From mboxrd@z Thu Jan 1 00:00:00 1970 From: Robert Evans Subject: Confused about audit=1 in grub.conf Date: Thu, 28 Oct 2010 15:40:58 -0400 Message-ID: <4CC9D1CA.3050802@jhuapl.edu> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============1531204813555223907==" Return-path: Received: from mx1.redhat.com (ext-mx08.extmail.prod.ext.phx2.redhat.com [10.5.110.12]) by int-mx02.intmail.prod.int.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id o9SJfG2Z032725 for ; Thu, 28 Oct 2010 15:41:16 -0400 Received: from jhuapl.edu (piper.jhuapl.edu [128.244.251.37]) by mx1.redhat.com (8.13.8/8.13.8) with ESMTP id o9SJf0GU004341 for ; Thu, 28 Oct 2010 15:41:01 -0400 List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============1531204813555223907== Content-Type: text/html; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit Hi,

I did some research and am confused about starting the audit daemon at boot time, so that you don't get auid's of 4294967295.

In RHEL 5.5, my grub.conf looks like this:

audit=1
# grub.conf generated by anaconda
#
# Note that you do not have to rerun grub after making changes to this file
# NOTICE:  You have a /boot partition.  This means that
#          all kernel and initrd paths are relative to /boot/, eg.
#          root (hd0,0)
#          kernel /vmlinuz-version ro root=/dev/sda4
#          initrd /initrd-version.img
#boot=/dev/sda
default=0
timeout=5
splashimage=(hd0,0)/grub/splash.xpm.gz
hiddenmenu
title Red Hat Enterprise Linux Server (2.6.18-194.el5)
        root (hd0,0)
        kernel /vmlinuz-2.6.18-194.el5 ro root=LABEL=/ rhgb quiet
        initrd /initrd-2.6.18-194.el5.img

audit=1 is the first line, so why am I still getting the 4294967295 auid's?

Thanks

--===============1531204813555223907== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============1531204813555223907==--