# cleanup leftovers
rm -rf /var/ossec/etc /var/ossec/queue /var/ossec/stats
+
+# chown ossec mail directory back to root
+chown -Rh root:root /var/ossec
+
+# users and group names
+OSSEC_USER="ossec"
+OSSEC_USER_MAIL="ossecm"
+OSSEC_USER_EXEC="ossece"
+OSSEC_USER_REM="ossecr"
+OSSEC_GROUP="ossec"
+
+# delete users/groups
+if getent passwd $OSSEC_USER >/dev/null; then
+ deluser $OSSEC_USER
+fi
+if getent passwd $OSSEC_USER_MAIL >/dev/null; then
+ deluser $OSSEC_USER_MAIL
+fi
+if getent passwd $OSSEC_USER_EXEC >/dev/null; then
+ deluser $OSSEC_USER_EXEC
+fi
+if getent passwd $OSSEC_USER_REM >/dev/null; then
+ deluser $OSSEC_USER_REM
+fi
+if getent group $OSSEC_GROUP >/dev/null; then
+ delgroup --quiet $OSSEC_GROUP
+fi
# update system v init links
update-rc.d -f ossec-hids remove
# system ossec-init
echo "DIRECTORY=\"/var/ossec\"" > $(PKGDIR)/etc/ossec-init.conf
echo "VERSION=\"`cat src/VERSION`\"" >> $(PKGDIR)/etc/ossec-init.conf
- echo "DATE=\"$(date --utc -d "$(dpkg-parsechangelog | sed -ne 's/Date: //p')")\"" >> $(PKGDIR)/etc/ossec-init.conf
+ echo "DATE=\"$(shell date --utc -d "$(shell dpkg-parsechangelog | sed -ne 's/Date: //p')")\"" >> $(PKGDIR)/etc/ossec-init.conf
echo "TYPE=\"local\"" >> $(PKGDIR)/etc/ossec-init.conf
# Build architecture-independent files here.