audit file system

Discuss usability issues, general maintenance, and general support issues for a grsecurity-enabled system.

audit file system

Postby arkepp » Mon Oct 07, 2002 8:50 pm

Someone in the ext3-user newsgroup mentioned that grsecurity could *possibly* do what I need:

I need to audit a file system so that I get logs similar to
<date> <time> <user> <file> <action>

Is it true that grsecurity can do thi s or will be able to in the future? Couldn't find it in the docs, but I would imagine it would be a extremely usefull feature for a lot of sysadmins... sometimes plenty of backup and limiting access simply doesn't cut it.

Thanks for reading,
Arne
arkepp
 
Posts: 1
Joined: Mon Oct 07, 2002 8:44 pm

Postby spender » Mon Oct 07, 2002 9:54 pm

Right now we have limited auditing. Auditing will be built into the rewritten version of the ACL system and will audit virtually all filesystem related calls.

-Brad
spender
 
Posts: 2185
Joined: Wed Feb 20, 2002 8:00 pm


Return to grsecurity support