Thread (1 message) 1 message, 1 author, 2007-11-26

Re: Missing audit information in xfrm_audit_common_policyinfo()?

From: Paul Moore <hidden>
Date: 2007-11-26 16:52:03

On Monday 26 November 2007 11:47:09 am Joy Latten wrote:
Paul Moore [off-list ref] wrote on 11/21/2007 03:34:31 PM:
quoted
I just noticed that the IPsec auditing code does not appear to audit the

netmask for the selector source and destination addresses in
xfrm_audit_common_policyinfo().  Before I threw a patch together I
thought I
quoted
would check to see if there was a reason for this that I am missing ...
I don't think we ever discussed including netmask when we added the
ipsec audit info...
Hmmm ... okay.  I'm almost certain it should be included when auditing changes 
to the SPD as the netmask/prefixlen is very important when considering which 
traffic will be matched by a particular SPD entry.

I'm working on a patch now.

-- 
paul moore
linux security @ hp
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help