linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* auid=0
@ 2015-08-03 18:11 rshaw1
  2015-08-03 18:21 ` auid=0 Steve Grubb
  0 siblings, 1 reply; 4+ messages in thread
From: rshaw1 @ 2015-08-03 18:11 UTC (permalink / raw)
  To: linux-audit

Comparing the "official" STIG content with the scap-security-guide
content, the former seems to have added corresponding rules for "-F
auid=0" that aren't present in scap-security guide.  i.e. where
scap-security-guide will just have one rule:

-a always,exit -F arch=ARCH -S <a bunch of stuff> -F auid>=500 -F
auid!=4294967295 -k delete

the official content will have the above plus:

-a always,exit -F arch=ARCH -S <a bunch of stuff> -F auid=0 -k delete

Is the addition necessary?  It doesn't seem to be, as the rules caught
root usage of, for example, chmod just fine without it (I had used su; not
sure if there's a difference between that and other ways of being root.) 
I would like to make sure I'm right before asking one group or the other
to delete or add it, respectively.

--Ray

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2015-08-03 19:06 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-03 18:11 auid=0 rshaw1
2015-08-03 18:21 ` auid=0 Steve Grubb
2015-08-03 18:53   ` auid=0 rshaw1
2015-08-03 19:06     ` auid=0 Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).