From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com, Dan Gruhn <Dan.Gruhn@groupw.com>
Subject: Re: Latest Audit on RHEL 5.2
Date: Mon, 17 Nov 2008 12:37:36 -0500 [thread overview]
Message-ID: <200811171237.36672.sgrubb@redhat.com> (raw)
In-Reply-To: <2121478848.3051226506586159.JavaMail.root@zimbra.group-w-inc.com>
On Wednesday 12 November 2008 11:16:26 Dan Gruhn wrote:
> 1) I have read the HowTo at
> http://people.redhat.com/sgrubb/audit/prelude.txt but it seems rather old
> as it talks about audit 1.6.6 to 1.6.7 upgrading
This is a particular warning for anyone that ever installed and used the audit
1.6.6 prelude plugin because the name of the sensor being registered was
changed at the prelude developer's request. If you never installed that
version, then that note doesn't apply to you. I updated the text to hopefully
make that more plain.
I also added a new Deployment Tips section to explain a little about
maintaining & tuning the setup.
> and updates to come after things have been checked out. Does anyone have
> any updates to this procedure that will be helpful?
The update I need to make to the text was that we assigned a new UID/GID pair
to prelude out of the pool of UIDs reserved for daemons. I think the Fedora
10 prelude packages create that user if it doesn't exist. But since Fedora 10
is not shipping yet, I haven't spent the time testing out the new UID/GID
pair. I just wanted to get it reserved since that is a much longer process
requiring coordination with other groups inside Red Hat.
> 2) The pre-reqs for audit-1.7.9-1.src.rpm says it needs glibc-kernheaders
> >= 3.0-14. I must not understand what this is asking for. Is this some kind
> of abbreviation? Where can I find this?
This is the kernel headers shipped with the 2.6 kernel. RHEL5 is OK. RHEL4 is
not.
-Steve
prev parent reply other threads:[~2008-11-17 17:37 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2008-11-12 16:16 Latest Audit on RHEL 5.2 Dan Gruhn
2008-11-17 17:37 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=200811171237.36672.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=Dan.Gruhn@groupw.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox