Hello,
I've just released a new version of the audit daemon. It can be downloaded
from
http://people.redhat.com/sgrubb/audit It will also be in rawhide
tomorrow. The Changelog is:
- Fix ausearch to handle missing audit log better
- Fix auditctl blank line handling
- Trim trailing '/' from file system watches in auditctl
- Catch cases where parameter was passed without option being given to
auditctl
- Add CAPP sample configuration
This is mostly a bug fix release. This release also features a first draft
sample CAPP configuration from Amy Griffis of HP. It will be updated as we
finalize security concerns.
If anyone sees problems, please let me know.
-Steve