[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#872726: linux: apparmor doesn't use proper audit event ids



On Sun, 20 Aug 2017 16:42:55 +0200 Laurent Bigonville <bigon@debian.org> wrote:
IMVHO, in regard to the recent proposal of enabling apparmor in debian
by default, this needs to be addressed first.

Yes this is very important, although we have aa-logprof to be used as auditing
tool, but I agree that not seeing AppArmor events in your custom auditd report
is rather bad.

We could ask John Johansen if he has it on it's queue. He is upstreaming Ubuntu
patches to mainline Linux, so I guess we depend on his work entirely.


Reply to: