public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: "Brian K. Whatcott" <bwhatcott@meicompany.com>
To: Linux-audit@redhat.com
Subject: RE: [RFC] NISPOM audit rules - first draft
Date: Fri, 13 Apr 2007 15:45:10 -0600	[thread overview]
Message-ID: <007201c77e15$02ad8e10$0c01a8c0@Whatcott2> (raw)
In-Reply-To: <200704131431.39959.sgrubb@redhat.com>

 Steve,

I am a bit new at using mail lists, but I joined this one to get help on
setting up auditd for NISPOM chapter 8.

Below you say the nispom.rules has been updated several times.  Where is the
latest version located?  

In the nispom.rules version in your post in the archive, the comments said
several NISPOM audit requirements were met by other programs (1(b) by
patches to login, gdm, and openssh; 1(d) by patches to libpam; 1(e) & 1(f)
by patches to pam_tally).  Can these patches be downloaded from somewhere?
Do the patches work with SuSE 10.1 or 10.2?  

Sorry I come from a non-RH distro background.  Our choice of SuSE came from
the long historic past.  I rather not have to switch several machines to RH
in order to meet NISPOM requirements, but I could if absolutely necessary.

Brian K. Whatcott
Senior Software and Systems Engineer
Millennium Engineering Integration
(719) 264-4310, FAX (719) 264-4318
(719) 331-5100 (Cell)
bwhatcott@meicompany.com 
-----Original Message-----
From: linux-audit-bounces@redhat.com [mailto:linux-audit-bounces@redhat.com]
On Behalf Of Steve Grubb
Sent: Friday, April 13, 2007 12:32 PM
To: Timothy R. Chavez
Cc: Linux Audit
Subject: Re: [RFC] NISPOM audit rules - first draft

On Friday 13 April 2007 14:24, Timothy R. Chavez wrote:
> Wow... finally just getting to these.  Just a couple quick comments below.

The nispom.rules file has been updated several times since this was
initially posted.

> > ## unsuccessful modifications
> > -a exit,always -S rename -S truncate -S ftruncate -F exit=-13 -k 
> > mods -a exit,always -S renameat -F exit=-13 -k mods -a exit,always 
> > -F perm=a -F exit=-13 -k mods
>
> No system call specified...

That's what the magic of "perm" is. It selects all syscalls that match the
changing of attribute.

-Steve

--
Linux-audit mailing list
Linux-audit@redhat.com
https://www.redhat.com/mailman/listinfo/linux-audit

  reply	other threads:[~2007-04-13 21:44 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-03-01 18:33 [RFC] NISPOM audit rules - first draft Steve Grubb
2007-04-13 18:24 ` Timothy R. Chavez
2007-04-13 18:31   ` Steve Grubb
2007-04-13 21:45     ` Brian K. Whatcott [this message]
2007-04-13 21:54       ` Steve Grubb
2007-04-18 20:41         ` Wieprecht, Karen M.
2007-04-18 21:16           ` Steve Grubb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='007201c77e15$02ad8e10$0c01a8c0@Whatcott2' \
    --to=bwhatcott@meicompany.com \
    --cc=Linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox