public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Removing open_by_handle_at in local copy of stig.rules
@ 2013-11-04 13:55 leam hall
  2013-11-04 14:05 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: leam hall @ 2013-11-04 13:55 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 488 bytes --]

As much as I'd like to be on a more current kernel, the open_by_handle_at
syscall seems to have been introduced in 2.6.39, per para 1.9 of:

http://kernelnewbies.org/Linux_2_6_39

I removed it from my local copy of:

https://fedorahosted.org/audit/browser/trunk/contrib/stig.rules

My old RHEL 5 boxes are easily confused with this new-fangled stuff!  :)

Is there a plan to have a RHEL 5 and RHEL 6 version of the stig.rules?

Leam

-- 
Mind on a Mission <http://leamhall.blogspot.com/>

[-- Attachment #1.2: Type: text/html, Size: 859 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Removing open_by_handle_at in local copy of stig.rules
  2013-11-04 13:55 Removing open_by_handle_at in local copy of stig.rules leam hall
@ 2013-11-04 14:05 ` Steve Grubb
  0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2013-11-04 14:05 UTC (permalink / raw)
  To: linux-audit

On Monday, November 04, 2013 08:55:16 AM leam hall wrote:
> As much as I'd like to be on a more current kernel, the open_by_handle_at
> syscall seems to have been introduced in 2.6.39, per para 1.9 of:
> 
> http://kernelnewbies.org/Linux_2_6_39
> 
> I removed it from my local copy of:
> 
> https://fedorahosted.org/audit/browser/trunk/contrib/stig.rules
> 
> My old RHEL 5 boxes are easily confused with this new-fangled stuff!  :)

You would have to have an auditctl that matched it.

> Is there a plan to have a RHEL 5 and RHEL 6 version of the stig.rules?

I think they are pretty well separated. The rules shipped in rhel5 I think are 
current with the requirements levied on RHEL5. RHEL6 just got a STIG and I 
have not yet reviewed it to see if they stuck to the agreement we had. But the 
rules that would apply to RHEL6 would be shipped on RHEL6. I had not planned 
to separate them in svn.

-Steve

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2013-11-04 14:05 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2013-11-04 13:55 Removing open_by_handle_at in local copy of stig.rules leam hall
2013-11-04 14:05 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox