cloudera / cloudera-scripts-for-log4j

Scripts for addressing log4j zero day security issue
Apache License 2.0
86 stars 68 forks source link

Create Summary Report After Completion #6

Open belugabehr opened 2 years ago

belugabehr commented 2 years ago

Please create some sort of summary.date.log file in each CDH/CDP /opt/cloudera/ scanned directory which records all of the original SHA fingerprints of the affected JAR/TAR/WAR files and the SHA fingerprints of their modified versions. This information may be helpful, but most importantly, can be used as a maker to indicate that a particular node has been secured.

jtran-cloudera commented 2 years ago

Thanks for the report. We will consider this.

starkjs commented 2 years ago

I have started work on logging for my clients, as the current code also breaks permissions with a umask that was not tested