netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Missing audit information in xfrm_audit_common_policyinfo()?
@ 2007-11-21 21:34 Paul Moore
  0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2007-11-21 21:34 UTC (permalink / raw)
  To: linux-audit, netdev, Joy Latten

I just noticed that the IPsec auditing code does not appear to audit the 
netmask for the selector source and destination addresses in 
xfrm_audit_common_policyinfo().  Before I threw a patch together I thought I 
would check to see if there was a reason for this that I am missing ...

-- 
paul moore
linux security @ hp

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: Missing audit information in xfrm_audit_common_policyinfo()?
       [not found] <OFDEF5C6F1.0AEFC4FF-ON8725739F.005BF832-8625739F.005C2038@us.ibm.com>
@ 2007-11-26 16:52 ` Paul Moore
  0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2007-11-26 16:52 UTC (permalink / raw)
  To: Joy Latten; +Cc: netdev, linux-audit

On Monday 26 November 2007 11:47:09 am Joy Latten wrote:
> Paul Moore <paul.moore@hp.com> wrote on 11/21/2007 03:34:31 PM:
> > I just noticed that the IPsec auditing code does not appear to audit the
> >
> > netmask for the selector source and destination addresses in
> > xfrm_audit_common_policyinfo().  Before I threw a patch together I
>
> thought I
>
> > would check to see if there was a reason for this that I am missing ...
>
> I don't think we ever discussed including netmask when we added the
> ipsec audit info...

Hmmm ... okay.  I'm almost certain it should be included when auditing changes 
to the SPD as the netmask/prefixlen is very important when considering which 
traffic will be matched by a particular SPD entry.

I'm working on a patch now.

-- 
paul moore
linux security @ hp

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2007-11-26 16:52 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-11-21 21:34 Missing audit information in xfrm_audit_common_policyinfo()? Paul Moore
     [not found] <OFDEF5C6F1.0AEFC4FF-ON8725739F.005BF832-8625739F.005C2038@us.ibm.com>
2007-11-26 16:52 ` Paul Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).