Re: Warning: MFC of security event audit support RELENG_6 in the next 2-3 weeks




On Wed, 16 Aug 2006, Robert Watson wrote:

Dear 6-STABLE users,

In the next 2-3 weeks, I plan to MFC support for CAPP security eventing auditing from 7-CURRENT to 6-STABLE. The implementation has been running quite nicely in -CURRENT for several months. Right now, I'm just waiting on a confirmation from Sun regarding formal allocation of a BSM header version number so as to avoid accidental version number conflicts in the future, which I hope to get this week, as well as a bug fix in the handling of per-pipe preselection, which Christian Peron is currently working on. The audit implementation will be considered an experimental feature in 6.2-RELEASE, but in practice runs quite well, so is ready for more wide-spread deployment.

Dear 6-STABLE users,

After a couple of weeks of settling, polishing, etc, the MFC of audit support is about to begin. Over the next couple of days, the 6-STABLE build may be briefly broken as inter-dependent components are merged. I do not anticipate any serious disruption, but some caution is called for. In principle, all the potentially tricky kernel ABI dependencies, etc, were dealt with before 6.0-RELEASE, such as changes in the size of the kernel system call data structures. The approximate merge plan, run by re@ a few days ago, is as follows:

- Merge OpenBSM contrib subtree detached from build.

- Merge kernel trees (src/sys/bsm, src/sys/security/audit), attach to build.

- Merge kernel audit event hooks across the kernel. In principle, we've
reserved space in the syscall table, etc, so that there is no disruptive
kernel ABI change for critical data structures.

- Merge OpenBSM library and command line tools build, as well as install of
/etc/security, /etc/rc.d files.

- Merge kernel man pages (src/share/man/man4/audit*).

- Merge user space tool changes, such as to login, sshd, su, etc, so that
events are audited.

- Loose ends, such as make.conf man page, etc.

- Update Handbook to indicate that Audit applies to 6.x and 7.x.

I will send out a status e-mail once the merge is completed, and send out a notice if any problems are encountered. If you experience any problems, especially problems not related to the build (which will likely get picked up and fixed quickly, if they occur), please let me know. I'm especially interested in any issues relating to changes in ability to log in, programs exiting due to using unrecognized system calls (SIGSYS), etc. As I said above, these sorts of problems are unlikely to occur, but if they do occur, I'd like to fix them as quickly as possible. I would like to have the merge largely done by 4 September 2006, although it's possible a few straggling tweaks will come in after that.

Thanks,

Robert N M Watson
Computer Laboratory
University of Cambridge
_______________________________________________
freebsd-stable@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-stable
To unsubscribe, send any mail to "freebsd-stable-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Warning: MFC of security event audit support RELENG_6 in the next 2-3 weeks
    ... I plan to MFC support for CAPP security eventing auditing from 7-CURRENT to 6-STABLE. ... The audit implementation will be considered an experimental feature in 6.2-RELEASE, but in practice runs quite well, so is ready for more wide-spread deployment. ... In principle, all the potentially tricky kernel ABI dependencies, etc, were dealt with before 6.0-RELEASE, such as changes in the size of the kernel system call data structures. ...
    (FreeBSD-Security)
  • Re: Q on audit, audit-syscall: insecure?
    ... How does this audit method overcome the well known security ... audit time, and a second, different object is used when the kernel ... the user space buffer into the kernel space buffer which the kernel ... systems have been known to achieve CAPP and LSPP certification. ...
    (Linux-Kernel)
  • Re: [linux-usb-devel] why was MODALIAS removed from usb kernel events? [u]
    ... in the usb-interface event, and they only exist in the usb-device event? ... And MODALIAS is not what you miss, and the subject of the mail is ... I'm coming from a different side, as I know not much about the kernel ... same plan: migration plan first, enough time to adjust the software and get ...
    (Linux-Kernel)
  • Re: netstat issue on Tru64. Kernel bug?
    ... You can maybe get this info using the audit subsystem, ... If audit is not supported by your kernel, you can doconfig a new kernel ... Loic Domaigne wrote: ...
    (comp.unix.tru64)
  • Alpha tftp bootloader kernel stack not valid halt
    ... I have an AlphaPC 164LX that I've decided to try Plan 9 on, ... Bootp works great, the loader loads, the loader loads its configuration ... perfectly, but as soon as it gets the first block of the kernel, the ... Intel 8255x isn't known to work with Plan 9 on Alpha, ...
    (comp.os.plan9)