--On Sunday, November 30, 2008 9:02 AM -0500 Ignacio Vazquez-Abrams ivazqueznet@gmail.com wrote:
You forgot one important bit: the actual denials.
I don't find anything in /var/log/audit/audit.log nor /var/log/messages. audit.log looks like the right place but it's not logged anything since June. Do I need to enable this? (I suspect another admin turned it off inadvertantly.) The auditd service is running.