Bug 794861 - RFE: Add audit rule to generate better selinux audit information
Summary: RFE: Add audit rule to generate better selinux audit information
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: oVirt
Classification: Retired
Component: ovirt-node
Version: unspecified
Hardware: Unspecified
OS: Unspecified
low
low
Target Milestone: ---
: 3.4.3
Assignee: Mike Burns
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 829023
TreeView+ depends on / blocked
 
Reported: 2012-02-17 19:35 UTC by Perry Myers
Modified: 2016-04-26 20:47 UTC (History)
11 users (show)

Fixed In Version: 2.6.0
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2012-10-04 12:20:01 UTC
oVirt Team: ---


Attachments (Terms of Use)

Description Perry Myers 2012-02-17 19:35:41 UTC
Need to add "-w /etc/shadow -p wa" to /etc/audit/audit.rules file so that selinux generates better information.

Nothing should be writing to /etc/shadow, and if something does it should be audited.


Note You need to log in before you can comment on or make changes to this bug.