From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: [PATCH] log all actions by privileged user in bash Date: Mon, 19 Feb 2007 20:16:17 -0500 Message-ID: <200702192016.17772.sgrubb@redhat.com> References: <200702041954.25501.sgrubb@redhat.com> <200702061550.21026.sgrubb@redhat.com> <200702062321.l16NL6bY016674@turing-police.cc.vt.edu> Mime-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <200702062321.l16NL6bY016674@turing-police.cc.vt.edu> Content-Disposition: inline List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Valdis.Kletnieks@vt.edu Cc: Linux Audit List-Id: linux-audit@redhat.com On Tuesday 06 February 2007 18:21:06 Valdis.Kletnieks@vt.edu wrote: > I can think of enough ways to bypass it that I have a hard time > convincing myself that it has any hope of making an auditor happy. You raised a lot of really good points. I haven't forgotten this patch, I will revisit it again soon after I get some new audit features finished. Thanks, -Steve