* Missing audit information in xfrm_audit_common_policyinfo()?
@ 2007-11-21 21:34 Paul Moore
0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2007-11-21 21:34 UTC (permalink / raw)
To: linux-audit, netdev, Joy Latten
I just noticed that the IPsec auditing code does not appear to audit the
netmask for the selector source and destination addresses in
xfrm_audit_common_policyinfo(). Before I threw a patch together I thought I
would check to see if there was a reason for this that I am missing ...
--
paul moore
linux security @ hp
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: Missing audit information in xfrm_audit_common_policyinfo()?
[not found] <OFDEF5C6F1.0AEFC4FF-ON8725739F.005BF832-8625739F.005C2038@us.ibm.com>
@ 2007-11-26 16:52 ` Paul Moore
0 siblings, 0 replies; 2+ messages in thread
From: Paul Moore @ 2007-11-26 16:52 UTC (permalink / raw)
To: Joy Latten; +Cc: netdev, linux-audit
On Monday 26 November 2007 11:47:09 am Joy Latten wrote:
> Paul Moore <paul.moore@hp.com> wrote on 11/21/2007 03:34:31 PM:
> > I just noticed that the IPsec auditing code does not appear to audit the
> >
> > netmask for the selector source and destination addresses in
> > xfrm_audit_common_policyinfo(). Before I threw a patch together I
>
> thought I
>
> > would check to see if there was a reason for this that I am missing ...
>
> I don't think we ever discussed including netmask when we added the
> ipsec audit info...
Hmmm ... okay. I'm almost certain it should be included when auditing changes
to the SPD as the netmask/prefixlen is very important when considering which
traffic will be matched by a particular SPD entry.
I'm working on a patch now.
--
paul moore
linux security @ hp
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2007-11-26 16:52 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-11-21 21:34 Missing audit information in xfrm_audit_common_policyinfo()? Paul Moore
[not found] <OFDEF5C6F1.0AEFC4FF-ON8725739F.005BF832-8625739F.005C2038@us.ibm.com>
2007-11-26 16:52 ` Paul Moore
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).