17c478bd9Sstevel@tonic-gate#! /sbin/sh 27c478bd9Sstevel@tonic-gate# 37c478bd9Sstevel@tonic-gate# CDDL HEADER START 47c478bd9Sstevel@tonic-gate# 57c478bd9Sstevel@tonic-gate# The contents of this file are subject to the terms of the 6*6927f468Sdp# Common Development and Distribution License (the "License"). 7*6927f468Sdp# You may not use this file except in compliance with the License. 87c478bd9Sstevel@tonic-gate# 97c478bd9Sstevel@tonic-gate# You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE 107c478bd9Sstevel@tonic-gate# or http://www.opensolaris.org/os/licensing. 117c478bd9Sstevel@tonic-gate# See the License for the specific language governing permissions 127c478bd9Sstevel@tonic-gate# and limitations under the License. 137c478bd9Sstevel@tonic-gate# 147c478bd9Sstevel@tonic-gate# When distributing Covered Code, include this CDDL HEADER in each 157c478bd9Sstevel@tonic-gate# file and include the License file at usr/src/OPENSOLARIS.LICENSE. 167c478bd9Sstevel@tonic-gate# If applicable, add the following below this CDDL HEADER, with the 177c478bd9Sstevel@tonic-gate# fields enclosed by brackets "[]" replaced with your own identifying 187c478bd9Sstevel@tonic-gate# information: Portions Copyright [yyyy] [name of copyright owner] 197c478bd9Sstevel@tonic-gate# 207c478bd9Sstevel@tonic-gate# CDDL HEADER END 217c478bd9Sstevel@tonic-gate# 227c478bd9Sstevel@tonic-gate# 23*6927f468Sdp# Copyright 2006 Sun Microsystems, Inc. All rights reserved. 247c478bd9Sstevel@tonic-gate# Use is subject to license terms. 257c478bd9Sstevel@tonic-gate# 267c478bd9Sstevel@tonic-gate# ident "%Z%%M% %I% %E% SMI" 277c478bd9Sstevel@tonic-gate 287c478bd9Sstevel@tonic-gate# if the audit state is "disabled" auditconfig returns 297c478bd9Sstevel@tonic-gate# non-zero exit status unless the c2audit module is loaded; 307c478bd9Sstevel@tonic-gate# if c2audit is loaded, "disabled" becomes "noaudit" early 317c478bd9Sstevel@tonic-gate# in the boot cycle and "auditing" only after auditd starts. 327c478bd9Sstevel@tonic-gate 337c478bd9Sstevel@tonic-gate. /lib/svc/share/smf_include.sh 347c478bd9Sstevel@tonic-gate 357c478bd9Sstevel@tonic-gateAUDITCONFIG=/usr/sbin/auditconfig 367c478bd9Sstevel@tonic-gate 377c478bd9Sstevel@tonic-gateAUDITCOND=`$AUDITCONFIG -getcond 2> /dev/null` 387c478bd9Sstevel@tonic-gate 397c478bd9Sstevel@tonic-gateif [ $? -ne 0 ]; then 407c478bd9Sstevel@tonic-gate # The decision whether to start 417c478bd9Sstevel@tonic-gate # auditing is driven by bsmconv / bsmunconv 427c478bd9Sstevel@tonic-gate /usr/sbin/svcadm mark maintenance system/auditd 437c478bd9Sstevel@tonic-gate exit $SMF_EXIT_MON_OFFLINE; 447c478bd9Sstevel@tonic-gatefi 457c478bd9Sstevel@tonic-gate 467c478bd9Sstevel@tonic-gate# In a non-global zone, auditd is started only if the "perzone" 477c478bd9Sstevel@tonic-gate# audit policy has been set. 48*6927f468Sdpif smf_is_nonglobalzone; then 497c478bd9Sstevel@tonic-gate echo `$AUDITCONFIG -getpolicy` | grep perzone > /dev/null 507c478bd9Sstevel@tonic-gate 517c478bd9Sstevel@tonic-gate if [ $? -eq 1 ]; then 527c478bd9Sstevel@tonic-gate echo "$0: auditd is not configured to run in a local zone" 537c478bd9Sstevel@tonic-gate exit $SMF_EXIT_ERR_CONFIG; 547c478bd9Sstevel@tonic-gate fi 557c478bd9Sstevel@tonic-gatefi 567c478bd9Sstevel@tonic-gate 577c478bd9Sstevel@tonic-gate/etc/security/audit_startup 587c478bd9Sstevel@tonic-gate# daemon forks, parent exits when child says it's ready 597c478bd9Sstevel@tonic-gateexec /usr/sbin/auditd 607c478bd9Sstevel@tonic-gate 61