From mboxrd@z Thu Jan 1 00:00:00 1970 From: Valdis.Kletnieks@vt.edu Subject: Re: [PATCH] audit=0 appears not to completely disable auditing Date: Mon, 02 Apr 2007 15:17:01 -0400 Message-ID: <16942.1175541421@turing-police.cc.vt.edu> References: <200703091550.11104.sgrubb@redhat.com> <20070322214519.GA15039@fc.hp.com> <200703221755.45802.sgrubb@redhat.com> <20070402185711.GA21145@fc.hp.com> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1592516937==" Return-path: In-Reply-To: Your message of "Mon, 02 Apr 2007 14:57:11 EDT." <20070402185711.GA21145@fc.hp.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Amy Griffis Cc: Linux Audit List-Id: linux-audit@redhat.com --===============1592516937== Content-Type: multipart/signed; boundary="==_Exmh_1175541421_5877P"; micalg=pgp-sha1; protocol="application/pgp-signature" Content-Transfer-Encoding: 7bit --==_Exmh_1175541421_5877P Content-Type: text/plain; charset=us-ascii On Mon, 02 Apr 2007 14:57:11 EDT, Amy Griffis said: > Steve Grubb wrote: [Thu Mar 22 2007, 05:55:45PM EDT] > > > If you want audit_enabled=0 to turn off audit completely, do you also > > > want to drop selinux messages? > > > > No, the SE Linux folks want avc messages at all times unless the admin > > specifically sets a rule to suppress them. > > Okay, makes sense. Do you think audit should return an error if > someone tries to add a rule when audit_enabled=0 ? Yes, probably. You'd kind of think that the human doing the auditing would like a large and loud complaint if auditing had been accidentally disabled. The only question is what behavior it should have if a site (for whatever reason) decides to first load all the rules, then enable auditing (possibly to avoid spurious complaints about processes because not all the rules have been loaded yet). --==_Exmh_1175541421_5877P Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (GNU/Linux) Comment: Exmh version 2.5 07/13/2001 iD8DBQFGEVatcC3lWbTT17ARAnJxAJ0fFIdVV8Sra5ma1v7uFlh4nkoqjwCfRkEO 3E3uus413C3VbjFUS02ZMi0= =7BJg -----END PGP SIGNATURE----- --==_Exmh_1175541421_5877P-- --===============1592516937== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1592516937==--