Steve Grubb wrote: [Thu Mar 22 2007, 05:55:45PM EDT] > > If you want audit_enabled=0 to turn off audit completely, do you also > > want to drop selinux messages? > > No, the SE Linux folks want avc messages at all times unless the admin > specifically sets a rule to suppress them.
Okay, makes sense. Do you think audit should return an error if someone tries to add a rule when audit_enabled=0 ? -- Linux-audit mailing list [email protected] https://www.redhat.com/mailman/listinfo/linux-audit
