From mboxrd@z Thu Jan 1 00:00:00 1970 From: Bill Tangren Subject: Re: Status of /etc/audit/filter.conf Date: Wed, 25 Apr 2007 16:35:23 -0400 Message-ID: <462FBB8B.1040102@usno.navy.mil> References: <39d2723b0704231309m3f4aaa64tf5e58477f15c2198@mail.gmail.com> Mime-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Return-path: Received: from mx1.redhat.com (mx1.redhat.com [172.16.48.31]) by int-mx1.corp.redhat.com (8.13.1/8.13.1) with ESMTP id l3PKZPwX008803 for ; Wed, 25 Apr 2007 16:35:26 -0400 Received: from [198.116.61.254] (beatrix.usno.navy.mil [198.116.61.254]) by mx1.redhat.com (8.13.1/8.13.1) with ESMTP id l3PKZO1X032213 for ; Wed, 25 Apr 2007 16:35:24 -0400 Received: from [10.1.5.58] (mach2.usno.navy.mil [10.1.5.58]) by aa.usno.navy.mil (Postfix) with ESMTP id 9456F205698 for ; Wed, 25 Apr 2007 16:35:23 -0400 (EDT) In-Reply-To: <39d2723b0704231309m3f4aaa64tf5e58477f15c2198@mail.gmail.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com Aaron Lippold wrote: > Hello All, > > Silly question 1: > > I have a security checking script that is complaining that my system > is not able to audit all discretionary access to control permission > modifications. > > To verify this it is looking for /etc/audit/filter.conf > > Is this still the correct place to look on RHEL4/5? I'd assume not > since I can't find a man page on audit-filter.conf anymore. > > Silly Question 2: > > If not, where and how would I add this feature to my audit configuration? > > Thanks, > > Aaron The Linux SRR script you are referring to (GEN002800, I think) was broken as of the January version of the SRR. They might have fixed it in the March version, I don't know.