From b7bafe97c3abae823efb663377012a7a7a3e100e Mon Sep 17 00:00:00 2001 From: Sergio Correia Date: Mon, 21 Jun 2021 11:12:29 -0300 Subject: [PATCH] Enable default RHEL configuration This enables syscall auditing by default. Resolves: rhbz#1924561 --- audit.spec | 12 ++++++++---- 1 file changed, 8 insertions(+), 4 deletions(-) diff --git a/audit.spec b/audit.spec index b0782b0..b11e120 100644 --- a/audit.spec +++ b/audit.spec @@ -2,7 +2,7 @@ Summary: User space tools for kernel auditing Name: audit Version: 3.0.1 -Release: 3%{?dist} +Release: 4%{?dist} License: GPLv2+ URL: http://people.redhat.com/sgrubb/audit/ Source0: http://people.redhat.com/sgrubb/audit/%{name}-%{version}.tar.gz @@ -144,9 +144,8 @@ rm -f rules/Makefile* # Copy default rules into place on new installation files=`ls /etc/audit/rules.d/ 2>/dev/null | wc -w` if [ "$files" -eq 0 ] ; then -# FESCO asked for audit to be off by default. #1117953 - if [ -e %{_datadir}/%{name}/sample-rules/10-no-audit.rules ] ; then - cp %{_datadir}/%{name}/sample-rules/10-no-audit.rules /etc/audit/rules.d/audit.rules + if [ -e %{_datadir}/%{name}/sample-rules/10-base-config.rules ] ; then + cp %{_datadir}/%{name}/sample-rules/10-base-config.rules /etc/audit/rules.d/audit.rules else touch /etc/audit/rules.d/audit.rules fi @@ -260,6 +259,11 @@ fi %attr(750,root,root) /sbin/audispd-zos-remote %changelog +* Mon Jun 21 2021 Sergio Correia - 3.0.1-4 +- Enable default RHEL configuration + This enables syscall auditing by default. + Resolves: rhbz#1924561 + * Thu Apr 15 2021 Mohan Boddu - 3.0.1-3 - Rebuilt for RHEL 9 BETA on Apr 15th 2021. Related: rhbz#1947937