Oracle Solaris System Administration (MOSC)

MOSC Banner

Protecting Oracle Solaris Audit trail files from tampering/removal – even by root

Starting in Oracle Solaris 11.4.87 the auditd plugin audit_binfile, which is responsible for writing to the local binary format audit files, now marks the active audit file as append_only when it is first created, and will remove all write permissions when it is closed and renamed from <start_time>.not_terminated.<hostname> to <start_time>.<end_time>.<hostname>. This means we can now use ZFS File Retention to provide additional protection for the audit trail files.

For more details, please visit: Protecting Oracle Solaris Audit trail files from tampering/removal – even by root

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center