkhunter.conf.local is checked with
rkhunter -C beside a copy of the main file before it lands - an unknown
option and a whitelist of a missing path are refused, a bad value is not
(measured) - and its DISABLE_TESTS adds to the package's list rather than
replacing it (measured).
Proven by a tampered binary. The live test first finds the three data
files in place - read before the daily job runs, because the job fetches them
itself and would hide a role that did not - and MAILTO set. Then it runs the
package's daily job as cron would: on the host as the role left it, it exits 0.
With one byte appended to /usr/bin/sha256sum it exits 1, the log says
"Package manager verification has failed" for that file, and the report is in
/root/dead.letter, as this lane has no mail transfer agent. The binary is put
back afterwards.
License
Commercial - IaC Bazaar EULA. (c) IaC Bazaar.
Usage code & full reference need an account
The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.
- Variables
- Test
Related modules
ansible-lynis
Lynis from EPEL on a systemd timer, with the units the package keeps only in its docs, your skipped tests in custom.prf, and a minimum hardening index below which the audit unit fails, so a falling score shows as a failed unit. The live test runs the audit, reads the index and the tests that ran, and finds the timer enabled. Original role, live-tested on Rocky Linux 10.
ansible-suricata
Suricata from EPEL watching the default-route interface as the suricata user, ET Open fetched at install and refreshed daily, plus a canary rule that proves the sensor is alive. A root-run check left root-owned logs and a daemon recording nothing; the role prevents it. The live test raises the canary alert while a second lookup is logged, not alerted. Original role, live-tested on Rocky Linux 10.
ansible-aide
AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.
ansible-389-ds
389 Directory Server from AppStream. A fresh instance listens on every interface and lets anonymous clients read the tree; this role binds both listeners to loopback and limits anonymous clients to the rootDSE. The live test adds a user who binds, sees a wrong password and an anonymous search refused, and reads the LDAPS certificate. Original role, live-tested on Rocky Linux 10.
ansible-krb5-kdc
An MIT Kerberos KDC: the realm created once with a stash, kadmind behind an ACL, a default policy that locks an account after five wrong passwords, every listener on loopback. The KDC starts on a broken config without a word, so the live test proves each setting by behaviour: the ticket lifetime, the refusals, the lockout. Original role, live-tested on Rocky Linux 10.
ansible-authelia
Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.