Hi,
A recently started thread on the linux-security-module mailing list may
be of interest to others here: Serge Hallyn has proposed LSM hooks to
allow security modules to control actions that affect the existing audit
framework rather than just performing CAP_SYS_ADMIN checks (or in some
cases, no checks at all at present). See the thread beginning at
http://marc.theaimsgroup.com/?l=linux-security-module&m=1095252764227...
--
Stephen Smalley <sds(a)epoch.ncsc.mil>
National Security Agency