[PATCH] LSPP audit enablement: storing selinux ocontext and scontext

Amy Griffis amy.griffis at hp.com
Thu Jul 28 19:03:00 UTC 2005


Hi Dustin,

I have some comments about this patch as well, but I think I'll
hold them until we discuss the LSPP audit requirements.  As Steve
previously mentioned, it's really not appropriate to be looking at
code when we haven't yet discussed what needs to be done.

Dustin Kirkland wrote:     [Thu Jul 21 2005, 11:48:41AM EDT]
> The attached patch contains functionality specified by the labeled
> security protection profile--basically appending object context and
> subject context labels to audit records.

If you have already researched the requirements, please include a
listing with your patch, along with an explanation of how your patch
meets those requirements.  There is more to it than "basically
appending object context and subject context labels to audit records".

If you haven't done any investigation, let us know, so someone can
work up a first draft of the requirements for us to discuss.

Thanks,
Amy




More information about the Linux-audit mailing list