rkhunter With A Clean First Check And Tamper Reports

rkhunter from EPEL, set up so the first daily check is clean: data files fetched, file properties recorded, passwd and group copies made, file installed, the kernel-module test off only where modules are missing. The live test runs the package's daily job: exit 0 as left, exit 1 naming the binary once a byte of sha256sum changes. Original role, live-tested on Rocky Linux 10.

ansibleSecurity & Secrets

Verification

Live-tested

Really deployed to a container sandbox, proven idempotent (a second run changes nothing), verified against the role’s assertions, then torn down.

Conformance

  • Static validation (yamllint · ansible-lint)

Provenance

  • SHA-256 checksum
  • Signature (pending)

Functional

  • Live-tested - applied, verified, destroyed

Last verified 2026-10-03 · podman 4.9.3 · ansible 2.21.4 · how we verify

Cite it in your README

badge · attribution

Paste this beside the module in the repository that uses it. The badge is rendered from this artifact's verification record, so it reads live-tested because the record says so, and the link lands on this page.

README.md, GitLab, Gitea
[![IaC Bazaar: live-tested](https://www.iac-bazaar.com/api/artifacts/ansible-rkhunter/badge)](https://www.iac-bazaar.com/catalog/ansible-rkhunter?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

Ansible role 1.0.0, live-tested on IaC Bazaar: [rkhunter With A Clean First Check And Tamper Reports](https://www.iac-bazaar.com/catalog/ansible-rkhunter?utm_source=syndication&utm_medium=readme&utm_campaign=artifact)

```yaml
# rkhunter With A Clean First Check And Tamper Reports: https://www.iac-bazaar.com/catalog/ansible-rkhunter (download from your IaC Bazaar account)
```

Preview:IaC Bazaar: live-tested

Documentation

rkhunter

rkhunter from EPEL, set up so its first daily check is clean: the data files the package lists but does not ship fetched, the file properties recorded, its copies of passwd and group made, the file command it needs installed, and the one test that cannot work without kernel modules switched off only where they are missing - then the package's own daily job left to run it. Original role for EL 10, live-tested with podman on Rocky Linux 10.

No download, and no version to pin. EL 10 packages rkhunter in EPEL, so the role installs it by name and takes what the distribution ships: a new rkhunter arrives through dnf, not through a new release of this role. What the role owns is the configuration, the first run, and the proof that the check works.

The package's daily job, kept. rkhunter ships /etc/cron.daily/rkhunter, which updates the data files, runs the check and mails a failed one to MAILTO; the package pulls in cronie for it, and the install enables crond without starting it (measured). The role starts crond, sets MAILTO, and leaves the job as the package wrote it. The mail needs a mail transfer agent - with none, s-nail keeps the report in /root/dead.letter (measured) - so pair this role with one (this catalogue's postfix role), or watch /var/log/rkhunter/rkhunter.log, which gets every run.

A clean first check, on purpose. On a fresh EL 10 host a check warns four ways before anything is wrong: the file command is missing ("all script replacement checks will be skipped"), the backdoor-ports file is empty (the package lists it but does not install it), no copy of passwd or group exists yet, and in a container there is no /lib/modules/<kernel>. The role installs file, runs --update (exit 2 means it fetched something), records the file properties with --propupd, makes the passwd and group copies with a two-test check that takes seconds, and switches avail_modules off only where the modules directory is missing. rkhunter.conf.local is checked with rkhunter -C beside a copy of the main file before it lands - an unknown option and a whitelist of a missing path are refused, a bad value is not (measured) - and its DISABLE_TESTS adds to the package's list rather than replacing it (measured).

Proven by a tampered binary. The live test first finds the three data files in place - read before the daily job runs, because the job fetches them itself and would hide a role that did not - and MAILTO set. Then it runs the package's daily job as cron would: on the host as the role left it, it exits 0. With one byte appended to /usr/bin/sha256sum it exits 1, the log says "Package manager verification has failed" for that file, and the report is in /root/dead.letter, as this lane has no mail transfer agent. The binary is put back afterwards.

License

Commercial - IaC Bazaar EULA. (c) IaC Bazaar.

Usage code & full reference need an account

The complete copy-paste usage, the full input/output reference, and operational notes are free with an account - shown here and bundled in the download. Sign in and this section fills in.

  • Variables
  • Test

Related modules

Live-tested

ansible-lynis

Lynis from EPEL on a systemd timer, with the units the package keeps only in its docs, your skipped tests in custom.prf, and a minimum hardening index below which the audit unit fails, so a falling score shows as a failed unit. The live test runs the audit, reads the index and the tests that ran, and finds the timer enabled. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-suricata

Suricata from EPEL watching the default-route interface as the suricata user, ET Open fetched at install and refreshed daily, plus a canary rule that proves the sensor is alive. A root-run check left root-owned logs and a daemon recording nothing; the role prevents it. The live test raises the canary alert while a second lookup is logged, not alerted. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-aide

AIDE from AppStream on EL 10: a watched tree, a baseline database built once, and the oneshot unit and timer the package does not ship. The live test passes on an unchanged host, FAILS when a file appears inside a watched path and names it, ignores one inside an excluded path, and passes again once the change is gone. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-389-ds

389 Directory Server from AppStream. A fresh instance listens on every interface and lets anonymous clients read the tree; this role binds both listeners to loopback and limits anonymous clients to the rootDSE. The live test adds a user who binds, sees a wrong password and an anonymous search refused, and reads the LDAPS certificate. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-krb5-kdc

An MIT Kerberos KDC: the realm created once with a stash, kadmind behind an ACL, a default policy that locks an account after five wrong passwords, every listener on loopback. The KDC starts on a broken config without a word, so the live test proves each setting by behaviour: the ticket lifetime, the refusals, the lockout. Original role, live-tested on Rocky Linux 10.

View module
Live-tested

ansible-authelia

Authelia from the upstream release (sha256-verified) as a hardened system service on loopback with file users and sqlite; its secrets are generated once on the host and reach the service as AUTHELIA_*_FILE variables. The live test hashes a password with Authelia's hasher, logs in, sees a wrong password refused and an anonymous visitor sent to the portal. Original role, live-tested on Rocky 10.

View module