public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: [RFC] NISPOM audit rules - first draft
Date: Fri, 13 Apr 2007 17:54:27 -0400	[thread overview]
Message-ID: <200704131754.27644.sgrubb@redhat.com> (raw)
In-Reply-To: <007201c77e15$02ad8e10$0c01a8c0@Whatcott2>

On Friday 13 April 2007 17:45, Brian K. Whatcott wrote:
> Below you say the nispom.rules has been updated several times.  Where is
> the latest version located?

You can download the latest source code, open the archive and copy 
nispom.rules to wherever you needed it.

http://people.redhat.com/sgrubb/audit/audit-1.5.2.tar.gz

The configuration takes advantage of some newer features. So, it may or may 
not work with the exact version of audit/kernel that you have.

> In the nispom.rules version in your post in the archive, the comments said
> several NISPOM audit requirements were met by other programs (1(b) by
> patches to login, gdm, and openssh; 1(d) by patches to libpam; 1(e) & 1(f)
> by patches to pam_tally).  Can these patches be downloaded from somewhere?

These patches have been sent upstream and hopefully your versions of those 
apps are new enough to have the patches and audit is enabled for them. I did 
not collect them up into one place, but rather tried to get them where they 
ultimately needed to go so everyone benefits from the work. The one exception 
might be util-linux which seems to be a dead project that each distro 
maintains themselves.

> Do the patches work with SuSE 10.1 or 10.2?  

I don't know.

-Steve

  reply	other threads:[~2007-04-13 21:54 UTC|newest]

Thread overview: 7+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2007-03-01 18:33 [RFC] NISPOM audit rules - first draft Steve Grubb
2007-04-13 18:24 ` Timothy R. Chavez
2007-04-13 18:31   ` Steve Grubb
2007-04-13 21:45     ` Brian K. Whatcott
2007-04-13 21:54       ` Steve Grubb [this message]
2007-04-18 20:41         ` Wieprecht, Karen M.
2007-04-18 21:16           ` Steve Grubb

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200704131754.27644.sgrubb@redhat.com \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox