public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* audit 1.2.1 released
@ 2006-04-17 22:34 Steve Grubb
  2006-04-18 14:06 ` Michael C Thompson
  0 siblings, 1 reply; 3+ messages in thread
From: Steve Grubb @ 2006-04-17 22:34 UTC (permalink / raw)
  To: linux-audit

Hi,

I've just released a new version of the audit daemon. It can be downloaded 
from http://people.redhat.com/sgrubb/audit  It will also be in rawhide  
tomorrow. The Changelog is:

- New message type for trusted apps
- Add new keywords: today, yesterday, & now for ausearch and aureport
- Make audit_log_user_avc_message really send to syslog on error
- Updated syscall tables in auditctl
- Deprecated the 'possible' action for syscall rules in auditctl
- Update watch code to use file syscalls instead of 'all' in auditctl

This is mostly a bugfix release. Let me know if there are any problems with 
it.

-Steve

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: audit 1.2.1 released
  2006-04-17 22:34 audit 1.2.1 released Steve Grubb
@ 2006-04-18 14:06 ` Michael C Thompson
  2006-04-18 14:13   ` Steve Grubb
  0 siblings, 1 reply; 3+ messages in thread
From: Michael C Thompson @ 2006-04-18 14:06 UTC (permalink / raw)
  To: Steve Grubb; +Cc: linux-audit

Steve Grubb wrote:
> Hi,
> 
> I've just released a new version of the audit daemon. It can be downloaded 
> from http://people.redhat.com/sgrubb/audit  It will also be in rawhide  
> tomorrow. The Changelog is:
> 
> - New message type for trusted apps

Can you given an example of this new message type please?

> - Add new keywords: today, yesterday, & now for ausearch and aureport
> - Make audit_log_user_avc_message really send to syslog on error
> - Updated syscall tables in auditctl
> - Deprecated the 'possible' action for syscall rules in auditctl
> - Update watch code to use file syscalls instead of 'all' in auditctl
> 
> This is mostly a bugfix release. Let me know if there are any problems with 
> it.
> 
> -Steve

^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: audit 1.2.1 released
  2006-04-18 14:06 ` Michael C Thompson
@ 2006-04-18 14:13   ` Steve Grubb
  0 siblings, 0 replies; 3+ messages in thread
From: Steve Grubb @ 2006-04-18 14:13 UTC (permalink / raw)
  To: Michael C Thompson; +Cc: linux-audit

On Tuesday 18 April 2006 10:06, Michael C Thompson wrote:
> > - New message type for trusted apps
>
> Can you given an example of this new message type please?

It is AUDIT_TRUSTED_APP. Just use it with audit_log_user_message. This is for 
third party's that want to log something to the audit system from their 
trusted app. I think examples given were virus scanners, intrusion detection 
systems, and other such beasts. Nothing to do with LSPP or CAPP.

-Steve

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2006-04-18 14:13 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-04-17 22:34 audit 1.2.1 released Steve Grubb
2006-04-18 14:06 ` Michael C Thompson
2006-04-18 14:13   ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox