Re: A question

2018-09-24 Thread Frank Thommen
All systems I know disallow reading of /etc/shadow for others or even group (for good reasons). Hence sudo would be required. frank On 09/24/2018 06:35 AM, William Roberts wrote: Sorry for the HTML... This seems off topic. This is list for questions surrounding the linux audit subsystem.

auditing automounted filesystems (NFS)

2018-04-06 Thread Frank Thommen
Hello, we have started auditing on our systems (file open, close, write etc.). This is no problem on local and on statically mounted NFS systems (-a exit,always -F dir=/a/b/c ...). However for automounted filesystems auditd only reports on system calls on those filesystems which are mounted

Re: auditing automounted filesystems (NFS)

2018-04-07 Thread Frank Thommen
On 07/04/18 13:56, Richard Guy Briggs wrote: On 2018-04-07 04:04, Frank Thommen wrote: Hello, we have started auditing on our systems (file open, close, write etc.). This is no problem on local and on statically mounted NFS systems (-a exit,always -F dir=/a/b/c ...). However for automounted

Re: auditing automounted filesystems (NFS)

2018-04-08 Thread Frank Thommen
On 08/04/18 03:08, Richard Guy Briggs wrote: On 2018-04-07 18:38, Frank Thommen wrote: On 07/04/18 13:56, Richard Guy Briggs wrote: On 2018-04-07 04:04, Frank Thommen wrote: Hello, we have started auditing on our systems (file open, close, write etc.). This is no problem on local and on

Re: auditing automounted filesystems (NFS)

2018-04-09 Thread Frank Thommen
On 04/07/2018 06:38 PM, Frank Thommen wrote: On 07/04/18 13:56, Richard Guy Briggs wrote: On 2018-04-07 04:04, Frank Thommen wrote: Hello, we have started auditing on our systems (file open, close, write etc.). This is no problem on local and on statically mounted NFS systems (-a exit

Re: auditing automounted filesystems (NFS)

2018-04-19 Thread Frank Thommen
Hi, On 04/09/2018 07:45 PM, Frank Thommen wrote: On 04/07/2018 06:38 PM, Frank Thommen wrote: On 07/04/18 13:56, Richard Guy Briggs wrote: On 2018-04-07 04:04, Frank Thommen wrote: Hello, we have started auditing on our systems (file open, close, write etc.). This is no problem on local