* Question concerning -l option
@ 2017-02-10 16:52 Tom Hall
2017-02-10 17:09 ` Steve Grubb
0 siblings, 1 reply; 2+ messages in thread
From: Tom Hall @ 2017-02-10 16:52 UTC (permalink / raw)
To: linux-audit@redhat.com
[-- Attachment #1.1: Type: text/plain, Size: 466 bytes --]
Please forgive me, I assume this has already been addressed in the mail archive but I've been unable to locate a related thread. Can someone tell me why the default for auditd is O_NOFOLLOW for accessing auditd configuration files? I assume there is a reason for not supporting links as the default that is important enough to justify the extra work to add the -l option but it is not clear to me.
Thanks,
Tom Hall
Brocade Communications Systems, Inc.
[-- Attachment #1.2: Type: text/html, Size: 901 bytes --]
[-- Attachment #2: Type: text/plain, Size: 0 bytes --]
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Question concerning -l option
2017-02-10 16:52 Question concerning -l option Tom Hall
@ 2017-02-10 17:09 ` Steve Grubb
0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2017-02-10 17:09 UTC (permalink / raw)
To: linux-audit
Hello,
On Friday, February 10, 2017 4:52:13 PM EST Tom Hall wrote:
> Please forgive me, I assume this has already been addressed in the mail
> archive but I've been unable to locate a related thread. Can someone tell
> me why the default for auditd is O_NOFOLLOW for accessing auditd
> configuration files? I assume there is a reason for not supporting links as
> the default that is important enough to justify the extra work to add the
> -l option but it is not clear to me.
It was made that way to ensure that the security assumptions are exactly as
expected. Meaning no one has replaced the real configuration with a weaker one
somewhere else on disk. And since auditd is covered by selinux policy, moving
the configuration also means policy label problems. So, this is kind of a
strong hint to leave it where its supposed to be to avoid problems.
In the old days, all it took was a simple edit to /etc/sysconfig/auditd to fix.
But with systemd, it is a bit more work to copy the service file to the right
place before editing.
-Steve
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2017-02-10 17:09 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-02-10 16:52 Question concerning -l option Tom Hall
2017-02-10 17:09 ` Steve Grubb
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).