public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: Joe Nall <joe@nall.com>
Cc: linux-audit@redhat.com
Subject: Re: libprelude in RHEL 6
Date: Sun, 16 Jan 2011 11:56:00 -0500	[thread overview]
Message-ID: <201101161156.00948.sgrubb@redhat.com> (raw)
In-Reply-To: <625A7D0C-45E7-49A0-90BF-C99A329D99DD@nall.com>

On Sunday, January 16, 2011 10:43:46 am Joe Nall wrote:
> On Jan 16, 2011, at 8:33 AM, Steve Grubb wrote:
> > On Saturday, January 15, 2011 03:09:05 pm Joe Nall wrote:
> >> I can find libprelude-devel.x86_64 in the RHEL 6 repos, but not
> >> libprelude or the i686 versions. Did I miss a rename, repackage or a
> >> repo?
> >
> > 
> >
> > I can't find 'libprelude-*' in any RHEL6 variant. The spec file for the
> > audit daemon on  RHEL6 also makes no "BuildRequires" statements on
> > libprelude-*. Fedora, on the otherhand, is different.
> 
> Ok, I found libprelude-devel-0.9.24.1-1.el6.x86_64.rpm in one of our repos,
> so that explains where it came from.
> 
> So no Prelude in RHEL 6?

Nope.

> Is the functionality incorporated into some other RH offering?

Not that I know of. But just to give you some idea of what I am thinking about...I am 
on the editorial board of CEE.  http://cee.mitre.org/  The main developer of rsyslog 
is also on that board. He has been working on an implementation: 
http://blog.gerhards.net/2010/10/cee-library-will-be-named-libee.html. And 
http://doc.libee.org.

What I am thinking about is making a plugin that can take native audit events and put 
them into CEE events. That would open the Linux Audit system to future SCAP tools. Its 
a lot of work and that's why we started open-scap a couple years ago. I don't expect a 
CEE based system to materialize over night. There are still lots of standards work to 
do.

-Steve

      reply	other threads:[~2011-01-16 16:56 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2011-01-15 20:09 libprelude in RHEL 6 Joe Nall
2011-01-16 14:33 ` Steve Grubb
2011-01-16 15:43   ` Joe Nall
2011-01-16 16:56     ` Steve Grubb [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=201101161156.00948.sgrubb@redhat.com \
    --to=sgrubb@redhat.com \
    --cc=joe@nall.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox