Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-58838

All auditd-plugins files are processed, even those not having ".conf" suffix, which somehow breaks the common naming rules

    • Icon: Story Story
    • Resolution: Unresolved
    • Icon: Undefined Undefined
    • rhel-10.0
    • None
    • audit
    • None
    • rhel-sst-security-special-projects
    • ssg_security
    • 16
    • None
    • False
    • Hide

      None

      Show
      None
    • No
    • Red Hat Enterprise Linux
    • None
    • Unspecified Release Note Type - Unknown
    • None

      After much troubleshooting of a customer issue, where he wasn't able to disable the sedipatch plugin, it appears that we found out the reason was the customer had created a backup of sedispatch.conf with naming sedispatch.conf_<date>, which caused auditd to process the file anyway, despite not having a .conf extension.

      This behavior is documented in the auditd-plugins(5) man page but looks totally counter-intuitive and somehow breaks the common standard naming rules used for every other component shipped on RHEL (e.g. systemd, httpd, selinux, dracut and many more).

      It would be great to avoid this odd behavior and stick to common habits.

              scorreia@redhat.com Sergio Correia
              rhn-support-rmetrich Renaud Métrich
              Sergio Correia Sergio Correia
              SSG Security QE SSG Security QE
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated: