From mboxrd@z Thu Jan 1 00:00:00 1970 From: LC Bruzenak Subject: Re: file watch result help Date: Mon, 21 Jul 2008 09:14:18 -0500 Message-ID: <1216649658.8213.36.camel@homeserver> References: <1216612916.8213.23.camel@homeserver> <48841BB5.6080904@cn.fujitsu.com> <1216647554.8213.32.camel@homeserver> Mime-Version: 1.0 Content-Type: text/plain Content-Transfer-Encoding: 7bit Return-path: Received: from mx3.redhat.com (mx3.redhat.com [172.16.48.32]) by int-mx1.corp.redhat.com (8.13.1/8.13.1) with ESMTP id m6LEEkbZ011914 for ; Mon, 21 Jul 2008 10:14:46 -0400 Received: from magi (rrcs-24-242-137-197.sw.biz.rr.com [24.242.137.197]) by mx3.redhat.com (8.13.8/8.13.8) with ESMTP id m6LEEYCA015577 for ; Mon, 21 Jul 2008 10:14:35 -0400 In-Reply-To: <1216647554.8213.32.camel@homeserver> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: zhangxiliang Cc: Linux Audit List-Id: linux-audit@redhat.com On Mon, 2008-07-21 at 08:39 -0500, LC Bruzenak wrote: ... > > Thank you for the reply, however there was no config change after I > installed this file. > The action is happening automatically, since it occurred at 4AM. > I suspect that the prelink cron job is doing this. That is definitely the problem - prelink cron job moves file, which erases the CAP. The audit record was adequate in pointing me to the problem. LCB. -- LC (Lenny) Bruzenak lenny@magitekltd.com