public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* stime(2) auditing on x86_64
@ 2007-10-27  4:29 Todd, Charles
  2007-10-27 14:55 ` Steve Grubb
  0 siblings, 1 reply; 5+ messages in thread
From: Todd, Charles @ 2007-10-27  4:29 UTC (permalink / raw)
  To: Linux Audit


[-- Attachment #1.1: Type: text/plain, Size: 1241 bytes --]

I was trying to get my system to pass a System Readiness Review (SRR)
from disa.mil and it would appear that stime(2) is not audited under
x86_64, either in v1.0.15 or v1.2.1 of auditd.  I've looked at the
source code and stime(2) only seems to be audited on i386, ppc, and
s390.  stime(2) is in my libc (nm /lib/libc.so.6 | grep stime).
 
Is this on purpose or is there something deeper?   The full line of what
DISA expected me to configure is
-a exit,always -S stime -S acct -S reboot -S swapon
 
A careful observer will note that the CAPP suggested configuration
already captures adjtimex and settimeofday.  I just want to pass my
test, but is there overlap here that I should push back on?
 
Thanks,
Charlie Todd 
Ball Aerospace & Technologies Corp.  

 



This message and any enclosures are intended only for the addressee.  Please  
notify the sender by email if you are not the intended recipient.  If you are  
not the intended recipient, you may not use, copy, disclose, or distribute this  
message or its contents or enclosures to any other person and any such actions  
may be unlawful.  Ball reserves the right to monitor and review all messages  
and enclosures sent to or from this email address.

[-- Attachment #1.2: Type: text/html, Size: 2326 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2007-10-29 13:11 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-10-27  4:29 stime(2) auditing on x86_64 Todd, Charles
2007-10-27 14:55 ` Steve Grubb
2007-10-28 21:51   ` Todd, Charles
2007-10-28 22:46     ` Matthew Booth
2007-10-29 13:11     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox