For -nids: - plugins/detects/snortrules/ruleset/convert_ruleset should be installed in something like /usr/libexec (chmod 755). - The rules should be kept in /usr/share/prelude/nids/ with a symlink in /etc/prelude-nids/ruleset pointing to it (so we don't need to re-write the default config) For -lml: - The rules should be kept in /usr/share/prelude/lml/ with a symlink in /etc/prelude-lml/ruleset pointing to it (so we don't need to re-write the default config)
Created attachment 13856 [details, diff] Diff for prelude-lml ebuild Warning: UNTESTED!
Created attachment 13857 [details, diff] Diff for prelude-nids Warning: UNTESTED!
I'll grab these right quick and update the prelude-{lml,nids}
convert_ruleset added, rulesets moved to /usr/share/prelude/ with symlinks and all the goods. Michael Bomans diff's fixes worked flawless.