> -----Original Message----- > From: fedora-selinux-list-bounces@xxxxxxxxxx > [mailto:fedora-selinux-list-bounces@xxxxxxxxxx] On Behalf Of > Stephen Smalley > I suspect that you don't actually want SELinux auditing here, > as it is just of MAC permission checks, but instead want > ordinary system call auditing. There is ongoing work to > enhance the existing Linux audit framework and userspace > tools toward that end, see the linux-audit mailing list. Thanks, Stephen, I'll check it out. In the meantime, I've turned on enforcement and will see if that at least is a temporary fix. A quick test of major programs I use shows no problems. Tom Browder