From mboxrd@z Thu Jan 1 00:00:00 1970 From: Michael C Thompson Subject: type=USER_ROLE_CHANGE Date: Thu, 13 Jul 2006 16:03:55 -0500 Message-ID: <44B6B53B.80802@us.ibm.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Return-path: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Linux Audit , Steve Grubb , Amy Griffis List-Id: linux-audit@redhat.com Hey Steve / Amy, In doing some tests, I've noticed that the USER_ROLE_CHANGE audit record is associated with both newrole, and semanage user -[ad]. I do not think that USER_ROLE_CHANGE is a good name to have associated with SELinux user creation/removal, not to mention that the payload of the record resulting from newrole looks nothing like the payload from that generated by semanage user -[ad]. Can we add a USER_ROLE_MODIFY, or some other label, that would indicate and differentiate SELinux user creation/removal from a simple newrole? Thanks, Mike