Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

The auditd checks should process the actively running rules #6597

Closed
trevor-vaughan opened this issue Feb 3, 2021 · 4 comments
Closed

The auditd checks should process the actively running rules #6597

trevor-vaughan opened this issue Feb 3, 2021 · 4 comments

Comments

@trevor-vaughan
Copy link
Collaborator

Description of problem:

The default configuration of auditd will cause rules to not be loaded after the first failing rule. This means that, while the checks may pass, the actual rules loaded at runtime may be completely blank.

SCAP Security Guide Version:

All

Operating System Version:

Any

@trevor-vaughan trevor-vaughan changed the title The auditd rules should check the running rules The auditd checks should process the actively running rules Feb 3, 2021
@yuumasato
Copy link
Member

Checking the runtime environment with OVAL can be tricky, we can't just run the auditctl -l command.
Do you have ideas how this could be done?

@yuumasato
Copy link
Member

Well, the answer is in the future with auditdline_test:
OVAL-Community/OVAL#112

@gdidot
Copy link

gdidot commented Feb 16, 2021

The proposal is now present at OVAL-Community/OVAL#114

@Mab879
Copy link
Member

Mab879 commented Nov 14, 2024

Until the above OVAL issue is closed we will close this issue.

No comment on the OVAL issue since 2021. :(

@Mab879 Mab879 closed this as not planned Won't fix, can't repro, duplicate, stale Nov 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants