Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-06-01 Thread Stefan Berger
On 06/01/2018 04:13 PM, Paul Moore wrote: On Fri, Jun 1, 2018 at 4:00 PM, Stefan Berger wrote: On 05/30/2018 07:34 PM, Richard Guy Briggs wrote: On 2018-05-30 17:38, Stefan Berger wrote: On 05/30/2018 05:22 PM, Paul Moore wrote: On Wed, May 30, 2018 at 9:08 AM, Stefan Berger wrote: On 05/3

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-06-01 Thread Paul Moore
On Fri, Jun 1, 2018 at 4:13 PM, Paul Moore wrote: > On Fri, Jun 1, 2018 at 4:00 PM, Stefan Berger > wrote: >> On 05/30/2018 07:34 PM, Richard Guy Briggs wrote: >>> >>> On 2018-05-30 17:38, Stefan Berger wrote: On 05/30/2018 05:22 PM, Paul Moore wrote: > > On Wed, May 30, 2018 at

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-06-01 Thread Paul Moore
On Fri, Jun 1, 2018 at 4:00 PM, Stefan Berger wrote: > On 05/30/2018 07:34 PM, Richard Guy Briggs wrote: >> >> On 2018-05-30 17:38, Stefan Berger wrote: >>> >>> On 05/30/2018 05:22 PM, Paul Moore wrote: On Wed, May 30, 2018 at 9:08 AM, Stefan Berger wrote: > > On 05/30/2018

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-06-01 Thread Stefan Berger
On 05/30/2018 07:34 PM, Richard Guy Briggs wrote: On 2018-05-30 17:38, Stefan Berger wrote: On 05/30/2018 05:22 PM, Paul Moore wrote: On Wed, May 30, 2018 at 9:08 AM, Stefan Berger wrote: On 05/30/2018 08:49 AM, Richard Guy Briggs wrote: On 2018-05-24 16:11, Stefan Berger wrote: The AUDIT_I

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-31 Thread Paul Moore
On Wed, May 30, 2018 at 8:46 PM, Lenny Bruzenak wrote: > On 05/30/2018 06:54 PM, Paul Moore wrote: > > ... > >> Finally, since you probably haven't followed all of the discussion >> around associating records into a single event, I wanted to give you >> my side of the story (if you don't care, you

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Lenny Bruzenak
On 05/30/2018 06:54 PM, Paul Moore wrote: ... > Finally, since you probably haven't followed all of the discussion > around associating records into a single event, I wanted to give you > my side of the story (if you don't care, you can simply skip the rest > of this email). Currently an audit "

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Paul Moore
On Wed, May 30, 2018 at 5:49 PM, Stefan Berger wrote: > On 05/30/2018 05:24 PM, Paul Moore wrote: >> >> On Wed, May 30, 2018 at 3:54 PM, Stefan Berger >> wrote: >>> >>> On 05/30/2018 12:27 PM, Steve Grubb wrote: On Wednesday, May 30, 2018 11:25:05 AM EDT Stefan Berger wrote: > >

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Richard Guy Briggs
On 2018-05-30 17:38, Stefan Berger wrote: > On 05/30/2018 05:22 PM, Paul Moore wrote: > > On Wed, May 30, 2018 at 9:08 AM, Stefan Berger > > wrote: > > > On 05/30/2018 08:49 AM, Richard Guy Briggs wrote: > > > > On 2018-05-24 16:11, Stefan Berger wrote: > > > > > The AUDIT_INTEGRITY_RULE is used f

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Mimi Zohar
On Wed, 2018-05-30 at 18:15 -0400, Stefan Berger wrote: > On 05/30/2018 06:00 PM, Mimi Zohar wrote: > > On Wed, 2018-05-30 at 17:49 -0400, Stefan Berger wrote: > >> So the other choice is to only keep patches 1,2, 6, and 7, so leave most > >> of the integrity audit messages untouched. Then only cre

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/30/2018 06:00 PM, Mimi Zohar wrote: On Wed, 2018-05-30 at 17:49 -0400, Stefan Berger wrote: So the other choice is to only keep patches 1,2, 6, and 7, so leave most of the integrity audit messages untouched. Then only create a different format for the new AUDIT_INTEGRITY_POLICY_RULE (curre

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Mimi Zohar
On Wed, 2018-05-30 at 17:49 -0400, Stefan Berger wrote: > > So the other choice is to only keep patches 1,2, 6, and 7, so leave most > of the integrity audit messages untouched. Then only create a different > format for the new AUDIT_INTEGRITY_POLICY_RULE (current 8/8) that shares > (for consis

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/30/2018 05:24 PM, Paul Moore wrote: On Wed, May 30, 2018 at 3:54 PM, Stefan Berger wrote: On 05/30/2018 12:27 PM, Steve Grubb wrote: On Wednesday, May 30, 2018 11:25:05 AM EDT Stefan Berger wrote: On 05/30/2018 11:15 AM, Steve Grubb wrote: On Wednesday, May 30, 2018 9:54:00 AM EDT Stef

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/30/2018 05:22 PM, Paul Moore wrote: On Wed, May 30, 2018 at 9:08 AM, Stefan Berger wrote: On 05/30/2018 08:49 AM, Richard Guy Briggs wrote: On 2018-05-24 16:11, Stefan Berger wrote: The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and the IMA "audit" policy action. This p

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Paul Moore
On Wed, May 30, 2018 at 3:54 PM, Stefan Berger wrote: > On 05/30/2018 12:27 PM, Steve Grubb wrote: >> >> On Wednesday, May 30, 2018 11:25:05 AM EDT Stefan Berger wrote: >>> >>> On 05/30/2018 11:15 AM, Steve Grubb wrote: On Wednesday, May 30, 2018 9:54:00 AM EDT Stefan Berger wrote: >

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Paul Moore
On Wed, May 30, 2018 at 9:08 AM, Stefan Berger wrote: > On 05/30/2018 08:49 AM, Richard Guy Briggs wrote: >> >> On 2018-05-24 16:11, Stefan Berger wrote: >>> >>> The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and >>> the IMA "audit" policy action. This patch defines >>> AUDIT_INTE

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/30/2018 12:27 PM, Steve Grubb wrote: On Wednesday, May 30, 2018 11:25:05 AM EDT Stefan Berger wrote: On 05/30/2018 11:15 AM, Steve Grubb wrote: On Wednesday, May 30, 2018 9:54:00 AM EDT Stefan Berger wrote: On 05/29/2018 05:30 PM, Steve Grubb wrote: Hello, On Thursday, May 24, 2018 4:1

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Steve Grubb
On Wednesday, May 30, 2018 11:25:05 AM EDT Stefan Berger wrote: > On 05/30/2018 11:15 AM, Steve Grubb wrote: > > On Wednesday, May 30, 2018 9:54:00 AM EDT Stefan Berger wrote: > >> On 05/29/2018 05:30 PM, Steve Grubb wrote: > >>> Hello, > >>> > >>> On Thursday, May 24, 2018 4:11:05 PM EDT Stefan B

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/30/2018 11:15 AM, Steve Grubb wrote: On Wednesday, May 30, 2018 9:54:00 AM EDT Stefan Berger wrote: On 05/29/2018 05:30 PM, Steve Grubb wrote: Hello, On Thursday, May 24, 2018 4:11:05 PM EDT Stefan Berger wrote: The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and the IMA

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Steve Grubb
On Wednesday, May 30, 2018 9:54:00 AM EDT Stefan Berger wrote: > On 05/29/2018 05:30 PM, Steve Grubb wrote: > > Hello, > > > > On Thursday, May 24, 2018 4:11:05 PM EDT Stefan Berger wrote: > >> The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and > >> the IMA "audit" policy action.

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/29/2018 05:30 PM, Steve Grubb wrote: Hello, On Thursday, May 24, 2018 4:11:05 PM EDT Stefan Berger wrote: The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and the IMA "audit" policy action. This patch defines AUDIT_INTEGRITY_POLICY_RULE to reflect the IMA policy rules. Wi

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Stefan Berger
On 05/30/2018 08:49 AM, Richard Guy Briggs wrote: On 2018-05-24 16:11, Stefan Berger wrote: The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and the IMA "audit" policy action. This patch defines AUDIT_INTEGRITY_POLICY_RULE to reflect the IMA policy rules. With this change we now

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Steve Grubb
On Wednesday, May 30, 2018 8:49:20 AM EDT Richard Guy Briggs wrote: > On 2018-05-24 16:11, Stefan Berger wrote: > > The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and > > the IMA "audit" policy action. This patch defines > > AUDIT_INTEGRITY_POLICY_RULE to reflect the IMA policy rul

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-30 Thread Richard Guy Briggs
On 2018-05-24 16:11, Stefan Berger wrote: > The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and > the IMA "audit" policy action. This patch defines > AUDIT_INTEGRITY_POLICY_RULE to reflect the IMA policy rules. > > With this change we now call integrity_audit_msg_common() to get >

Re: [PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-29 Thread Steve Grubb
Hello, On Thursday, May 24, 2018 4:11:05 PM EDT Stefan Berger wrote: > The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and > the IMA "audit" policy action. This patch defines > AUDIT_INTEGRITY_POLICY_RULE to reflect the IMA policy rules. > > With this change we now call integrity

[PATCH 8/8] ima: Differentiate auditing policy rules from "audit" actions

2018-05-24 Thread Stefan Berger
The AUDIT_INTEGRITY_RULE is used for auditing IMA policy rules and the IMA "audit" policy action. This patch defines AUDIT_INTEGRITY_POLICY_RULE to reflect the IMA policy rules. With this change we now call integrity_audit_msg_common() to get common integrity auditing fields. This now produces th