lspp.rules and time changes

Steve m6x at ornl.gov
Tue Jul 18 18:18:39 UTC 2006


I know updating contrib/lspp.rules isn't a priority, but if anyone is 
trying to catch changes to the system time, you may find this useful...

I tried out the rule in lspp.rules that should catch changes in the 
system time and discovered that it doesn't catch changes made by the 
date command.  date uses the clock_settime syscall instead of adjtimex 
or settimeofday.

Steve




More information about the Linux-audit mailing list