Re: [PATCH] audit: listen in all network namespaces

2013-07-30 Thread Richard Guy Briggs
On Mon, Jul 22, 2013 at 11:20:57AM +0800, Gao feng wrote: On 07/20/2013 05:15 AM, Richard Guy Briggs wrote: On Wed, Jul 17, 2013 at 11:54:21AM +0800, Gao feng wrote: Hi, Richard On 07/17/2013 04:32 AM, Richard Guy Briggs wrote: Convert audit from only listening in init_net to use

Rational behind RefuseManualStop=yes in auditd.service

2013-07-30 Thread Laurent Bigonville
Hi, I would like to know the rational behind RefuseManualStop=yes in auditd.service file. I'm currently looking at upgrading the audit package in debian and RefuseManualStop=yes is preventing the daemon to be restarted during upgrade. Looking at systemd.unit(5) manpage, I don't have the feeling

Re: Rational behind RefuseManualStop=yes in auditd.service

2013-07-30 Thread Steve Grubb
On Tuesday, July 30, 2013 10:04:46 PM Laurent Bigonville wrote: Hi, I would like to know the rational behind RefuseManualStop=yes in auditd.service file. Common Criteria requires that we have the identity of the user altering any audit settings such as whether its running or not. Systemctl