freedomofpress / securedrop-docs

Documentation for the SecureDrop project
https://docs.securedrop.org/
Other
22 stars 26 forks source link

"OSSEC Guide" still recommends editing `site-specific` manually #556

Closed cfm closed 3 months ago

cfm commented 3 months ago

Expected behavior

Our documentation on OSSEC instructs administrators to configure OSSEC via securedrop-admin sdconfig just like everything else.

Actual behavior

https://github.com/freedomofpress/securedrop-docs/blob/24d35119423703957e4864fe05ad056221d1fbe3/docs/admin/maintenance/ossec_alerts.rst?plain=1#L20-L23

Steps to reproduce the problem

  1. Read.
  2. Do a double-take.

Additional information

This has the risk of confusing administrators, e.g. that OSSEC is optional if they don't go out of their way to edit site-specific manually.