From gww@sac.sfbay.sun.com Fri Jan  1 20:04:29 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0244TdO018522
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 1 Jan 2010 20:04:29 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o0244Sxi059840;
	Fri, 1 Jan 2010 21:04:29 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVL00G05PZG2A00@nwk-avmta-2.sfbay.sun.com>; Fri,
 01 Jan 2010 20:04:28 -0800 (PST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVL000ZJPZGGU80@nwk-avmta-2.sfbay.sun.com>; Fri,
 01 Jan 2010 20:04:28 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o0244RMG001179; Fri, 01 Jan 2010 20:04:27 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o0244QGP018517; Fri,
 01 Jan 2010 20:04:26 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id o0244QPA018513; Fri, 01 Jan 2010 20:04:26 -0800 (PST)
Date: Fri, 01 Jan 2010 20:04:26 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: User object audit token [PSARC/2010/001 FastTrack timeout 01/11/2010]
To: psarc-ext@sun.com
Cc: audit-core@sun.com, rbac_admin@sun.com, sharon.read@sun.com
Message-id: <201001020404.o0244QPA018513@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 3375

I'm sponsoring the case on behalf of myself, the Audit Project Team
and the RBAC and Admin Project Team.

It requests a Patch Release Binding.  However, there is no intention to
back port unless there is a business need to do so.  The exposed interfaces
were never formally ARCed.  They have been treated as Committed by the
Audit Project team for some time.  The man pages are updated to indicate
this.  The project requests a Committed Interface Taxonomy for the
proposed changes.

Full diff-marked man pages are in the case directory.

The timer is set for 11 Jan, 2010.

Gary..
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Background:
==========
Audit records include information on who did what to what.  The who is
the subject of the audit record, the what is the audit event and the
to what is the object of the audit record.  Audit records are generally
searchable based on who, what and to what by auditreduce(1m).

Audit records dealing with the administration of user attributes are not
searchable for the user affected.  Present audit records contain a text
token of the user name.  Examples of such audit records are those
generated by passwd user, passwd -f user, usermod <options> user.

Text tokens are generally used for supplemental information not object
identifiers.  Current object types include "path" for files, "fmri" for
FMRIs, "ipc" for System V IPC, "process" for processes.

Proposal:
========
Add a new audit token named "user" and permit selection of audit records
that contain that user value.  The auditreduce user object user name is
the same form as the other auditreduce user specifications.  The actual
token value is both a uid_t and a user name string.  Both are needed for
the case where the user has been removed from the system and the name to
uid translation is not available.

audit.log(4):
++++++++++++
NAME
     audit.log - audit trail file

DESCRIPTION

     The audit.log  files  contains  audit  records.  Each  audit
     record  is	 made  up of audit tokens. Each	record contains	a
     header token followed by various data tokens.  Depending  on
     the  audit	 policy	 in  place  by auditon(2), optional other
     tokens such as trailers or	sequences may be included.

+    The user token consists of:
+      token ID		       1 byte
+      user ID	       	       4 bytes
+      user name length	       2 bytes
+      user name	       <user name len> including terminating NULL byte

auditreduce(1m):
+++++++++++++++

NAME
     auditreduce - merge and  select  audit  records  from  audit
     trail files

SYNOPSIS
     auditreduce [options] [audit-trail-file]...

OPTIONS

  Record Selection Options
     The record	selection options listed below are used	to  indi-
     cate  which  records are written to the output file produced
     by	auditreduce.

     Multiple arguments	of the same type are not permitted.

     -o	object_type=objectID_value
	 Select	records	by object type.	A match	occurs	when  the
	 record	contains the information describing the	specified
	 object_type and the object ID equals the value	specified
	 by objectID_value. The	allowable object types and values
	 are as	follows:

+	user=user name
+	     Select records containing the user object whose name
+	     is specified.  User objects are generally specified
+	     for administrative actions on a user.

From Sebastien.Roy@sun.com Wed Jan  6 09:48:43 2010
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o06HmhaK011279
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 Jan 2010 09:48:43 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o06HmgNg006566;
	Wed, 6 Jan 2010 09:48:42 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVU0012F6T5E700@brm-avmta-1.central.sun.com>; Wed,
 06 Jan 2010 10:48:41 -0700 (MST)
Received: from brmea-mail-2.sun.com ([192.18.98.43])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVU00FX66T4YHA0@brm-avmta-1.central.sun.com>; Wed,
 06 Jan 2010 10:48:40 -0700 (MST)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id o06HmeCH001074; Wed,
 06 Jan 2010 17:48:40 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.04 64bit (built Jul  2 2009))
 id <0KVU00K006871E00@mail-amer.sun.com>; Wed, 06 Jan 2010 10:48:40 -0700 (MST)
Received: from [192.168.1.5] ([unknown] [173.76.16.34])
 by mail-amer.sun.com (Sun Java(tm) System Messaging Server 7u2-7.04 64bit
 (built Jul  2 2009)) with ESMTPSA id <0KVU004U76T1AE90@mail-amer.sun.com>; Wed,
 06 Jan 2010 10:48:38 -0700 (MST)
Date: Wed, 06 Jan 2010 12:48:36 -0500
From: Sebastien Roy <Sebastien.Roy@sun.com>
Subject: Re: User object audit token [PSARC/2010/001 FastTrack timeout
 01/11/2010]
In-reply-to: <201001020404.o0244QPA018513@sac.sfbay.sun.com>
Sender: Sebastien.Roy@sun.com
To: Gary Winiger <gww@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, rbac_admin@sun.com, audit-core@sun.com,
        Sharon.Read@sun.com
Message-id: <1262800116.1037.33.camel@seb>
Organization: Sun Microsystems
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <201001020404.o0244QPA018513@sac.sfbay.sun.com>
Status: RO
Content-Length: 175

On Fri, 2010-01-01 at 20:04 -0800, Gary Winiger wrote:
> I'm sponsoring the case on behalf of myself, the Audit Project Team
> and the RBAC and Admin Project Team.

+1
-Seb



From gww@sac.sfbay.sun.com Wed Jan  6 11:17:32 2010
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o06JHWU8002100
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 Jan 2010 11:17:32 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o06JHKH2023471;
	Wed, 6 Jan 2010 11:17:22 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVU00H17AWVGP00@nwk-avmta-2.sfbay.sun.com>; Wed,
 06 Jan 2010 11:17:19 -0800 (PST)
Received: from dm-sfbay-02.sfbay.sun.com ([129.146.11.31])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVU00G0KAWUU110@nwk-avmta-2.sfbay.sun.com>; Wed,
 06 Jan 2010 11:17:19 -0800 (PST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o06JHIZ4029481; Wed, 06 Jan 2010 11:17:18 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o06JH3PS002093; Wed,
 06 Jan 2010 11:17:13 -0800 (PST)
Received: (from gww@localhost)	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit)
 id o06JGraP002092; Wed, 06 Jan 2010 11:16:53 -0800 (PST)
Date: Wed, 06 Jan 2010 11:16:53 -0800 (PST)
From: Gary Winiger <gww@sac.sfbay.sun.com>
Subject: Re: User object audit token [PSARC/2010/001 FastTrack timeout
 01/11/2010]
To: psarc-ext@sun.com
Cc: audit-core@sun.com, rbac_admin@sun.com, sharon.read@sun.com
Message-id: <201001061916.o06JGraP002092@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 57

This case was approved at today's PSARC meeting.

Gary..

From gww@eng.sun.com Wed Jan  6 11:53:04 2010
Received: from sunmail6brm.central.sun.com (sunmail6brm.Central.Sun.COM [129.147.4.169])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o06JqsKY002531
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 Jan 2010 11:53:04 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail6brm.central.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4) with ESMTP id o06JqnTp017883
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 6 Jan 2010 13:52:49 -0600 (CST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVU00D01CK0RJ00@brm-avmta-1.central.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 06 Jan 2010 12:52:49 -0700 (MST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVU005SGCK0ICE0@brm-avmta-1.central.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 06 Jan 2010 12:52:48 -0700 (MST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.4)
 with ESMTP id o06Jqlmu020343; Wed, 06 Jan 2010 11:52:47 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id o06JpK8K025694; Wed,
 06 Jan 2010 11:51:20 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id o06JpJeU025693; Wed,
 06 Jan 2010 11:51:19 -0800 (PST)
Date: Wed, 06 Jan 2010 11:51:19 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: User object audit token [PSARC/2010/001 FastTrack timeout
 01/11/2010]]
To: rlhamil@smart.net, psarc-ext@sun.com
Message-id: <201001061951.o06JpJeU025693@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1095

For some reason, this never made it to the case log or my inbox.
Sorry for the delay.

> From: Richard L. Hamilton <rlhamil@smart.net>
> To: opensolaris-arc@opensolaris.org
> Subject: Re: User object audit token [PSARC/2010/001 FastTrack timeout
> 01/11/2010]
> Date: Sat, 02 Jan 2010 05:39:59 -0800 (PST)
> 
> Is the user SID also in audit output?  If it isn't, shouldn't it be, if available, esp.
> if the UID is ephemeral?  Wouldn't it be worth recording for forensics?

	The short answer is no presuming SIDs are Windows Security IDs
	as opposed to Solaris Audit Session IDs.

	Windows SIDs are not presently part of OpenSolaris.  Auditing
	covers identified and authenticated users logged into OpenSolaris.
	No OpenSolaris user has an ephemeral user ID.  The purpose of
	the user object token is to represent a user as the object
	of some action, not as the subject of an action.  In particular,
	as noted in the case "passwd -f" auditing would be served well
	by being able to express the user as an object in a searchable
	way.  Thus, the motivation for this new token.

Cheers,
Gary..
	

From Nicolas.Williams@sun.com Wed Jan  6 13:14:30 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o06LETvN005559
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 6 Jan 2010 13:14:29 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o06LENR1030635
	for <@sunmail2sca.sfbay.sun.com:psarc-ext@sun.com>; Wed, 6 Jan 2010 14:14:29 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KVU00103GC4EE00@nwk-avmta-2.sfbay.sun.com> for psarc-ext@sun.com
 (ORCPT psarc-ext@sun.com); Wed, 06 Jan 2010 13:14:28 -0800 (PST)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KVU00G1OGC4U7B0@nwk-avmta-2.sfbay.sun.com> for
 psarc-ext@sun.com (ORCPT psarc-ext@sun.com); Wed,
 06 Jan 2010 13:14:28 -0800 (PST)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id o06L6pdg022185;
 Wed, 06 Jan 2010 15:06:51 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id o06L6pJl022184; Wed,
 06 Jan 2010 15:06:51 -0600 (CST)
Date: Wed, 06 Jan 2010 15:06:51 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: User object audit token [PSARC/2010/001 FastTrack timeout
 01/11/2010]]
In-reply-to: <201001061951.o06JpJeU025693@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: rlhamil@smart.net, PSARC-ext@sun.com
Message-id: <20100106210650.GW1516@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <201001061951.o06JpJeU025693@marduk.eng.sun.com>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 1960

On Wed, Jan 06, 2010 at 11:51:19AM -0800, Gary Winiger wrote:
> For some reason, this never made it to the case log or my inbox.
> Sorry for the delay.
> 
> > From: Richard L. Hamilton <rlhamil@smart.net>
> > To: opensolaris-arc@opensolaris.org
> > Subject: Re: User object audit token [PSARC/2010/001 FastTrack timeout
> > 01/11/2010]
> > Date: Sat, 02 Jan 2010 05:39:59 -0800 (PST)
> > 
> > Is the user SID also in audit output?  If it isn't, shouldn't it be, if available, esp.
> > if the UID is ephemeral?  Wouldn't it be worth recording for forensics?
> 
> 	The short answer is no presuming SIDs are Windows Security IDs
> 	as opposed to Solaris Audit Session IDs.
> 
> 	Windows SIDs are not presently part of OpenSolaris.  Auditing
> 	covers identified and authenticated users logged into OpenSolaris.
> 	No OpenSolaris user has an ephemeral user ID.  The purpose of

Well, I think you're splitting hairs.  SIDs are definitely part of
OpenSolaris, in ZFS, cred_t, the SMB stack, and the NFSv4 stack even, as
well as libsec consumers like chmod(1) and ls(1).

True, SIDs are represented as UIDs and GIDs -- ephemeral ones when no
mapping to a real Unix user/group can be found -- in all places where
there's no choice but to use UIDs/GIDs (or where there are standard
interfaces that use UIDs/GIDs).  But that's not the same thing as "SIDs
are not ... part of OpenSolaris".

> 	the user object token is to represent a user as the object
> 	of some action, not as the subject of an action.  In particular,
> 	as noted in the case "passwd -f" auditing would be served well
> 	by being able to express the user as an object in a searchable
> 	way.  Thus, the motivation for this new token.

Indeed, this case is not about the subject of an audit record, but about
an object that a an audit record is about.  In this case there's no need
for SIDs because the relevant admin interfaces currently can't be used
to admin non-Unix Windows users/groups.

Nico
-- 

