An interception event is an event that CA Access Control encounters for the first time and for which no authorization information or audit information exists in the kernel cache.
To log audit records, CA Access Control performs the following actions and causes these effects for an interception event:

CA Access Control writes an audit item only if the audit property for the resource or accessor is set to audit the resulting event and the audit filter file is not set to filter this event.
CA Access Control writes an audit item only if the audit filter file is not set to filter this event. The authorization result in this mode is always P (permitted).
Note: Intercepted login events (TERMINAL class), and audit records generated by user traces, are not cached; the authorization engine always writes audit records for these events.
| Copyright © 2012 CA. All rights reserved. |
|