Re: [PATCH] audit: file system auditing based on location and name

From: Arjan van de Ven
Date: Fri Jul 08 2005 - 00:34:37 EST



> > [foo@liltux /]$ cat /etc/shadow
> > cat: /etc/shadow: Permission denied
>
> Additionally, the apps would need to either be rewritten to create
> the files under the audited context, or policy would have to cause all
> files created by those apps to be under the audited context. Neither
> one of those options is satisfactory

why not?
If your /etc/shadow has no selinux context you've lost already :0


-
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/