Hide Forgot
Need to add "-w /etc/shadow -p wa" to /etc/audit/audit.rules file so that selinux generates better information. Nothing should be writing to /etc/shadow, and if something does it should be audited.