lspp.rules and time changes
Steve
m6x at ornl.gov
Tue Jul 18 18:18:39 UTC 2006
I know updating contrib/lspp.rules isn't a priority, but if anyone is
trying to catch changes to the system time, you may find this useful...
I tried out the rule in lspp.rules that should catch changes in the
system time and discovered that it doesn't catch changes made by the
date command. date uses the clock_settime syscall instead of adjtimex
or settimeofday.
Steve
More information about the Linux-audit
mailing list