From mboxrd@z Thu Jan 1 00:00:00 1970 From: Amy Griffis Subject: Re: [PATCH] audit=0 appears not to completely disable auditing Date: Mon, 2 Apr 2007 14:57:11 -0400 Message-ID: <20070402185711.GA21145@fc.hp.com> References: <200703091550.11104.sgrubb@redhat.com> <20070322214519.GA15039@fc.hp.com> <200703221755.45802.sgrubb@redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8 Return-path: Content-Disposition: inline In-Reply-To: <200703221755.45802.sgrubb@redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb Cc: Linux Audit List-Id: linux-audit@redhat.com Steve Grubb wrote: [Thu Mar 22 2007, 05:55:45PM EDT] > > If you want audit_enabled=0 to turn off audit completely, do you also > > want to drop selinux messages? > > No, the SE Linux folks want avc messages at all times unless the admin > specifically sets a rule to suppress them. Okay, makes sense. Do you think audit should return an error if someone tries to add a rule when audit_enabled=0 ?