audit 0.6.10 released

Steve Grubb sgrubb at redhat.com
Fri Apr 1 19:39:00 UTC 2005


Hello,

Another audit package has been released. This release is mostly code cleanups 
and getting things finalized for Fedora Core 4. It can be downloaded from 
http://people.redhat.com/sgrubb/audit

The changelog includes:

- Code cleanups
- Support the arch field for auditctl
- Add version to auditctl command
- Documentation updates
- Moved default location of the audit log to /var/log/audit/audit.log

The default location for the audit log was moved for a couple reasons. We want 
to put it in a place that could be used as a mount point. People doing any 
serious auditing need to have a partition set aside just for auditing. This 
move, by default, will make it easier for people to do that. We also wanted 
to put it in its own directory so that we can add some SE Linux policy later 
to protect the logs.

The audit watch list code is not in this release. I feel that we still need to 
discuss the way it needs to work and solidify that before I put it into the 
FC4 distribution. The watch add & remove I think are fine and the code is 
included so that one day when this gets upstream and that kernel gets 
released, everyone can start using it.

Let me know if there are any problems with this latest release.

Thanks,
-Steve Grubb




More information about the Linux-audit mailing list