From sacadmin Tue Nov 24 12:21:24 2009
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id nAOKLOIb011492;
	Tue, 24 Nov 2009 12:21:24 -0800 (PST)
Received: (from gww@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id nAOKLOdj011488;
	Tue, 24 Nov 2009 12:21:24 -0800 (PST)
Date: Tue, 24 Nov 2009 12:21:24 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Message-Id: <200911242021.nAOKLOdj011488@sac.sfbay.sun.com>
To: PSARC-record@sac.sfbay.sun.com
Cc: audit-core@sun.com
Subject: audit_control EOL and removal [PSARC/2009/642 FastTrack]
Status: RO
Content-Length: 565


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 audit_control EOL and removal
    1.2. Name of Document Author/Supplier:
	 Author:  Jan Friedel
    1.3  Date of This Document:
	24 November, 2009
4. Technical Description
    See the case directory for more detail

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From gww@sac.sfbay.sun.com Sat Jan  9 14:08:14 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o09M8EdY027069
	for <psarc-ext@sac.sfbay.sun.com>; Sat, 9 Jan 2010 14:08:14 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o09M8E2C024717;
	Sat, 9 Jan 2010 14:08:14 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KW000L012TQ4A00@nwk-avmta-2.sfbay.sun.com>; Sat,
 09 Jan 2010 14:08:14 -0800 (PST)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KW0005242TQP460@nwk-avmta-2.sfbay.sun.com>; Sat,
 09 Jan 2010 14:08:14 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o09M88va000918; Sat, 09 Jan 2010 14:08:08 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o09M88w7027067; Sat,
 09 Jan 2010 14:08:08 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id o09M88mJ027066; Sat, 09 Jan 2010 14:08:08 -0800 (PST)
Date: Sat, 09 Jan 2010 14:08:08 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: PSARC/2009/642 audit_control(4) EOL and removal
To: psarc-ext@sun.com
Cc: audit-core@sun.com, jan.friedel@sun.com, sharon.read@sun.com
Message-id: <201001092208.o09M88mJ027066@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 7427

I'm sponsoring this case for Jan Friedel and the Solaris Audit project team.
It is the second phase of converting the audit service configuration to
SMF.  The first phase was PSARC/2009/022 audit_startup(1m) EOL and removal.

PSARC/2008/787 Obsolete of some Solaris Audit commands and PSARC/2009/636
Obsolete getacinfo(3bsm) announced Obsolescence (EOF) of a number Solaris
Audit interfaces in the next Patch release.

When the audit service, auditd(1m), was created (6232332 auditd should run
under SMF) as part of the conversion from /etc/rc scripts to SMF
(PSARC/2002/547 Greenline) the configuration information in audit_startup(1m)
and audit_control(4) were not converted.  This case proposes to provide the
configuration information contained in audit_control in audit service private
properties and to remove audit_control(4) in a Minor release.

Copies of the Obsolete audit_control(4) and getacinfo(3bsm) man pages, a
diff marked auditconfig(1m) man page and the new proposed audit_flags(5)
man page, as well as the delivered audit_control file are in the case
directory.

The interface taxonomy of auditconfig(1m) is unchange (Committed).

For reference purposes a "references" subdirectory is provided with other
related man pages and a prototype audit service manifest.

The timer is set for 19 Jan 2010.

Gary..
+++++++++++++++++++++++++++++++++

Background:
==========
audit_control(4) is a file that contains configuration of the default
audit classes (flags: and naflags: keywords) [see audit_flags(5) and
audit_class(4)] and audit trail destinations (plugin: keyword) [the dir:
and minfree: keywords were effectively EOLed but not removed by PSARC/2002/150
Secure Remote Audit Log -- "Secure" a misnomer here].  An administrator can
configure these by editing the audit_control file.

Proposal:
========
Project Private properties are added to auditd(1m).

    1) Remove the Obsolete Committed audit_control(4) file from the system.
    2) As the audit_control(4) file was not world readable,
       add Project Private read protected SMF property groups (PSARC/2007/177
       SMF Read-Protected Property Storage) to contain the persistent
       values for the default audit flags and audit trail destinations.
    3) Remove the Obsolete Committed getacinfo(3bsm) APIs from the system.
       These interfaces are used to access fields in the audit_control file.
    4) Add project private properties to the audit service to contain
       the information in the removed audit_control file.
    5) Add auditconfig(1m) subcommands -getflags, -getnaflags, -getplugin,
       -setflags, -setnaflags, -setplugin to display and set the default
       audit classes and audit trail destinations.
    6) Modify auditd(1m) to initialize the default audit classes and audit
       trail destinations from audit service properties.
    7) Deliver the service manifest with slightly different default
       configuration from what audit_control contained (flags lo, naflags lo,
       plugin audit_binfile(5) active).  audit_control flags were empty and
       naflags were lo, which would audit for failed events of the "login"
       class, but not for successful ones.  The change is to audit both
       successful and failed logins when auditing is enabled.  audit_binfile
       default is unchanged.
    8) Update au_user_mask(3bsm) to use default audit classes configured in
       the audit service.

auditconfig(1m):
NAME
     auditconfig - configure auditing

SYNOPSIS
     auditconfig subcommand ...

  SUBCOMMANDS

+    -getflags
+	 Display the default audit preselection flags.

+    -getnaflags
+	 Display the non-attributable audit mask.

+    -getplugin [name]
+	 Display information about the plugin name.  If name is not
+	 specified, display all plugins.

+    -setflags audit_flags
+	 Set the default audit classes, see audit_flags(5).  The default
+	 audit classes are combined with the user's specific audit
+	 flags to form the user's process audit preselection mask.
	 
+    -setnaflags audit_flags
+	 Set the non-attributable audit classes, see audit_flags(5).
+	 Non-attributable audit classes define what classes of events
+	 are to be audited when the action cannot be attributed to
+	 an authenticated user.  Failed login is an example of an
+	 event that is non-attributable.

+    -setplugin name active | inactive [ attributes [ qsize]]
+	 Configure the plugin name to be "active" or "inactive".
+	 Optionally configure the attributes and number of
+	 unprocessed audit records to queue for the plugin.
+	 See the audit plugin man pages and auditd(1m).

NOTES

+    The change to plugins (-setplugin) settings do not take effect
+    (such as becoming active or inactive, changing the active attribute
+    or queue size values) until the audit service is refreshed.  Use
+    audit(1M) to refresh the audit service.

Notes:
======
    1) Activation of updates (except for flags:) to the current
       audit_control(4) required refreshing the audit service.
    2) The removed audit_control(4) man page contained the primary
       description of the syntax for specifying user audit flags.
       audit_flags(5) is proposed to provide that information.
    3) New audit service plugins may be added within the Solaris
       distribution by distributing an updated service manifest.
       3rd party audit service plugins may be added by using svccfg(1m)
       to add the appropriate property group information.
    4) Activation of both flags (-setflags) and naflags (-setnaflags)
       requires no additional steps.  Activation of plugins (-setplugin
       <name> active) still requires refreshing the audit service.
       See 1) above.

Issues:
=======
    1) Many man pages refer to audit_control(4).  The project team plans
       to use this as an opportunity to refresh and align these man pages.
       The updates are not documented as part of this case.
    2) audit_control(4) will not be automatically converted.  The currently
       understood conversion for Solaris 10 to Solaris next is a fresh
       install.  "What's New" documentation will be provided:

	    If you have modified the audit_control(4) file, you will
	    need to use auditconfig(1M) to configure the audit service
	    with your modifications.
	    o use auditconfig -getflags, -getnaflags, -getplugin
	      to display the current configuration
	    o use auditconfig -setflags <the value of the audit_control(4)
	      flags:>
	    o use auditconfig -setnaflags <the value of the audit_control(4)
	      naflags:>
	    o for any audit_control(4) plugin: configured, use
	      auditconfig -setplugin to activate and configure the same
	      attributes (p_* values), and qsize
	    o if the audit_control(4) obsolete dir: and/or minfree: are
	      configured, use
	      auditconfig -setplugin binfile active "p_dir=<dir: value>;
	      p_minfree=<minfree: value>"

    3) The policy for read protected properties states that values should
       not be delivered in the manifest.
       The project team believes that compatibility with the existing
       default which is openly documented in the Solaris Auditing section
       of the System Administration Guide section of the Solaris Security
       Services document is sufficient motivation for delivering audit_binfile
       configured and active.
http://docs.sun.com/app/docs/doc/816-4557/auditref-12?l=en&a=view&q=audit_control

From Darren.Moffat@sun.com Mon Jan 11 01:44:13 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0B9iDHm022444
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 11 Jan 2010 01:44:13 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o0B9iD6H005661;
	Mon, 11 Jan 2010 01:44:13 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KW200103TPPHN00@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 11 Jan 2010 01:44:13 -0800 (PST)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KW200IZPTPOQ310@nwk-avmta-1.sfbay.Sun.COM>; Mon,
 11 Jan 2010 01:44:13 -0800 (PST)
Received: from fe-emea-10.sun.com
 (gmp-eb-lb-1-fe1.eu.sun.com [192.18.6.7] (may be forged))
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id o0B9iBju011618; Mon,
 11 Jan 2010 09:44:11 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KW200300T2O6000@fe-emea-10.sun.com>; Mon, 11 Jan 2010 09:43:55 +0000 (GMT)
Received: from [192.168.1.105]
 (cpc2-rdng20-2-0-cust917.15-3.cable.virginmedia.com [86.28.167.150])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 with ESMTPSA id <0KW200F6ETP17VB0@fe-emea-10.sun.com>; Mon,
 11 Jan 2010 09:43:49 +0000 (GMT)
Date: Mon, 11 Jan 2010 09:43:48 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: PSARC/2009/642 audit_control(4) EOL and removal
In-reply-to: <201001092208.o09M88mJ027066@sac.sfbay.sun.com>
Sender: Darren.Moffat@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: psarc-ext@sun.com, audit-core@sun.com, Jan.Friedel@sun.com,
        Sharon.Read@sun.com
Message-id: <4B4AF2D4.2060405@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <201001092208.o09M88mJ027066@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.23 (X11/20091124)
Status: RO
Content-Length: 164

+1 for the case as specified.  I particularly like the change so that 
successful logins are audited by default as soon as auditing is enabled.

--
Darren J Moffat

From sharon.read@sun.com Mon Jan 11 08:53:09 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0BGr9Hl029041
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 11 Jan 2010 08:53:09 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o0BGr8dS007911;
	Mon, 11 Jan 2010 10:53:08 -0600 (CST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KW300901DKJLH00@brm-avmta-1.central.sun.com>; Mon,
 11 Jan 2010 09:53:08 -0700 (MST)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KW300EZODKJRZB0@brm-avmta-1.central.sun.com>; Mon,
 11 Jan 2010 09:53:07 -0700 (MST)
Received: from [129.146.68.172] (thought.SFBay.Sun.COM [129.146.68.172])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id o0BGr6EE635452; Mon, 11 Jan 2010 08:53:06 -0800 (PST)
Date: Mon, 11 Jan 2010 08:47:11 -0800
From: Sharon Veach <sharon.read@sun.com>
Subject: Re: PSARC/2009/642 audit_control(4) EOL and removal
In-reply-to: <4B4AF2D4.2060405@Sun.COM>
To: Darren J Moffat <Darren.Moffat@sun.com>
Cc: Gary Winiger <gww@sac.sfbay.sun.com>, psarc-ext@sun.com,
        audit-core@sun.com, Jan.Friedel@sun.com
Message-id: <4B4B560F.7020206@sun.com>
Organization: Sun Microsystems, Inc
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <201001092208.o09M88mJ027066@sac.sfbay.sun.com>
 <4B4AF2D4.2060405@Sun.COM>
User-Agent: Mozilla/5.0 (X11; U; SunOS sun4u; en-US; rv:1.9.1.5) Gecko/20091202
 Thunderbird/3.0
Status: RO
Content-Length: 258

All logins, not just root login?  Sharon

On 01/11/10 01:43, Darren J Moffat wrote:
> +1 for the case as specified.  I particularly like the change so that 
> successful logins are audited by default as soon as auditing is enabled.
>
> -- 
> Darren J Moffat

From gww@eng.sun.com Mon Jan 11 09:26:59 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0BHQx8g000043
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 11 Jan 2010 09:26:59 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o0BHQvQm036527;
	Mon, 11 Jan 2010 10:26:59 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KW300C0ZF4YU700@brm-avmta-1.central.sun.com>; Mon,
 11 Jan 2010 10:26:58 -0700 (MST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KW300EM6F4XRXE0@brm-avmta-1.central.sun.com>; Mon,
 11 Jan 2010 10:26:57 -0700 (MST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o0BHQr32016243; Mon, 11 Jan 2010 09:26:53 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id o0BHPLHO029062; Mon,
 11 Jan 2010 09:25:21 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id o0BHPLve029061; Mon,
 11 Jan 2010 09:25:21 -0800 (PST)
Date: Mon, 11 Jan 2010 09:25:21 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: PSARC/2009/642 audit_control(4) EOL and removal
To: Darren.Moffat@sun.com, sharon.read@sun.com
Cc: gww@sac.sfbay.sun.com, psarc-ext@sun.com, audit-core@sun.com,
        Jan.Friedel@sun.com
Message-id: <201001111725.o0BHPLve029061@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 600

> All logins, not just root login?  Sharon


Proposal:
========
Project Private properties are added to auditd(1m).

    7) Deliver the service manifest with slightly different default
       configuration from what audit_control contained (flags lo, naflags lo,
       plugin audit_binfile(5) active).  audit_control flags were empty and
       naflags were lo, which would audit for failed events of the "login"
       class, but not for successful ones.  The change is to audit both
       successful and failed logins when auditing is enabled.  audit_binfile
       default is unchanged.

Gary..

From gww@sac.sfbay.sun.com Wed Jan 20 10:50:14 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0KIoEWm014618
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 20 Jan 2010 10:50:14 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o0KIoD35009063;
	Wed, 20 Jan 2010 11:50:14 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KWK00E0D6ZP2600@nwk-avmta-2.sfbay.sun.com>; Wed,
 20 Jan 2010 10:50:14 -0800 (PST)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KWK00AQU6ZPQE90@nwk-avmta-2.sfbay.sun.com>; Wed,
 20 Jan 2010 10:50:13 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o0KIo7jC014049; Wed, 20 Jan 2010 10:50:07 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0KIo7F7014615; Wed,
 20 Jan 2010 10:50:07 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id o0KIo7X2014614; Wed, 20 Jan 2010 10:50:07 -0800 (PST)
Date: Wed, 20 Jan 2010 10:50:07 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: PSARC/2009/642 audit_control(4) EOL and removal
To: psarc-ext@sun.com
Cc: audit-core@sun.com, jan.friedel@sun.com, sharon.read@sun.com
Message-id: <201001201850.o0KIo7X2014614@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 290

> I'm sponsoring this case for Jan Friedel and the Solaris Audit project team.
> It is the second phase of converting the audit service configuration to
> SMF.  The first phase was PSARC/2009/022 audit_startup(1m) EOL and removal.

	This case was approved at today's PSARC meeting.

Gary..

