public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* Setting Audit Rules
@ 2011-07-25 18:27 Rye, Gene R.
  2011-07-25 19:06 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Rye, Gene R. @ 2011-07-25 18:27 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 394 bytes --]

I am attempting to secure a RHEL 5 64bit system.  I am modifying the
stig.rules file to use as the audit.rules file.  The NSA guide
identifies some rules requiring the ARCH value to be either 64b or 32b.
Some existing rules have both OS versions being audited.  Should I leave
both available even though my system is 64b or should I only use the 64b
options?

Thanks

Gene Rye

 


[-- Attachment #1.2: Type: text/html, Size: 4631 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Setting Audit Rules
  2011-07-25 18:27 Setting Audit Rules Rye, Gene R.
@ 2011-07-25 19:06 ` Steve Grubb
  0 siblings, 0 replies; 2+ messages in thread
From: Steve Grubb @ 2011-07-25 19:06 UTC (permalink / raw)
  To: linux-audit; +Cc: Rye, Gene R.

On Monday, July 25, 2011 02:27:33 PM Rye, Gene R. wrote:
> I am attempting to secure a RHEL 5 64bit system.  I am modifying the
> stig.rules file to use as the audit.rules file.  The NSA guide
> identifies some rules requiring the ARCH value to be either 64b or 32b.
> Some existing rules have both OS versions being audited.  Should I leave
> both available even though my system is 64b or should I only use the 64b
> options?

All 64 bit x86_64 systems have both a 64 and 32 bit interface. So, you want both. 32 
bit system don't and you would only want 32 bit values for it.

-Steve

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2011-07-25 19:06 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-07-25 18:27 Setting Audit Rules Rye, Gene R.
2011-07-25 19:06 ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox