Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

including audit in Fedora CoreOS #461

Open
dustymabe opened this issue Apr 15, 2020 · 1 comment
Open

including audit in Fedora CoreOS #461

dustymabe opened this issue Apr 15, 2020 · 1 comment

Comments

@dustymabe
Copy link
Member

@dustymabe dustymabe commented Apr 15, 2020

We have been discussing whether or not to include the audit rpm (includes the audit daemon) in Fedora CoreOS. The discussion started over in #220 and we also discussed it in the the community meeting today.

There are some changes upstream that we'd like to track/discuss that include:

What others exist?

Also if you are a user and need the audit tools, please speak up so we can get a feeling for how much need there is.

@egeturgay

This comment has been minimized.

Copy link

@egeturgay egeturgay commented Apr 21, 2020

+1 for auditctl and augenrules (not full blown auditd) , we currently use (on CoreOS) for enabling auditd's file integrity management feature by adding rules where it's a requirement from a PCI compliance perspective.

additional rules land into /etc/audit/rules.d on CoreOS with configs such as
-w /etc -p wa -k file_integrity
and a systemd unit is provided for restarting auditd upon config change named audit-rules

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
2 participants
You can’t perform that action at this time.