audit/protected-kernel-modules.patch
Cropi 9875489357 Allow defining rules for /usr/lib/modules dir
Resolves: RHEL-59013
augenrules: fix return code if immutable mode is set
Resolves: RHEL-40109
2025-06-09 10:17:26 +02:00

15 lines
488 B
Diff

diff --git a/init.d/auditd.service b/init.d/auditd.service
index 8210c60eb..dd7ec694b 100644
--- a/init.d/auditd.service
+++ b/init.d/auditd.service
@@ -38,7 +38,8 @@ MemoryDenyWriteExecute=true
LockPersonality=true
# The following control prevents rules on /proc so its off by default
#ProtectControlGroups=true
-ProtectKernelModules=true
+## The following control prevents rules on /usr/lib/modules/ its off by default
+#ProtectKernelModules=true
RestrictRealtime=true
[Install]