-
Story
-
Resolution: Can't Do
-
Normal
-
None
-
rhel-9.0.0
-
Medium
-
rhel-sst-security-special-projects
-
ssg_security
-
None
-
False
-
-
None
-
None
-
None
-
None
-
If docs needed, set a value
-
-
All
-
None
Description of problem:
With RHEL7, "RefuseManualStop=yes" is defined in auditd service unit. This prevents admins to restart auditd to reload rules for example.
But there is a trick, using "service auditd restart" just works fine, the protection is hence very weak.
There are also other ways to achieve this: "pkill -TERM auditd" then "systemctl start auditd".
I think this "protection" should be removed from the unit file, it just annoys sysadmins and is definitely useless.
Version-Release number of selected component (if applicable):
audit-2.8.5 and later