From owner-freebsd-stable@FreeBSD.ORG Wed Sep 6 07:38:58 2006 Return-Path: X-Original-To: freebsd-stable@freebsd.org Delivered-To: freebsd-stable@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 0EDA416A4DF for ; Wed, 6 Sep 2006 07:38:58 +0000 (UTC) (envelope-from cristiano.deana@gmail.com) Received: from wx-out-0506.google.com (wx-out-0506.google.com [66.249.82.239]) by mx1.FreeBSD.org (Postfix) with ESMTP id 8FA6643D49 for ; Wed, 6 Sep 2006 07:38:57 +0000 (GMT) (envelope-from cristiano.deana@gmail.com) Received: by wx-out-0506.google.com with SMTP id i27so2556036wxd for ; Wed, 06 Sep 2006 00:38:56 -0700 (PDT) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:mime-version:content-type:content-transfer-encoding:content-disposition; b=fosUvjWnG92P3VQar62RKqkZtgfiwbIvRurK/x5u4+ZmPP75euAtH18gRKvR1by0NFzIPAEVDNGylTqzY1PNSvM6hd7Bf+DhzAYuqgZNg4cTrdmgNtZut2YziUKVif4PV4QUZ9pRUbm8+9QjOtQU/6EMABCP7b39c2goxamYDlU= Received: by 10.90.78.16 with SMTP id a16mr2045105agb; Wed, 06 Sep 2006 00:37:23 -0700 (PDT) Received: by 10.90.81.5 with HTTP; Wed, 6 Sep 2006 00:37:23 -0700 (PDT) Message-ID: Date: Wed, 6 Sep 2006 09:37:23 +0200 From: "Cristiano Deana" To: "FreeBSD Stable Mailing List" MIME-Version: 1.0 Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Content-Disposition: inline Subject: Problems with auditd X-BeenThere: freebsd-stable@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Production branch of FreeBSD source code List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 06 Sep 2006 07:38:58 -0000 Hi, i updated my system to -STABLE (FreeBSD mobile.deana.it 6.1-STABLE FreeBSD 6.1-STABLE #10: Wed Sep 6 08:20:43 CEST 2006) and followed instructions at http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/audit.html but when i tried to start auditd i got: # grep auditd /etc/rc.conf auditd_enable="YES" # /etc/rc.d/auditd start Starting auditd. # tail -6 /var/log/messages Sep 6 09:34:29 mobile auditd[3867]: auditctl failed setting log file! : Invalid argument Sep 6 09:34:29 mobile auditd[3867]: Log directories exhausted Sep 6 09:34:29 mobile auditd[3867]: Could not swap audit file Sep 6 09:34:29 mobile auditd[3867]: Error reading control file Sep 6 09:34:29 mobile cris: audit warning: getacdir /var/audit Sep 6 09:34:29 mobile cris: audit warning: nostart files in /etc/security has not been modified. where i'm wrong? thanks in advance. -- Cris, member of G.U.F.I Italian FreeBSD User Group http://www.gufi.org/