Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 20 Apr 2009 22:17:12 +0200
From:      =?ISO-8859-1?Q?Eirik_=D8verby?= <ltning@anduin.net>
To:        freebsd-security@freebsd.org
Subject:   Audit(d) and jails
Message-ID:  <4BD35D05-473B-46EB-A96F-EA18234FED9D@anduin.net>

next in thread | raw e-mail | index | archive | help
Hi all,

I've been struggling lately to find a way to use the audit  
functionality in any meaningful way while using jails. My original  
idea was running auditd on the host, and thus get audit data for all  
the jails - however this proves impractical as identifying, for  
instance, the path of an executable inside a jail is impossible (it  
shows as //usr/bin/something in the logs). I have also failed to run  
auditd inside the jails, and doing so would somehow reduce its value -  
as the idea is to lock down the host and audit from there.

I see there is a SOC project to make audit jail-aware, but I'm sure  
I've missed something in the current implementation (7.1) as well.  
Could anyone share their experiences on this with me - or am I on the  
wrong track entirely?

Thanks,
/Eirik



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4BD35D05-473B-46EB-A96F-EA18234FED9D>