public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Audit-3.0 pre-release available
Date: Wed, 18 Jul 2018 11:52:20 -0400	[thread overview]
Message-ID: <1813615.GrRj1zR9PD@x2> (raw)

Hello,

This is to let everyone know that an audit-3.0 pre-release is being made. 
The big change that is prompting this email is that there is a config change 
that people might need to be aware of. One of the improvements is to drop 
audispd (realtime audit event dispatcher) and merge its functionality into 
auditd. This will eliminate one source of overflow messages and decrease the 
time from event occurrence to plugin seeing it. But since audispd doesn't 
exist anymore, I think that the location for the plugin directory should be 
moved from /etc/audisp/plugins.d/ to /etc/audit/plugins.d/. This way we have 
all audit config items in one place for the first time. There is a config 
option to point auditd to another directory for plugins in case you want to 
use the old location.

I have already coordinated this with some selinux developers. They are moving 
the selinux troubleshooter plugin and adjusting selinux policy for the new 
locations and label transitions from auditd to the plugins. I don't know how 
many people beyond those I have contacted makes use of the audit dispatcher 
plugin capabilities for real time audit analysis. But that is why I'm doing a 
pre-release and making this announcement.

You can find the pre-release here:
http://people.redhat.com/sgrubb/audit/audit-3.0-alpha.tar.gz

Its sha256 hash is:
5c6bd356dfd8f2f6a35df35a8cd5138bd511413ee03d56076b47dc120f406dbf

I will be blogging about the new capabilities in the coming weeks. If you are 
inclined, give it a try. There are changes that packagers will need to make 
to accommodate the move from audisp to auditd directly handling plugins. I 
have also pushed this into Fedora's rawhide and it should be available on the 
next compose.

Thanks,
-Steve

                 reply	other threads:[~2018-07-18 15:52 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1813615.GrRj1zR9PD@x2 \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox