Debian 6.0.3 system.
I have a problem when I have my RBAC policy enabled that logrotate doesn't work properly.
Firstly, there's no denies in the log to help me with this, thus my frustration.
What it'll do it move /var/log/syslog to /var/log/syslog.1 as it's supposed to, it also creates a new /var/log/syslog. But this file stays empty and it keeps writing to the /var/log/syslog.1 file, until I restart it.
If I don't have the RBAC system enabled - it works fine.
Does anyone have any clues/pointers as to how I could track this down? The lack of any grsec deny messages is what's really bugging me.