public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* close(2) not being audited?
@ 2006-12-28 21:58 Todd, Charles
  2006-12-30 14:36 ` Steve Grubb
  2007-01-26 17:37 ` Steve Grubb
  0 siblings, 2 replies; 14+ messages in thread
From: Todd, Charles @ 2006-12-28 21:58 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 1271 bytes --]

All,
I'm on an RHEL4u3 with Steve's preliminary 1.0.15 package (I built the
RPM) under x86_64 2.6.9-34-ELsmp.  I'm using the CAPP.rules sample
fileset to great success.  NISPOM 8-602 requires that CLOSE operations
on security-relevant objects be logged.  Well, I've got logging for OPEN
on security-relevant objects (with the watches) working VERY well
(yeah!!!).  The default CAPP.rules file had nothing about close(2), so
just to test it, I ran:
  auditctl -a entry,possible -S close
and then as a normal user typed: cat /etc/group (which is a
security-relevant object that I have permission to open, and thus
eventually close)
However, when I review the audit files, nothing is logged.  If I change
the "entry,possible" to "entry,always" then lots of stuff gets logged,
but not my actual opening of the /etc/group file.
  There is only one other thing that could be a configuration issue:
"auditctl -l |grep /etc/group" reveals an additional "perm=wa" field
that is set by the -p option in CAPP.rules, but even if root writes to
one of the watched files, close(2) is still not logged.
 
Do I have a configuration problem or is something deeper going on?
 
Thanks,
Charlie Todd 
Ball Aerospace & Technologies Corp.  
ctodd- at -ball.com 

 

[-- Attachment #1.2: Type: text/html, Size: 2672 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2007-01-29 20:19 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2006-12-28 21:58 close(2) not being audited? Todd, Charles
2006-12-30 14:36 ` Steve Grubb
2007-01-26 17:37 ` Steve Grubb
2007-01-26 18:03   ` John D. Ramsdell
2007-01-26 20:14   ` Wieprecht, Karen M.
2007-01-26 22:19     ` Alexander Viro
2007-01-26 23:00       ` Timothy R. Chavez
2007-01-26 23:01       ` Timothy R. Chavez
2007-01-26 23:20         ` Alexander Viro
2007-01-26 23:46           ` Timothy R. Chavez
2007-01-28 21:40             ` James Antill
2007-01-29 20:19               ` Timothy R. Chavez
2007-01-26 23:29         ` Alexander Viro
2007-01-27  0:03           ` Timothy R. Chavez

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox