From: Steve Grubb <sgrubb@redhat.com>
To: Joe Nall <joe@nall.com>
Cc: linux-audit@redhat.com
Subject: Re: libprelude in RHEL 6
Date: Sun, 16 Jan 2011 11:56:00 -0500 [thread overview]
Message-ID: <201101161156.00948.sgrubb@redhat.com> (raw)
In-Reply-To: <625A7D0C-45E7-49A0-90BF-C99A329D99DD@nall.com>
On Sunday, January 16, 2011 10:43:46 am Joe Nall wrote:
> On Jan 16, 2011, at 8:33 AM, Steve Grubb wrote:
> > On Saturday, January 15, 2011 03:09:05 pm Joe Nall wrote:
> >> I can find libprelude-devel.x86_64 in the RHEL 6 repos, but not
> >> libprelude or the i686 versions. Did I miss a rename, repackage or a
> >> repo?
> >
> >
> >
> > I can't find 'libprelude-*' in any RHEL6 variant. The spec file for the
> > audit daemon on RHEL6 also makes no "BuildRequires" statements on
> > libprelude-*. Fedora, on the otherhand, is different.
>
> Ok, I found libprelude-devel-0.9.24.1-1.el6.x86_64.rpm in one of our repos,
> so that explains where it came from.
>
> So no Prelude in RHEL 6?
Nope.
> Is the functionality incorporated into some other RH offering?
Not that I know of. But just to give you some idea of what I am thinking about...I am
on the editorial board of CEE. http://cee.mitre.org/ The main developer of rsyslog
is also on that board. He has been working on an implementation:
http://blog.gerhards.net/2010/10/cee-library-will-be-named-libee.html. And
http://doc.libee.org.
What I am thinking about is making a plugin that can take native audit events and put
them into CEE events. That would open the Linux Audit system to future SCAP tools. Its
a lot of work and that's why we started open-scap a couple years ago. I don't expect a
CEE based system to materialize over night. There are still lots of standards work to
do.
-Steve
prev parent reply other threads:[~2011-01-16 16:56 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2011-01-15 20:09 libprelude in RHEL 6 Joe Nall
2011-01-16 14:33 ` Steve Grubb
2011-01-16 15:43 ` Joe Nall
2011-01-16 16:56 ` Steve Grubb [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=201101161156.00948.sgrubb@redhat.com \
--to=sgrubb@redhat.com \
--cc=joe@nall.com \
--cc=linux-audit@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox