public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* RedHat 6 Testing
@ 2011-03-25 14:55 Boyce, Kevin P (AS)
  2011-03-25 15:32 ` Sean.Hollinger
  2011-03-25 16:15 ` Steve Grubb
  0 siblings, 2 replies; 6+ messages in thread
From: Boyce, Kevin P (AS) @ 2011-03-25 14:55 UTC (permalink / raw)
  To: linux-audit@redhat.com


[-- Attachment #1.1: Type: text/plain, Size: 540 bytes --]

All,

I have some puzzling behavior, can anyone shed some light here?

I have a script in cron.weekly that has a command being executed which I am auditing for execve.  That part seems to work fine. However, in the detailed audit report my user id is associated with the execution.  Root owns the files there and ultimately root is the effective UID in the record, but why am I associated with the activity at all?
Audit version is: 2.0.4-1
Kernel version is: 2.6.32-71

I did not notice this behavior in RHEL5.

Regards,
Kevin

[-- Attachment #1.2: Type: text/html, Size: 5212 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2011-03-25 21:38 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-03-25 14:55 RedHat 6 Testing Boyce, Kevin P (AS)
2011-03-25 15:32 ` Sean.Hollinger
2011-03-25 15:39   ` Boyce, Kevin P (AS)
2011-03-25 16:15 ` Steve Grubb
2011-03-25 18:53   ` EXT :Re: " Boyce, Kevin P (AS)
2011-03-25 21:38     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox