[PATCH] audit=0 appears not to completely disable auditing

Amy Griffis amy.griffis at hp.com
Mon Apr 2 18:57:11 UTC 2007


Steve Grubb wrote:  [Thu Mar 22 2007, 05:55:45PM EDT]
> > If you want audit_enabled=0 to turn off audit completely, do you also
> > want to drop selinux messages?
> 
> No, the SE Linux folks want avc messages at all times unless the admin 
> specifically sets a rule to suppress them. 

Okay, makes sense. Do you think audit should return an error if
someone tries to add a rule when audit_enabled=0 ?




More information about the Linux-audit mailing list