All of lore.kernel.org
 help / color / mirror / Atom feed
* configuration for busy docker host
@ 2018-08-20  9:56 Frederik Bosch
  2018-08-20 14:10 ` Frederik Bosch
  2018-08-20 17:48 ` Steve Grubb
  0 siblings, 2 replies; 8+ messages in thread
From: Frederik Bosch @ 2018-08-20  9:56 UTC (permalink / raw)
  To: linux-audit

Hello Audit team,

As I have not found a location anywhere else on the web, I am sending my 
question to this list. I have an Ubuntu 18.04 machine with auditd and it 
acts as a Docker Host machine. I have hardened the system via this 
package: https://github.com/konstruktoid/hardening which installs auditd 
with the configuration to be found here: 
https://github.com/konstruktoid/hardening/blob/master/misc/audit.rules.

The problems I have are related to the directives -f and -b. The 
hardening package uses -b 8192 and -f 2. That results in a kernel panic 
very quickly because of audit backlog limit exceeded, and that causes a 
reboot of the system. Now I wonder what a good configuration would be. I 
started reading on the subject and read that -f 2 is probably the best 
for security reasons. However, I do not want to have a system that 
panics very quickly and reboots.

Should I simply increase the backlog to much higher numbers? Or should I 
change -f to not cause a kernel panic? Or am I missing something and 
should I change some other configuration? Thanks for your help.

Kind regards,
Frederik Bosch

^ permalink raw reply	[flat|nested] 8+ messages in thread

end of thread, other threads:[~2018-08-23 16:01 UTC | newest]

Thread overview: 8+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2018-08-20  9:56 configuration for busy docker host Frederik Bosch
2018-08-20 14:10 ` Frederik Bosch
2018-08-20 17:48 ` Steve Grubb
2018-08-22 11:40   ` Frederik Bosch
2018-08-22 12:42     ` Steve Grubb
2018-08-22 14:49       ` Frederik Bosch
2018-08-23 14:18         ` Steve Grubb
2018-08-23 16:01           ` Frederik Bosch

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.