-
Notifications
You must be signed in to change notification settings - Fork 1.5k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
False positives on NixOS #1542
Comments
Can you be more specific, so that we can troubleshoot these issues. Let's start with the first one (the audit log). Please include test number, the output of lynis.log for that particular test. Good to know: Lynis 3.1.2 was released yesterday and fixes a lot of items, possibly including the NETW-3200. |
@mboelen Sorry about the wait. I just updated to Lynis 3.1.2 and did a new system audit. The test number for the first false positive is ACCT-9634, and the output of
The output for NETW-3200 is:
|
The issue with the auditd log file is not NixOS specific. I assume your auditd configuration file simply does not set However, lynis extracts the log file location from the auditd configuration file and claims the log file is missing in case I have created PR #1594 to fix this. |
Describe the bug
I've noticed multiple false positives when running
sudo lynis audit system
on NixOS:Auditd log file is defined but can not be found on disk
:/var/log/audit/audit.log
existsdccp
,sctp
,rds
, andtipc
Version
Expected behavior
These false positives don't happen.
The text was updated successfully, but these errors were encountered: