From owner-freebsd-security@FreeBSD.ORG Wed Jun 29 12:44:51 2011 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 69AB8106566C; Wed, 29 Jun 2011 12:44:51 +0000 (UTC) (envelope-from patpro@patpro.net) Received: from rack.patpro.net (rack.patpro.net [193.30.227.216]) by mx1.freebsd.org (Postfix) with ESMTP id EA57A8FC16; Wed, 29 Jun 2011 12:44:50 +0000 (UTC) Received: from rack.patpro.net (localhost [127.0.0.1]) by rack.patpro.net (Postfix) with ESMTP id 998C71CC020; Wed, 29 Jun 2011 14:26:49 +0200 (CEST) X-Virus-Scanned: amavisd-new at patpro.net Received: from amavis-at-patpro.net ([127.0.0.1]) by rack.patpro.net (rack.patpro.net [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id ETJCTJnR95i7; Wed, 29 Jun 2011 14:26:44 +0200 (CEST) Received: from [127.0.0.1] (localhost [127.0.0.1]) by rack.patpro.net (Postfix) with ESMTP; Wed, 29 Jun 2011 14:26:44 +0200 (CEST) Mime-Version: 1.0 (Apple Message framework v1084) Content-Type: multipart/signed; boundary=Apple-Mail-9-330722501; protocol="application/pkcs7-signature"; micalg=sha1 From: Patrick Proniewski X-Priority: 3 (Normal) In-Reply-To: <1191160420.20110629145915@serebryakov.spb.ru> Date: Wed, 29 Jun 2011 14:26:44 +0200 Message-Id: References: <1191160420.20110629145915@serebryakov.spb.ru> To: Lev Serebryakov X-Mailer: Apple Mail (2.1084) X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Cc: Liste FreeBSD-security Subject: Re: OpenBSM: does somebody work on it? X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Wed, 29 Jun 2011 12:44:51 -0000 --Apple-Mail-9-330722501 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=us-ascii On 29 juin 2011, at 12:59, Lev Serebryakov wrote: > auditreduce doesn't filter events by date (-b/-a/-d options with any > arguments produces empty output), it doesn't merge files properly and > doesn't pick up files automagically, as Solaris' one does. It doesn't > have -C/-M/-O functionality of Solaris' one, too. So, proper merging > of audit trial files seems to be impossible :( >=20 > I could try to fix & extend auditreduce(1), but does somebdy but me > need it? >=20 > Does somebody use audit on FreeBSD on production systems? I do, almost (I've not finished my settup, but I'm auditing a production = server). May be you'll find this interesting: = http://forums.freebsd.org/showthread.php?t=3D23716#9 patpro= --Apple-Mail-9-330722501--