All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: redhat-lspp@redhat.com
Cc: James Antill <jantill@redhat.com>,
	linux-audit@redhat.com, Stephen Smalley <sds@tycho.nsa.gov>,
	selinux@tycho.nsa.gov
Subject: Re: Re: [patch] Full relabel audit event
Date: Tue, 30 May 2006 09:22:44 -0400	[thread overview]
Message-ID: <200605300922.44971.sgrubb@redhat.com> (raw)
In-Reply-To: <1148663120.20976.235.camel@moss-spartans.epoch.ncsc.mil>

On Friday 26 May 2006 13:05, Stephen Smalley wrote:
> Hmmm...what is it that you actually want to do here?

We need to meet the requirements for LSPP where there is a relabel on boot, 
but we do not want a record for each file that was touched. It was discussed 
on the LSPP telecon a while back that just one record was sufficient.

> If you only care about auditing autorelabel events, then I'd suggest
> generating the audit message from the autorelabel portion of rc.sysinit (via
> a helper, I suppose), not from setfiles itself.

This is a shell script and cannot connect to libaudit.

> If you want to audit all full relabels, then you need to instrument more
> than setfiles (e.g. restorecon -R / works just as well), and of course, you
> potentially need to do something at the kernel level with audit filters or
> auditallow rules in policy if you truly want to capture all relabels. 

We get relabels by monitoring the setxattr syscall. But during bootup before 
going interactive, we just want 1 message.

-Steve

--
redhat-lspp mailing list
redhat-lspp@redhat.com
https://www.redhat.com/mailman/listinfo/redhat-lspp

WARNING: multiple messages have this Message-ID (diff)
From: Steve Grubb <sgrubb@redhat.com>
To: redhat-lspp@redhat.com
Cc: Stephen Smalley <sds@tycho.nsa.gov>,
	James Antill <jantill@redhat.com>,
	linux-audit@redhat.com, selinux@tycho.nsa.gov
Subject: Re: [redhat-lspp] Re: [patch] Full relabel audit event
Date: Tue, 30 May 2006 09:22:44 -0400	[thread overview]
Message-ID: <200605300922.44971.sgrubb@redhat.com> (raw)
In-Reply-To: <1148663120.20976.235.camel@moss-spartans.epoch.ncsc.mil>

On Friday 26 May 2006 13:05, Stephen Smalley wrote:
> Hmmm...what is it that you actually want to do here?

We need to meet the requirements for LSPP where there is a relabel on boot, 
but we do not want a record for each file that was touched. It was discussed 
on the LSPP telecon a while back that just one record was sufficient.

> If you only care about auditing autorelabel events, then I'd suggest
> generating the audit message from the autorelabel portion of rc.sysinit (via
> a helper, I suppose), not from setfiles itself.

This is a shell script and cannot connect to libaudit.

> If you want to audit all full relabels, then you need to instrument more
> than setfiles (e.g. restorecon -R / works just as well), and of course, you
> potentially need to do something at the kernel level with audit filters or
> auditallow rules in policy if you truly want to capture all relabels. 

We get relabels by monitoring the setxattr syscall. But during bootup before 
going interactive, we just want 1 message.

-Steve

--
This message was distributed to subscribers of the selinux mailing list.
If you no longer wish to subscribe, send mail to majordomo@tycho.nsa.gov with
the words "unsubscribe selinux" without quotes as the message.

  parent reply	other threads:[~2006-05-30 13:22 UTC|newest]

Thread overview: 12+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2006-05-25 21:01 [patch] Full relabel audit event James Antill
2006-05-25 21:01 ` James Antill
2006-05-26 17:05 ` Stephen Smalley
2006-05-26 17:05   ` Stephen Smalley
2006-05-26 17:47   ` James Antill
2006-05-26 17:47     ` James Antill
2006-05-26 18:03     ` [redhat-lspp] " Stephen Smalley
2006-05-26 18:03       ` Stephen Smalley
2006-05-30 14:08       ` Steve Grubb
2006-05-30 14:08         ` [redhat-lspp] " Steve Grubb
2006-05-30 13:22   ` Steve Grubb [this message]
2006-05-30 13:22     ` Steve Grubb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200605300922.44971.sgrubb@redhat.com \
    --to=sgrubb@redhat.com \
    --cc=jantill@redhat.com \
    --cc=linux-audit@redhat.com \
    --cc=redhat-lspp@redhat.com \
    --cc=sds@tycho.nsa.gov \
    --cc=selinux@tycho.nsa.gov \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.