**********************************************************************
*                    Merlin README                                   *
**********************************************************************


What is Merlin?
----------------

Merlin is a tool for managing other tools -- it can take a powerful
but cryptic command-line tool and provide it with an easy-to-use
graphical interface.

Merlin comes with support for 5 popular security tool, but it can be
extended to support any command-line oriented tool.

Merlin provides for the execution of tools, and the viewing,
enhancment, and management of their reports.

Merlin is written almost entirely in Perl. All interface management is
performed through Netscape. It requires Perl 5.001m, C, and Netscape
1.1+.

Merlin is designed for Unix platforms. It has been tested on SGI 5.3,
Linux 1.2.8, SunOS 4.1.2, Solaris 2.4, and HP-UX 9.05, but should work
on a variety of other systems.


What tools does Merlin currently support?
------------------------------------------

* COPS 1.04
    (available at ftp://coast.cs.purdue.edu/pub/tools/unix/cops/1.04/)

* Tiger 2.2.3
    (availabe at ftp://coast.cs.purdue.edu/pub/tools/unix/TAMU/)

* Crack 4.1
    (available at ftp://coast.cs.purdue.edu/pub/tools/unix/crack/)

* Tripwire 1.2
    (available at ftp://coast.cs.purdue.edu/pub/COAST/Tripwire)

* SPI 3.2.x (DOD, DOE & their contractors only)
    (available at http://ciac.llnl.gov/cstc/CSTCProducts.html#spi)



So, Merlin comes with all these packages built in??
----------------------------------------------------

NO! You grab the package, tell Merlin what the home directory is,
via a configuration screen, and then you are ready to go.



Security data is sensitive - what precautions have you taken?
--------------------------------------------------------------

Since Merlin utilizes an HTTP server and client, security is an
important issue. Merlin tackles security in several ways:

1) A port is arbitrarly selected at the start of each session.

2) Connections are only accepted from the local host.

3) All requests to the server must include a "magic cookie" value,
   generated by the server at the beginning of each session.


Ok, so how do I get started?
------------------------------

Go to the INSTALL file for more information.



I have a suggestion/complaint/bug report to contribute. Who should I
talk to?
-------------------------------------------------------------

Send email to merlin@ciac.llnl.gov.
