public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* labeled ipsec auditing
@ 2006-10-05 21:23 Joy Latten
  2006-10-05 22:04 ` Steve Grubb
  2006-10-05 22:15 ` [redhat-lspp] " Paul Moore
  0 siblings, 2 replies; 10+ messages in thread
From: Joy Latten @ 2006-10-05 21:23 UTC (permalink / raw)
  To: linux-audit, redhat-lspp

I am auditing when an ipsec policy is added and removed from the 
Security Policy Database. Should I also add audit when an SA is 
added and removed? SAs can quickly fill up log since there can be many of them
and they also have a lifetime associated with them that can result in 
continuous renewal. I looked at how Paul implemented netlabel auditing, 
but was wondering is there any specific info I should audit for 
labeled ipsec?

Regards,
Joy   

^ permalink raw reply	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2006-10-11 18:07 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-10-05 21:23 labeled ipsec auditing Joy Latten
2006-10-05 22:04 ` Steve Grubb
2006-10-05 22:15 ` [redhat-lspp] " Paul Moore
2006-10-09 19:09   ` Klaus Weidner
2006-10-09 19:15     ` Paul Moore
2006-10-09 19:30       ` Klaus Weidner
2006-10-10 23:25         ` Joy Latten
2006-10-11  0:00           ` Klaus Weidner
2006-10-11 13:38           ` Serge E. Hallyn
2006-10-11 18:07             ` [redhat-lspp] " Joy Latten

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox