[LWN Logo]

Date:	Thu, 7 Jan 1999 21:40:26 -0500
From:	Gene Spafford <spaf@CS.PURDUE.EDU>
Subject:      Re: Tripwire mess..
To:	BUGTRAQ@NETSPACE.ORG

The patches for the old version of Tripwire with the 8-bit problem
have been in circulation for a while, and the source code is
available.   If someone wants more than that, the commercial version
is available (as Austin noted).

Tripwire 1.2 was released in August of 1994.  Other than systems
coming along after that so that the 1.2 distribution didn't have
config files, there were only 2 significant bugs or problems reported
in over 4 years: the timing problem, and the 8-bit filename problem.
We posted a fix for the timing problem, and the 8-bit fix has been
floating around mailing lists and newsgroups for years, and the fixed
version was being shipped with RedHat at one point.

We do research here at the university -- not product support.  When
Gene Kim's company offered to license Tripwire, maintain it, and
enhance it, we were happy to turn it over to them.  Not only was Gene
the original author, but we were happy to hear that it would get
ported to a Windows environment and enhanced in other ways, too.

Thus, for the community happy with freeware and source code, you have
TW 1.2 for Unix, and you can patch it or extend it as you wish, so
long as you respect the copyright and trademark restrictions.

For the people who want a formally-supported product or new features
or new platform support, contact the folks at Tripwire and see what
they have to offer.

In either case, I would argue that the code is being properly
maintained, as Austin noted.