xref: /freebsd/share/man/man4/audit.4 (revision 9ca971bce635a96d04ea01ba2d04ed981c6d726b)
10739bd60SRobert Watson.\" Copyright (c) 2006 Robert N. M. Watson
20739bd60SRobert Watson.\" All rights reserved.
30739bd60SRobert Watson.\"
40739bd60SRobert Watson.\" Redistribution and use in source and binary forms, with or without
50739bd60SRobert Watson.\" modification, are permitted provided that the following conditions
60739bd60SRobert Watson.\" are met:
70739bd60SRobert Watson.\" 1. Redistributions of source code must retain the above copyright
80739bd60SRobert Watson.\"    notice, this list of conditions and the following disclaimer.
90739bd60SRobert Watson.\" 2. Redistributions in binary form must reproduce the above copyright
100739bd60SRobert Watson.\"    notice, this list of conditions and the following disclaimer in the
110739bd60SRobert Watson.\"    documentation and/or other materials provided with the distribution.
120739bd60SRobert Watson.\"
130739bd60SRobert Watson.\" THIS SOFTWARE IS PROVIDED BY THE AUTHORS AND CONTRIBUTORS ``AS IS'' AND
140739bd60SRobert Watson.\" ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
150739bd60SRobert Watson.\" IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
160739bd60SRobert Watson.\" ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHORS OR CONTRIBUTORS BE LIABLE
170739bd60SRobert Watson.\" FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
180739bd60SRobert Watson.\" DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
190739bd60SRobert Watson.\" OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
200739bd60SRobert Watson.\" HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
210739bd60SRobert Watson.\" LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
220739bd60SRobert Watson.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
230739bd60SRobert Watson.\" SUCH DAMAGE.
240739bd60SRobert Watson.\"
250739bd60SRobert Watson.\" $FreeBSD$
260739bd60SRobert Watson.\"
270739bd60SRobert Watson.Dd February 2, 2006
280739bd60SRobert Watson.Os
290739bd60SRobert Watson.Dt AUDIT 4
300739bd60SRobert Watson.Sh NAME
310739bd60SRobert Watson.Nm audit
320739bd60SRobert Watson.Nd Security Event Audit
330739bd60SRobert Watson.Sh SYNOPSIS
340739bd60SRobert Watson.Cd "options AUDIT"
350739bd60SRobert Watson.Sh DESCRIPTION
360739bd60SRobert WatsonSecurity Event Audit is a facility to provide fine-grained, configurable
370739bd60SRobert Watsonlogging of security-relevant events, and is intended to meet the requirements
380739bd60SRobert Watsonof the Common Criteria (CC) Common Access Protection Profile (CAPP)
390739bd60SRobert Watsonevaluation.
400739bd60SRobert WatsonThe
410739bd60SRobert Watson.Fx
420739bd60SRobert Watsonaudit facility implements the de facto industry standard BSM API, file
430739bd60SRobert Watsonformats, and command line interface, first found in the Solaris operating
440739bd60SRobert Watsonsystem.
450739bd60SRobert WatsonInformation on the user space implementation can be found in
469ca971bcSChristian Brueffer.Xr libbsm 3 .
470739bd60SRobert Watson.Pp
480739bd60SRobert WatsonAudit support is enabled at boot, if present in the kernel, using an
490739bd60SRobert Watson.Xr rc.conf 5
500739bd60SRobert Watsonflag.
510739bd60SRobert WatsonThe audit daemon,
520739bd60SRobert Watson.Xr auditd 8 ,
530739bd60SRobert Watsonis responsible for configuring the kernel to perform audit, pushing
540739bd60SRobert Watsonconfiguration data from the various audit configuration files into the
550739bd60SRobert Watsonkernel.
560739bd60SRobert Watson.Sh SEE ALSO
570739bd60SRobert Watson.Xr auditreduce 1 ,
580739bd60SRobert Watson.Xr praudit 1 ,
590739bd60SRobert Watson.Xr audit 2 ,
600739bd60SRobert Watson.Xr auditctl 2 ,
610739bd60SRobert Watson.Xr auditon 2 ,
620739bd60SRobert Watson.Xr getaudit 2 ,
630739bd60SRobert Watson.Xr getauid 2 ,
640739bd60SRobert Watson.Xr setaudit 2 ,
650739bd60SRobert Watson.Xr setauid 2 ,
660739bd60SRobert Watson.Xr libbsm 3 ,
670739bd60SRobert Watson.Xr audit.log 5 ,
680739bd60SRobert Watson.Xr audit_class 5 ,
690739bd60SRobert Watson.Xr audit_control 5 ,
700739bd60SRobert Watson.Xr audit_event 5 ,
710739bd60SRobert Watson.Xr audit_user 5 ,
720739bd60SRobert Watson.Xr audit_warn 5 ,
730739bd60SRobert Watson.Xr event_code 5 ,
740739bd60SRobert Watson.Xr rc.conf 5 ,
750739bd60SRobert Watson.Xr audit 8 ,
760739bd60SRobert Watson.Xr auditd 8
770739bd60SRobert Watson.Sh AUTHORS
780739bd60SRobert WatsonThis software was created by McAfee Research, the security research division
790739bd60SRobert Watsonof McAfee, Inc., under contract to Apple Computer Inc.
800739bd60SRobert WatsonAdditional authors include Wayne Salamon, Robert Watson, and SPARTA Inc.
810739bd60SRobert Watson.Pp
820739bd60SRobert WatsonThe Basic Security Module (BSM) interface to audit records and audit event
830739bd60SRobert Watsonstream format were defined by Sun Microsystems.
840739bd60SRobert Watson.Pp
850739bd60SRobert WatsonThis manual page was written by
860739bd60SRobert Watson.An Robert Watson Aq rwatson@FreeBSD.org .
870739bd60SRobert Watson.Sh HISTORY
880739bd60SRobert WatsonThe OpenBSM implementation was created by McAfee Research, the security
890739bd60SRobert Watsondivision of McAfee Inc., under contract to Apple Computer Inc. in 2004.
900739bd60SRobert WatsonIt was subsequently adopted by the TrustedBSD Project as the foundation for
910739bd60SRobert Watsonthe OpenBSM distribution.
920739bd60SRobert Watson.Pp
930739bd60SRobert WatsonSupport for kernel audit first appeared in
940739bd60SRobert Watson.Fx 6.1 .
950739bd60SRobert Watson.Sh BUGS
960739bd60SRobert WatsonThe audit facility in
970739bd60SRobert Watson.Fx
980739bd60SRobert Watsonis considered experimental, and production deployment should occur only after
990739bd60SRobert Watsoncareful consideration of the risks of deploying experimental software.
1000739bd60SRobert Watson.Pp
1010739bd60SRobert WatsonThe
1020739bd60SRobert Watson.Fx
1030739bd60SRobert Watsonkernel does not fully validate that audit records submitted by user
1040739bd60SRobert Watsonapplications are syntactically valid BSM; as submission of records is limited
1050739bd60SRobert Watsonto privileged processes, this is not a critical bug.
1060739bd60SRobert Watson.Pp
1070739bd60SRobert WatsonInstrumentation of auditable events in the kernel is not complete, as some
1080739bd60SRobert Watsonsystem calls do not generate audit records, or generate audit records with
1090739bd60SRobert Watsonincomplete argument information.
1100739bd60SRobert Watson.Pp
1110739bd60SRobert WatsonMandatory Access Control (MAC) labels, as provided by the
1120739bd60SRobert Watson.Xr mac 4
1130739bd60SRobert Watsonfacility, are not audited as part of records involving MAC decisions.
114