From mboxrd@z Thu Jan 1 00:00:00 1970 From: "MAUPERTUIS, PHILIPPE" Subject: RHEL 8 audit rules Date: Wed, 6 Nov 2019 09:39:54 +0000 Message-ID: <5F4EE10832231F4F921A255C1D95429819F47E@DEERLM99EX7MSX.ww931.my-it-solutions.net> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============8892289376088853480==" Return-path: Received: from mx1.redhat.com (ext-mx19.extmail.prod.ext.phx2.redhat.com [10.5.110.48]) by smtp.corp.redhat.com (Postfix) with ESMTPS id C4D32608AC for ; Wed, 6 Nov 2019 09:39:59 +0000 (UTC) Received: from smtppost.atos.net (smtppost.atos.net [193.56.114.176]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id A99BE307D844 for ; Wed, 6 Nov 2019 09:39:56 +0000 (UTC) Content-Language: fr-FR List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: "linux-audit@redhat.com" List-Id: linux-audit@redhat.com --===============8892289376088853480== Content-Language: fr-FR Content-Type: multipart/alternative; boundary="_000_5F4EE10832231F4F921A255C1D95429819F47EDEERLM99EX7MSXww9_" --_000_5F4EE10832231F4F921A255C1D95429819F47EDEERLM99EX7MSXww9_ Content-Type: text/plain; charset=WINDOWS-1252 Content-Transfer-Encoding: quoted-printable Hi, The rules proposed in /usr/share/doc/audit/rules/ contain 32 bits stuff. For example : ## 10.2.5.b All elevation of privileges is logged -a always,exit -F arch=3Db64 -S setuid -F a0=3D0 -F exe=3D/usr/bin/su -F ke= y=3D10.2.5.b-elevated-privs-session -a always,exit -F arch=3Db32 -S setuid -F a0=3D0 -F exe=3D/usr/bin/su -F ke= y=3D10.2.5.b-elevated-privs-session Is it still necessary for RHEL 8 ? Would the 21-no32bit.rules be enough ? Can we run any 32 bits binary on rhel 8 ? Regards Philippe equensWorldline is a registered trade mark and trading name owned by the Wo= rldline Group through its holding company. This e-mail and the documents attached are confidential and intended solely= for the addressee. If you receive this e-mail in error, you are not author= ized to copy, disclose, use or retain it. Please notify the sender immediat= ely and delete this email from your systems. As emails may be intercepted, = amended or lost, they are not secure. EquensWorldline and the Worldline Gro= up therefore can accept no liability for any errors or their content. Altho= ugh equensWorldline and the Worldline Group endeavours to maintain a virus-= free network, we do not warrant that this transmission is virus-free and ca= n accept no liability for any damages resulting from any virus transmitted.= The risks are deemed to be accepted by everyone who communicates with eque= nsWorldline and the Worldline Group by email --_000_5F4EE10832231F4F921A255C1D95429819F47EDEERLM99EX7MSXww9_ Content-Type: text/html; charset=WINDOWS-1252 Content-Transfer-Encoding: quoted-printable

Hi,

The rules proposed in /usr/shar= e/doc/audit/rules/ contain 32 bits stuff.

For example :=

## 10.2.5.b All elevation of pr= ivileges is logged

-a always,exit -F arch=3Db64 -S= setuid -F a0=3D0 -F exe=3D/usr/bin/su -F key=3D10.2.5.b-elevated-privs-ses= sion

-a always,exit -F arch=3Db32 -S= setuid -F a0=3D0 -F exe=3D/usr/bin/su -F key=3D10.2.5.b-elevated-privs-ses= sion

 

Is it still necessary for RHEL = 8 ?

Would the 21-no32bit.rules be e= nough ?

Can we run any 32 bits binary o= n rhel 8 ?

 

Regards

Philippe

equensWorldline is a registered trade mark and trading name owned by the= Worldline Group through its holding company.
This e-mail and the documents attached are confidential and intended solely= for the addressee. If you receive this e-mail in error, you are not author= ized to copy, disclose, use or retain it. Please notify the sender immediat= ely and delete this email from your systems. As emails may be intercepted, amended or lost, they are not secur= e. EquensWorldline and the Worldline Group therefore can accept no liabilit= y for any errors or their content. Although equensWorldline and the Worldli= ne Group endeavours to maintain a virus-free network, we do not warrant that this transmission is virus-fr= ee and can accept no liability for any damages resulting from any virus tra= nsmitted. The risks are deemed to be accepted by everyone who communicates = with equensWorldline and the Worldline Group by email

--_000_5F4EE10832231F4F921A255C1D95429819F47EDEERLM99EX7MSXww9_-- --===============8892289376088853480== Content-Type: text/plain; charset=WINDOWS-1252 MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Disposition: inline --===============8892289376088853480==--