From owner-freebsd-security@FreeBSD.ORG Wed Jun 29 19:49:23 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 2657C106566B; Wed, 29 Jun 2011 19:49:23 +0000 (UTC) (envelope-from patpro@patpro.net) Received: from rack.patpro.net (rack.patpro.net [193.30.227.216]) by mx1.freebsd.org (Postfix) with ESMTP id CC3A58FC08; Wed, 29 Jun 2011 19:49:22 +0000 (UTC) Received: from rack.patpro.net (localhost [127.0.0.1]) by rack.patpro.net (Postfix) with ESMTP id BFB261CC020; Wed, 29 Jun 2011 21:49:21 +0200 (CEST) X-Virus-Scanned: amavisd-new at patpro.net Received: from amavis-at-patpro.net ([127.0.0.1]) by rack.patpro.net (rack.patpro.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id 8tk1McEoSH9N; Wed, 29 Jun 2011 21:49:19 +0200 (CEST) Received: from [127.0.0.1] (localhost [127.0.0.1]) by rack.patpro.net (Postfix) with ESMTP; Wed, 29 Jun 2011 21:49:19 +0200 (CEST) Mime-Version: 1.0 (Apple Message framework v1084) Content-Type: multipart/signed; boundary=Apple-Mail-7-357277473; protocol="application/pkcs7-signature"; micalg=sha1 From: Patrick Proniewski X-Priority: 3 (Normal) In-Reply-To: <696682733.20110629182327@serebryakov.spb.ru> Date: Wed, 29 Jun 2011 21:49:19 +0200 Message-Id: <5AD25EEF-D753-4480-9809-613447A470AC@patpro.net> References: <1191160420.20110629145915@serebryakov.spb.ru> <696682733.20110629182327@serebryakov.spb.ru> To: Lev Serebryakov X-Mailer: Apple Mail (2.1084) X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: Liste FreeBSD-security Subject: Re: OpenBSM: does somebody work on it? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Jun 2011 19:49:23 -0000 --Apple-Mail-7-357277473 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 On 29 juin 2011, at 16:23, Lev Serebryakov wrote: > Hello, Patrick. > You wrote 29 =D0=B8=D1=8E=D0=BD=D1=8F 2011 =D0=B3., 16:26:44: >=20 >> I do, almost (I've not finished my settup, but I'm auditing a = production server). >> May be you'll find this interesting: >> http://forums.freebsd.org/showthread.php?t=3D23716#9 > It seems, even system ftpd doesn't use setaudit() :( as long as it uses login to log users into the system, I don't think it = needs to use setaudit(). But I'm no BSM guru at all :) The audit system starts auditing a user as soon at he(r) logs in on the = system. I'll give ftpd a try if I have some spare time. patpro= --Apple-Mail-7-357277473--