From ed1f049c0c1e1f6c0aaa63b78e88229d2d25a5b6 Mon Sep 17 00:00:00 2001
From: Watson Sato <wsato@redhat.com>
Date: Thu, 20 Sep 2018 22:23:10 +0200
Subject: [PATCH 1/2] Select rules for audit privileged commands
- crontab
- umount
---
rhel7/profiles/ospp42.profile | 2 ++
2 files changed, 4 insertions(+)
diff --git a/rhel7/profiles/ospp42.profile b/rhel7/profiles/ospp42.profile
index 58ad10b1be..8550434ffa 100644
--- a/rhel7/profiles/ospp42.profile
+++ b/rhel7/profiles/ospp42.profile
@@ -141,7 +141,9 @@ selections:
- audit_rules_dac_modification_lchown
- audit_rules_unsuccessful_file_modification_lchown
- audit_rules_privileged_commands_at
+ - audit_rules_privileged_commands_crontab
- audit_rules_privileged_commands_mount
+ - audit_rules_privileged_commands_umount
- audit_rules_privileged_commands_passwd
- audit_rules_privileged_commands_unix_chkpwd
- audit_rules_privileged_commands_userhelper