Bug 794861

Summary: RFE: Add audit rule to generate better selinux audit information
Product: [Retired] oVirt Reporter: Perry Myers <pmyers>
Component: ovirt-nodeAssignee: Mike Burns <mburns>
Status: CLOSED CURRENTRELEASE QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: acathrow, cshao, dyasny, fdeutsch, gouyang, jboggs, leiwang, mburns, ovirt-bugs, ovirt-maint, ycui
Target Milestone: ---Keywords: FutureFeature
Target Release: 3.4.3   
Hardware: Unspecified   
OS: Unspecified   
Whiteboard:
Fixed In Version: 2.6.0 Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-10-04 12:20:01 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Bug Depends On:    
Bug Blocks: 829023    

Description Perry Myers 2012-02-17 19:35:41 UTC
Need to add "-w /etc/shadow -p wa" to /etc/audit/audit.rules file so that selinux generates better information.

Nothing should be writing to /etc/shadow, and if something does it should be audited.