Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 706656 Details for
Bug 919074
Instances fail to boot 'could not open disk image Permission denied'
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
/var/log/audit/audit.log
audit.log (text/plain), 2.73 MB, created by
Dan Prince
on 2013-03-07 15:03:03 UTC
(
hide
)
Description:
/var/log/audit/audit.log
Filename:
MIME Type:
Creator:
Dan Prince
Created:
2013-03-07 15:03:03 UTC
Size:
2.73 MB
patch
obsolete
>type=DAEMON_START msg=audit(1360691114.914:1860): auditd start, ver=2.2 format=raw kernel=2.6.32-356.el6.x86_64 auid=4294967295 pid=896 subj=system_u:system_r:auditd_t:s0 res=success >type=CONFIG_CHANGE msg=audit(1360691115.025:4): audit_backlog_limit=320 old=64 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 res=1 >type=DAEMON_START msg=audit(1360691979.757:9524): auditd start, ver=2.2 format=raw kernel=2.6.32-356.el6.x86_64 auid=4294967295 pid=911 subj=system_u:system_r:auditd_t:s0 res=success >type=CONFIG_CHANGE msg=audit(1360691979.875:4): audit_backlog_limit=320 old=64 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 res=1 >type=USER_AUTH msg=audit(1360691986.483:5): user pid=1079 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360691986.485:6): user pid=1079 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=LOGIN msg=audit(1360691986.485:7): pid=1079 uid=0 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=1 >type=USER_ROLE_CHANGE msg=audit(1360691986.602:8): user pid=1079 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_START msg=audit(1360691986.609:9): user pid=1079 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_ACQ msg=audit(1360691986.609:10): user pid=1079 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_LOGIN msg=audit(1360691986.612:11): user pid=1079 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360692061.548:12): user pid=1340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >type=CRED_ACQ msg=audit(1360692061.548:13): user pid=1340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >type=LOGIN msg=audit(1360692061.557:14): pid=1340 uid=0 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=2 >type=USER_START msg=audit(1360692061.559:15): user pid=1340 uid=0 auid=0 ses=2 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >type=CRED_DISP msg=audit(1360692061.611:16): user pid=1340 uid=0 auid=0 ses=2 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >type=USER_END msg=audit(1360692061.611:17): user pid=1340 uid=0 auid=0 ses=2 subj=system_u:system_r:crond_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/crond" hostname=? addr=? terminal=cron res=success' >type=CRED_DISP msg=audit(1360692250.163:18): user pid=1079 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_END msg=audit(1360692250.170:19): user pid=1079 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_AUTH msg=audit(1360692255.501:20): user pid=1675 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360692255.502:21): user pid=1675 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=LOGIN msg=audit(1360692255.503:22): pid=1675 uid=0 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=3 >type=USER_ROLE_CHANGE msg=audit(1360692255.613:23): user pid=1675 uid=0 auid=0 ses=3 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_START msg=audit(1360692255.617:24): user pid=1675 uid=0 auid=0 ses=3 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_ACQ msg=audit(1360692255.617:25): user pid=1675 uid=0 auid=0 ses=3 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_LOGIN msg=audit(1360692255.618:26): user pid=1675 uid=0 auid=0 ses=3 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_DISP msg=audit(1360692262.316:27): user pid=1675 uid=0 auid=0 ses=3 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_END msg=audit(1360692262.316:28): user pid=1675 uid=0 auid=0 ses=3 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=DAEMON_START msg=audit(1360694303.564:7588): auditd start, ver=2.2 format=raw kernel=2.6.32-356.el6.x86_64 auid=4294967295 pid=1017 subj=system_u:system_r:auditd_t:s0 res=success >type=CONFIG_CHANGE msg=audit(1360694303.679:4): audit_backlog_limit=320 old=64 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 res=1 >type=USER_AUTH msg=audit(1360694342.723:5): user pid=1185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360694342.724:6): user pid=1185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=LOGIN msg=audit(1360694342.725:7): pid=1185 uid=0 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=1 >type=USER_ROLE_CHANGE msg=audit(1360694342.830:8): user pid=1185 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_START msg=audit(1360694342.837:9): user pid=1185 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_ACQ msg=audit(1360694342.837:10): user pid=1185 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_LOGIN msg=audit(1360694342.838:11): user pid=1185 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_DISP msg=audit(1360694469.693:12): user pid=1185 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_END msg=audit(1360694469.699:13): user pid=1185 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_AUTH msg=audit(1360694475.279:14): user pid=1664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360694475.281:15): user pid=1664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=LOGIN msg=audit(1360694475.282:16): pid=1664 uid=0 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=2 >type=USER_ROLE_CHANGE msg=audit(1360694475.377:17): user pid=1664 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_START msg=audit(1360694475.381:18): user pid=1664 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_ACQ msg=audit(1360694475.381:19): user pid=1664 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_LOGIN msg=audit(1360694475.382:20): user pid=1664 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_DISP msg=audit(1360694482.142:21): user pid=1664 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_END msg=audit(1360694482.142:22): user pid=1664 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=DAEMON_START msg=audit(1360694934.514:4180): auditd start, ver=2.2 format=raw kernel=2.6.32-356.el6.x86_64 auid=4294967295 pid=979 subj=system_u:system_r:auditd_t:s0 res=success >type=CONFIG_CHANGE msg=audit(1360694934.629:4): audit_backlog_limit=320 old=64 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 res=1 >type=USER_AUTH msg=audit(1360694945.970:5): user pid=1147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360694945.972:6): user pid=1147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=LOGIN msg=audit(1360694945.973:7): pid=1147 uid=0 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=1 >type=USER_ROLE_CHANGE msg=audit(1360694946.077:8): user pid=1147 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_START msg=audit(1360694946.083:9): user pid=1147 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_ACQ msg=audit(1360694946.084:10): user pid=1147 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_LOGIN msg=audit(1360694946.085:11): user pid=1147 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_DISP msg=audit(1360695056.284:12): user pid=1147 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_END msg=audit(1360695056.285:13): user pid=1147 uid=0 auid=0 ses=1 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_AUTH msg=audit(1360695064.067:14): user pid=1184 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:authentication acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_ACCT msg=audit(1360695064.068:15): user pid=1184 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=LOGIN msg=audit(1360695064.069:16): pid=1184 uid=0 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=2 >type=USER_ROLE_CHANGE msg=audit(1360695064.155:17): user pid=1184 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_START msg=audit(1360695064.159:18): user pid=1184 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_ACQ msg=audit(1360695064.159:19): user pid=1184 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_LOGIN msg=audit(1360695064.160:20): user pid=1184 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=CRED_DISP msg=audit(1360695074.696:21): user pid=1184 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=USER_END msg=audit(1360695074.696:22): user pid=1184 uid=0 auid=0 ses=2 subj=system_u:system_r:local_login_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/bin/login" hostname=? addr=? terminal=tty1 res=success' >type=DAEMON_START msg=audit(1362665100.743:5458): auditd start, ver=2.2 format=raw kernel=2.6.32-356.el6.x86_64 auid=4294967295 pid=1139 subj=system_u:system_r:auditd_t:s0 res=success >type=CONFIG_CHANGE msg=audit(1362665100.859:4): audit_backlog_limit=320 old=64 auid=4294967295 ses=4294967295 subj=system_u:system_r:auditctl_t:s0 res=1 >type=CRYPTO_KEY_USER msg=audit(1362665109.721:5): user pid=1332 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1332 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665109.721:6): user pid=1332 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1332 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665109.724:7): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1332 suid=74 rport=55797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665109.724:8): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1332 suid=74 rport=55797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665109.866:9): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=55797 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665109.866:10): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=55797 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362665109.888:11): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665109.889:12): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1332 suid=74 rport=55797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665109.890:13): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665109.892:14): user pid=1331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362665109.892:15): pid=1331 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=1 >type=USER_ROLE_CHANGE msg=audit(1362665110.057:16): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665110.062:17): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665110.063:18): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665110.063:19): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.064:20): user pid=1334 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1334 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.064:21): user pid=1334 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1334 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362665110.066:22): user pid=1334 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665110.227:23): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665110.227:24): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665110.227:25): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665110.227:26): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.228:27): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1331 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.228:28): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1331 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.228:29): user pid=1331 uid=0 auid=0 ses=1 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1331 suid=0 rport=55797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.527:30): user pid=1349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1349 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.527:31): user pid=1349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1349 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665110.528:32): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1349 suid=74 rport=55798 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665110.528:33): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1349 suid=74 rport=55798 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665110.593:34): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=55798 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665110.594:35): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=55798 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362665110.600:36): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.601:37): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1349 suid=74 rport=55798 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665110.602:38): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665110.602:39): user pid=1348 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362665110.602:40): pid=1348 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=2 >type=USER_ROLE_CHANGE msg=audit(1362665110.731:41): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665110.734:42): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665110.736:43): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665110.736:44): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.737:45): user pid=1351 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1351 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665110.738:46): user pid=1351 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1351 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362665110.739:47): user pid=1351 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665190.454:48): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665190.454:49): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665190.455:50): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665190.455:51): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665190.455:52): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1348 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665190.455:53): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1348 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665190.455:54): user pid=1348 uid=0 auid=0 ses=2 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1348 suid=0 rport=55798 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665213.137:55): user pid=1361 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665213.137:56): user pid=1361 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665213.138:57): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1361 suid=74 rport=56204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665213.138:58): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1361 suid=74 rport=56204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665213.203:59): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56204 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665213.204:60): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56204 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362665213.213:61): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665213.214:62): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1361 suid=74 rport=56204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665213.215:63): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665213.215:64): user pid=1360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362665213.215:65): pid=1360 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=3 >type=USER_ROLE_CHANGE msg=audit(1362665213.351:66): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665213.356:67): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665213.358:68): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665213.359:69): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665213.360:70): user pid=1363 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1363 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665213.360:71): user pid=1363 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1363 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362665213.361:72): user pid=1363 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665215.117:73): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665215.117:74): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665215.118:75): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665215.118:76): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.118:77): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1360 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.118:78): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1360 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.119:79): user pid=1360 uid=0 auid=0 ses=3 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1360 suid=0 rport=56204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.401:80): user pid=1367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1367 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.402:81): user pid=1367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1367 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665215.402:82): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1367 suid=74 rport=56205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665215.402:83): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1367 suid=74 rport=56205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665215.467:84): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56205 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665215.467:85): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56205 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362665215.475:86): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.476:87): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1367 suid=74 rport=56205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665215.477:88): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665215.477:89): user pid=1366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362665215.477:90): pid=1366 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=4 >type=USER_ROLE_CHANGE msg=audit(1362665215.610:91): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665215.615:92): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665215.616:93): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665215.616:94): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.617:95): user pid=1369 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1369 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665215.618:96): user pid=1369 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1369 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362665215.618:97): user pid=1369 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=ADD_GROUP msg=audit(1362665235.115:98): user pid=1379 uid=0 auid=0 ses=4 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=48 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665235.206:99): user pid=1379 uid=0 auid=0 ses=4 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=48 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665235.207:100): user pid=1379 uid=0 auid=0 ses=4 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=48 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665235.321:101): user pid=1384 uid=0 auid=0 ses=4 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=48 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665243.769:102): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665243.769:103): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362665243.770:104): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665243.770:105): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665243.770:106): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1366 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665243.770:107): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1366 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665243.770:108): user pid=1366 uid=0 auid=0 ses=4 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1366 suid=0 rport=56205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665244.045:109): user pid=1566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1566 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665244.045:110): user pid=1566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1566 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665244.046:111): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1566 suid=74 rport=56206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665244.046:112): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1566 suid=74 rport=56206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665244.112:113): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56206 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665244.112:114): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56206 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362665244.121:115): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665244.121:116): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1566 suid=74 rport=56206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665244.122:117): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665244.123:118): user pid=1565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362665244.123:119): pid=1565 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=5 >type=USER_ROLE_CHANGE msg=audit(1362665244.268:120): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665244.273:121): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665244.274:122): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665244.274:123): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665244.276:124): user pid=1568 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1568 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665244.276:125): user pid=1568 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1568 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362665244.277:126): user pid=1568 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.413:127): user pid=1679 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1679 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.414:128): user pid=1679 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1679 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.439:129): user pid=1684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1684 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.439:130): user pid=1684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1684 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665252.440:131): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1684 suid=74 rport=60116 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665252.440:132): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1684 suid=74 rport=60116 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665252.521:133): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60116 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665252.521:134): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60116 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665252.530:135): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.531:136): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1684 suid=74 rport=60116 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665252.532:137): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665252.532:138): user pid=1683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665252.533:139): pid=1683 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=6 >type=USER_ROLE_CHANGE msg=audit(1362665252.666:140): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665252.670:141): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665252.676:142): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665252.676:143): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.677:144): user pid=1686 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1686 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.677:145): user pid=1686 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1686 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665252.677:146): user pid=1686 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665252.722:147): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665252.722:148): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665252.723:149): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665252.723:150): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.723:151): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.723:152): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.723:153): user pid=1683 uid=0 auid=0 ses=6 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1683 suid=0 rport=60116 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.750:154): user pid=1692 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1692 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.750:155): user pid=1692 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1692 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665252.751:156): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1692 suid=74 rport=60117 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665252.751:157): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1692 suid=74 rport=60117 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665252.817:158): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60117 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665252.817:159): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60117 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665252.824:160): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.826:161): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1692 suid=74 rport=60117 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665252.827:162): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665252.827:163): user pid=1691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665252.827:164): pid=1691 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=7 >type=USER_ROLE_CHANGE msg=audit(1362665252.952:165): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665252.955:166): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665252.960:167): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665252.960:168): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.961:169): user pid=1694 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1694 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665252.961:170): user pid=1694 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1694 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665252.962:171): user pid=1694 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665253.182:172): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665253.183:173): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665253.183:174): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665253.183:175): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.183:176): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1691 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.184:177): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1691 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.184:178): user pid=1691 uid=0 auid=0 ses=7 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1691 suid=0 rport=60117 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.211:179): user pid=1704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1704 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.211:180): user pid=1704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1704 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665253.212:181): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1704 suid=74 rport=60118 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665253.212:182): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1704 suid=74 rport=60118 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665253.275:183): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60118 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665253.275:184): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60118 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665253.282:185): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.283:186): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1704 suid=74 rport=60118 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665253.284:187): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665253.284:188): user pid=1703 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665253.284:189): pid=1703 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=8 >type=USER_ROLE_CHANGE msg=audit(1362665253.411:190): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665253.415:191): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665253.421:192): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665253.421:193): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.422:194): user pid=1706 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1706 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.422:195): user pid=1706 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1706 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665253.423:196): user pid=1706 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665253.727:197): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665253.728:198): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665253.728:199): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665253.728:200): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.728:201): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1703 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.729:202): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1703 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.729:203): user pid=1703 uid=0 auid=0 ses=8 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1703 suid=0 rport=60118 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.755:204): user pid=1712 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1712 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.755:205): user pid=1712 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1712 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665253.755:206): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1712 suid=74 rport=60119 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665253.756:207): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1712 suid=74 rport=60119 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665253.818:208): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60119 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665253.818:209): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60119 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665253.825:210): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.825:211): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1712 suid=74 rport=60119 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665253.826:212): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665253.826:213): user pid=1711 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665253.826:214): pid=1711 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=9 >type=USER_ROLE_CHANGE msg=audit(1362665253.951:215): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665253.955:216): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665253.960:217): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665253.960:218): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.961:219): user pid=1714 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1714 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665253.962:220): user pid=1714 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1714 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665253.963:221): user pid=1714 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665254.809:222): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665254.809:223): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665254.810:224): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665254.811:225): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665254.811:226): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1711 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665254.811:227): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1711 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665254.811:228): user pid=1711 uid=0 auid=0 ses=9 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1711 suid=0 rport=60119 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665254.845:229): user pid=1726 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1726 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665254.846:230): user pid=1726 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1726 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665254.846:231): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1726 suid=74 rport=60120 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665254.846:232): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1726 suid=74 rport=60120 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665254.912:233): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60120 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665254.912:234): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60120 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665254.922:235): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665254.922:236): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1726 suid=74 rport=60120 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665254.923:237): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665254.923:238): user pid=1725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665254.923:239): pid=1725 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=10 >type=USER_ROLE_CHANGE msg=audit(1362665255.053:240): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.058:241): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665255.064:242): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.064:243): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.065:244): user pid=1728 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1728 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.066:245): user pid=1728 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1728 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665255.066:246): user pid=1728 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.138:247): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665255.138:248): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.139:249): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665255.139:250): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.139:251): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1725 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.139:252): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1725 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.139:253): user pid=1725 uid=0 auid=0 ses=10 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1725 suid=0 rport=60120 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.160:254): user pid=1734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1734 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.160:255): user pid=1734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1734 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665255.161:256): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1734 suid=74 rport=60121 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665255.161:257): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1734 suid=74 rport=60121 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.227:258): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60121 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.227:259): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60121 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665255.234:260): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.235:261): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1734 suid=74 rport=60121 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.236:262): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665255.236:263): user pid=1733 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665255.236:264): pid=1733 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=11 >type=USER_ROLE_CHANGE msg=audit(1362665255.358:265): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.363:266): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665255.369:267): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.369:268): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.370:269): user pid=1736 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1736 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.370:270): user pid=1736 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1736 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665255.371:271): user pid=1736 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.420:272): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665255.420:273): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.421:274): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665255.421:275): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.421:276): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1733 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.421:277): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1733 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.421:278): user pid=1733 uid=0 auid=0 ses=11 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1733 suid=0 rport=60121 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.442:279): user pid=1743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1743 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.442:280): user pid=1743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1743 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665255.442:281): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1743 suid=74 rport=60122 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665255.443:282): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1743 suid=74 rport=60122 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.506:283): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60122 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.506:284): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60122 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665255.513:285): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.515:286): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1743 suid=74 rport=60122 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.516:287): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665255.516:288): user pid=1742 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665255.516:289): pid=1742 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=12 >type=USER_ROLE_CHANGE msg=audit(1362665255.644:290): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.649:291): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665255.654:292): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.654:293): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.655:294): user pid=1745 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1745 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.655:295): user pid=1745 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1745 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665255.656:296): user pid=1745 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.708:297): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665255.708:298): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.709:299): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665255.709:300): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.709:301): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1742 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.710:302): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1742 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.710:303): user pid=1742 uid=0 auid=0 ses=12 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1742 suid=0 rport=60122 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.730:304): user pid=1752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1752 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.731:305): user pid=1752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1752 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665255.731:306): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1752 suid=74 rport=60123 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665255.731:307): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1752 suid=74 rport=60123 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.794:308): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60123 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.794:309): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60123 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665255.801:310): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.801:311): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1752 suid=74 rport=60123 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665255.802:312): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665255.802:313): user pid=1751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665255.803:314): pid=1751 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=13 >type=USER_ROLE_CHANGE msg=audit(1362665255.924:315): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.929:316): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665255.934:317): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665255.935:318): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.935:319): user pid=1754 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1754 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.936:320): user pid=1754 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1754 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665255.936:321): user pid=1754 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.987:322): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665255.987:323): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665255.987:324): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665255.987:325): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.987:326): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1751 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.988:327): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1751 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665255.988:328): user pid=1751 uid=0 auid=0 ses=13 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1751 suid=0 rport=60123 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.008:329): user pid=1761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1761 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.008:330): user pid=1761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1761 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.009:331): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1761 suid=74 rport=60124 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.009:332): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1761 suid=74 rport=60124 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.071:333): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60124 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.072:334): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60124 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665256.079:335): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.079:336): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1761 suid=74 rport=60124 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.080:337): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665256.081:338): user pid=1760 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665256.081:339): pid=1760 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=14 >type=USER_ROLE_CHANGE msg=audit(1362665256.208:340): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665256.213:341): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665256.218:342): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665256.218:343): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.219:344): user pid=1763 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1763 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.220:345): user pid=1763 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1763 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665256.220:346): user pid=1763 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665256.273:347): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665256.273:348): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665256.274:349): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665256.274:350): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.274:351): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1760 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.274:352): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1760 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.274:353): user pid=1760 uid=0 auid=0 ses=14 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1760 suid=0 rport=60124 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.295:354): user pid=1769 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1769 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.295:355): user pid=1769 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1769 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.296:356): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1769 suid=74 rport=60125 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.296:357): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1769 suid=74 rport=60125 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.359:358): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60125 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.359:359): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60125 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665256.366:360): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.366:361): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1769 suid=74 rport=60125 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.367:362): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665256.368:363): user pid=1768 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665256.368:364): pid=1768 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=15 >type=USER_ROLE_CHANGE msg=audit(1362665256.491:365): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665256.496:366): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665256.500:367): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665256.501:368): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.502:369): user pid=1771 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1771 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.502:370): user pid=1771 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1771 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665256.502:371): user pid=1771 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665256.552:372): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665256.552:373): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665256.552:374): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665256.553:375): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.553:376): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1768 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.553:377): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1768 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.553:378): user pid=1768 uid=0 auid=0 ses=15 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1768 suid=0 rport=60125 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.574:379): user pid=1778 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1778 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.575:380): user pid=1778 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1778 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.575:381): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1778 suid=74 rport=60126 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.575:382): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1778 suid=74 rport=60126 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.639:383): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60126 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.640:384): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60126 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665256.646:385): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.647:386): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1778 suid=74 rport=60126 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.647:387): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665256.648:388): user pid=1777 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665256.648:389): pid=1777 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=16 >type=USER_ROLE_CHANGE msg=audit(1362665256.769:390): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665256.773:391): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665256.778:392): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665256.779:393): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.779:394): user pid=1780 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1780 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.780:395): user pid=1780 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1780 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665256.780:396): user pid=1780 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665256.824:397): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665256.824:398): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665256.824:399): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665256.825:400): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.825:401): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1777 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.825:402): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1777 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.825:403): user pid=1777 uid=0 auid=0 ses=16 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1777 suid=0 rport=60126 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.853:404): user pid=1785 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1785 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.853:405): user pid=1785 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1785 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.854:406): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1785 suid=74 rport=60127 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665256.854:407): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1785 suid=74 rport=60127 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.917:408): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60127 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.917:409): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60127 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665256.923:410): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665256.924:411): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1785 suid=74 rport=60127 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665256.925:412): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665256.925:413): user pid=1784 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665256.925:414): pid=1784 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=17 >type=USER_ROLE_CHANGE msg=audit(1362665257.052:415): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665257.056:416): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665257.062:417): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665257.062:418): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.063:419): user pid=1787 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1787 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.063:420): user pid=1787 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1787 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665257.064:421): user pid=1787 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665257.418:422): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665257.418:423): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665257.418:424): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665257.418:425): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.419:426): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1784 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.419:427): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1784 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.419:428): user pid=1784 uid=0 auid=0 ses=17 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1784 suid=0 rport=60127 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.450:429): user pid=1797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1797 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.450:430): user pid=1797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1797 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665257.451:431): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1797 suid=74 rport=60128 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665257.451:432): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1797 suid=74 rport=60128 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665257.514:433): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60128 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665257.514:434): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60128 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665257.521:435): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.522:436): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1797 suid=74 rport=60128 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665257.522:437): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665257.523:438): user pid=1796 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665257.523:439): pid=1796 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=18 >type=USER_ROLE_CHANGE msg=audit(1362665257.654:440): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665257.659:441): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665257.665:442): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665257.665:443): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.666:444): user pid=1799 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1799 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665257.666:445): user pid=1799 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1799 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665257.667:446): user pid=1799 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=ADD_GROUP msg=audit(1362665296.578:447): user pid=1809 uid=0 auid=0 ses=18 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=52 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665296.656:448): user pid=1809 uid=0 auid=0 ses=18 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=52 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665296.657:449): user pid=1809 uid=0 auid=0 ses=18 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=52 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665296.760:450): user pid=1814 uid=0 auid=0 ses=18 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=52 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665301.659:451): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665301.659:452): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665301.660:453): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665301.660:454): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.660:455): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1796 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.660:456): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1796 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.660:457): user pid=1796 uid=0 auid=0 ses=18 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1796 suid=0 rport=60128 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.699:458): user pid=1828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1828 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.700:459): user pid=1828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1828 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665301.700:460): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1828 suid=74 rport=60145 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665301.700:461): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1828 suid=74 rport=60145 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665301.764:462): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60145 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665301.764:463): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60145 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665301.773:464): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.773:465): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1828 suid=74 rport=60145 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665301.774:466): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665301.774:467): user pid=1827 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665301.775:468): pid=1827 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=19 >type=USER_ROLE_CHANGE msg=audit(1362665301.913:469): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665301.917:470): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665301.924:471): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665301.924:472): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.925:473): user pid=1830 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1830 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665301.925:474): user pid=1830 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1830 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665301.926:475): user pid=1830 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.100:476): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665302.100:477): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.101:478): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665302.101:479): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.101:480): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1827 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.101:481): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1827 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.101:482): user pid=1827 uid=0 auid=0 ses=19 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1827 suid=0 rport=60145 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.125:483): user pid=1839 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1839 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.125:484): user pid=1839 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1839 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665302.128:485): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1839 suid=74 rport=60146 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665302.128:486): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1839 suid=74 rport=60146 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.191:487): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60146 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.191:488): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60146 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665302.199:489): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.200:490): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1839 suid=74 rport=60146 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.201:491): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665302.202:492): user pid=1838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665302.202:493): pid=1838 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=20 >type=USER_ROLE_CHANGE msg=audit(1362665302.337:494): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665302.342:495): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665302.348:496): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665302.348:497): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.349:498): user pid=1841 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1841 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.350:499): user pid=1841 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1841 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665302.350:500): user pid=1841 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.398:501): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665302.398:502): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.399:503): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665302.399:504): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.399:505): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1838 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.399:506): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1838 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.399:507): user pid=1838 uid=0 auid=0 ses=20 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1838 suid=0 rport=60146 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.427:508): user pid=1848 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1848 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.427:509): user pid=1848 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1848 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665302.428:510): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1848 suid=74 rport=60147 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665302.428:511): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1848 suid=74 rport=60147 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.490:512): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60147 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.490:513): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60147 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665302.498:514): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.499:515): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1848 suid=74 rport=60147 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.499:516): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665302.500:517): user pid=1847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665302.500:518): pid=1847 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=21 >type=USER_ROLE_CHANGE msg=audit(1362665302.630:519): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665302.634:520): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665302.640:521): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665302.640:522): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.641:523): user pid=1850 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1850 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.641:524): user pid=1850 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1850 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665302.642:525): user pid=1850 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.691:526): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665302.691:527): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.691:528): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665302.692:529): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.692:530): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1847 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.692:531): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1847 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.692:532): user pid=1847 uid=0 auid=0 ses=21 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1847 suid=0 rport=60147 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.726:533): user pid=1862 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1862 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.727:534): user pid=1862 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1862 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665302.727:535): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=1862 suid=74 rport=60148 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665302.727:536): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=1862 suid=74 rport=60148 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.792:537): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60148 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.792:538): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60148 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665302.802:539): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.804:540): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1862 suid=74 rport=60148 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665302.806:541): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665302.806:542): user pid=1861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665302.806:543): pid=1861 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=22 >type=USER_ROLE_CHANGE msg=audit(1362665302.938:544): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665302.943:545): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665302.949:546): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665302.949:547): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.950:548): user pid=1887 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1887 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.950:549): user pid=1887 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1887 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665302.951:550): user pid=1887 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.996:551): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665302.996:552): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665302.997:553): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665302.997:554): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.997:555): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1861 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.997:556): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1861 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665302.998:557): user pid=1861 uid=0 auid=0 ses=22 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1861 suid=0 rport=60148 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.031:558): user pid=2119 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2119 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.031:559): user pid=2119 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2119 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665306.034:560): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2119 suid=74 rport=60149 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665306.034:561): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2119 suid=74 rport=60149 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665306.098:562): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60149 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665306.098:563): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60149 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665306.106:564): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.107:565): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2119 suid=74 rport=60149 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665306.107:566): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665306.108:567): user pid=2118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665306.108:568): pid=2118 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=23 >type=USER_ROLE_CHANGE msg=audit(1362665306.245:569): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665306.250:570): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665306.255:571): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665306.255:572): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.256:573): user pid=2121 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2121 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.256:574): user pid=2121 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2121 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665306.258:575): user pid=2121 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665306.309:576): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665306.309:577): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665306.309:578): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665306.309:579): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.309:580): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2118 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.310:581): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2118 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665306.310:582): user pid=2118 uid=0 auid=0 ses=23 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2118 suid=0 rport=60149 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.363:583): user pid=2130 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2130 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.363:584): user pid=2130 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2130 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665309.364:585): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2130 suid=74 rport=60151 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665309.364:586): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2130 suid=74 rport=60151 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665309.428:587): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60151 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665309.429:588): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60151 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665309.437:589): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.439:590): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2130 suid=74 rport=60151 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665309.440:591): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665309.440:592): user pid=2129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665309.440:593): pid=2129 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=24 >type=USER_ROLE_CHANGE msg=audit(1362665309.576:594): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665309.579:595): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665309.580:596): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665309.580:597): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.581:598): user pid=2132 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2132 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.581:599): user pid=2132 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2132 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665309.582:600): user pid=2132 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665309.634:601): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665309.634:602): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665309.634:603): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665309.635:604): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.635:605): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2129 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.635:606): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2129 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665309.635:607): user pid=2129 uid=0 auid=0 ses=24 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2129 suid=0 rport=60151 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.675:608): user pid=2139 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2139 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.676:609): user pid=2139 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2139 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665312.676:610): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2139 suid=74 rport=60152 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665312.677:611): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2139 suid=74 rport=60152 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665312.740:612): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60152 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665312.740:613): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60152 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665312.747:614): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.749:615): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2139 suid=74 rport=60152 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665312.749:616): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665312.750:617): user pid=2138 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665312.750:618): pid=2138 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=25 >type=USER_ROLE_CHANGE msg=audit(1362665312.875:619): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665312.878:620): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665312.879:621): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665312.879:622): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.880:623): user pid=2141 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2141 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.880:624): user pid=2141 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2141 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665312.881:625): user pid=2141 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665312.930:626): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665312.930:627): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665312.931:628): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665312.932:629): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.932:630): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2138 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.932:631): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2138 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665312.932:632): user pid=2138 uid=0 auid=0 ses=25 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2138 suid=0 rport=60152 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665315.973:633): user pid=2148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2148 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665315.973:634): user pid=2148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2148 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665315.975:635): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2148 suid=74 rport=60153 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665315.975:636): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2148 suid=74 rport=60153 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665316.039:637): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60153 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665316.039:638): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60153 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665316.047:639): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665316.048:640): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2148 suid=74 rport=60153 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665316.049:641): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665316.049:642): user pid=2147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665316.049:643): pid=2147 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=26 >type=USER_ROLE_CHANGE msg=audit(1362665316.186:644): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665316.189:645): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665316.190:646): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665316.190:647): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665316.191:648): user pid=2150 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2150 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665316.191:649): user pid=2150 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2150 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665316.192:650): user pid=2150 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665316.240:651): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665316.240:652): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665316.240:653): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665316.241:654): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665316.241:655): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2147 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665316.241:656): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2147 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665316.241:657): user pid=2147 uid=0 auid=0 ses=26 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2147 suid=0 rport=60153 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.282:658): user pid=2157 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2157 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.282:659): user pid=2157 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2157 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665319.283:660): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2157 suid=74 rport=60154 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665319.283:661): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2157 suid=74 rport=60154 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665319.347:662): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60154 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665319.347:663): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60154 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665319.356:664): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.357:665): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2157 suid=74 rport=60154 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665319.357:666): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665319.358:667): user pid=2156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665319.358:668): pid=2156 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=27 >type=USER_ROLE_CHANGE msg=audit(1362665319.493:669): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665319.496:670): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665319.497:671): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665319.497:672): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.498:673): user pid=2159 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2159 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.498:674): user pid=2159 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2159 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665319.499:675): user pid=2159 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665319.548:676): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665319.549:677): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665319.550:678): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665319.550:679): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.551:680): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2156 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.551:681): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2156 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665319.551:682): user pid=2156 uid=0 auid=0 ses=27 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2156 suid=0 rport=60154 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.589:683): user pid=2166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2166 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.589:684): user pid=2166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2166 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665322.590:685): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2166 suid=74 rport=60155 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665322.590:686): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2166 suid=74 rport=60155 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665322.655:687): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60155 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665322.655:688): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60155 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665322.662:689): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.662:690): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2166 suid=74 rport=60155 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665322.663:691): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665322.663:692): user pid=2165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665322.664:693): pid=2165 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=28 >type=USER_ROLE_CHANGE msg=audit(1362665322.794:694): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665322.797:695): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665322.798:696): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665322.798:697): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.799:698): user pid=2168 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2168 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.799:699): user pid=2168 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2168 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665322.800:700): user pid=2168 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665322.846:701): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665322.846:702): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665322.847:703): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665322.848:704): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.848:705): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2165 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.848:706): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2165 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665322.848:707): user pid=2165 uid=0 auid=0 ses=28 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2165 suid=0 rport=60155 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665325.887:708): user pid=2175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2175 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665325.887:709): user pid=2175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2175 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665325.888:710): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2175 suid=74 rport=60156 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665325.888:711): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2175 suid=74 rport=60156 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665325.951:712): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60156 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665325.951:713): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60156 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665325.959:714): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665325.962:715): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2175 suid=74 rport=60156 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665325.962:716): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665325.963:717): user pid=2174 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665325.963:718): pid=2174 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=29 >type=USER_ROLE_CHANGE msg=audit(1362665326.097:719): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665326.100:720): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665326.100:721): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665326.101:722): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665326.102:723): user pid=2177 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2177 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665326.102:724): user pid=2177 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2177 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665326.103:725): user pid=2177 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665326.150:726): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665326.150:727): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665326.151:728): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665326.151:729): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665326.151:730): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2174 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665326.151:731): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2174 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665326.151:732): user pid=2174 uid=0 auid=0 ses=29 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2174 suid=0 rport=60156 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.192:733): user pid=2184 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2184 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.192:734): user pid=2184 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2184 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665329.192:735): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2184 suid=74 rport=60157 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665329.193:736): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2184 suid=74 rport=60157 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665329.257:737): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60157 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665329.257:738): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60157 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665329.266:739): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.266:740): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2184 suid=74 rport=60157 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665329.267:741): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665329.268:742): user pid=2183 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665329.268:743): pid=2183 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=30 >type=USER_ROLE_CHANGE msg=audit(1362665329.396:744): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665329.399:745): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665329.401:746): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665329.401:747): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.402:748): user pid=2186 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2186 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.402:749): user pid=2186 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2186 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665329.402:750): user pid=2186 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665329.453:751): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665329.453:752): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665329.454:753): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665329.454:754): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.454:755): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2183 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.454:756): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2183 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665329.454:757): user pid=2183 uid=0 auid=0 ses=30 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2183 suid=0 rport=60157 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.492:758): user pid=2193 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2193 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.492:759): user pid=2193 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2193 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665332.493:760): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2193 suid=74 rport=60158 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665332.494:761): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2193 suid=74 rport=60158 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665332.557:762): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60158 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665332.557:763): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60158 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665332.564:764): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.564:765): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2193 suid=74 rport=60158 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665332.565:766): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665332.565:767): user pid=2192 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665332.566:768): pid=2192 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=31 >type=USER_ROLE_CHANGE msg=audit(1362665332.697:769): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665332.701:770): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665332.706:771): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665332.707:772): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.708:773): user pid=2195 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2195 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.708:774): user pid=2195 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2195 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665332.709:775): user pid=2195 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665332.754:776): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665332.755:777): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665332.755:778): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665332.755:779): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.756:780): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2192 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.756:781): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2192 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665332.756:782): user pid=2192 uid=0 auid=0 ses=31 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2192 suid=0 rport=60158 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665335.793:783): user pid=2202 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2202 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665335.794:784): user pid=2202 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2202 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665335.794:785): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2202 suid=74 rport=60159 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665335.794:786): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2202 suid=74 rport=60159 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665335.858:787): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60159 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665335.858:788): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60159 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665335.866:789): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665335.867:790): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2202 suid=74 rport=60159 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665335.867:791): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665335.868:792): user pid=2201 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665335.868:793): pid=2201 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=32 >type=USER_ROLE_CHANGE msg=audit(1362665335.998:794): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665336.000:795): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665336.005:796): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665336.005:797): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665336.006:798): user pid=2204 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2204 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665336.006:799): user pid=2204 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2204 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665336.007:800): user pid=2204 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665336.051:801): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665336.052:802): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665336.052:803): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665336.052:804): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665336.052:805): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2201 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665336.052:806): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2201 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665336.053:807): user pid=2201 uid=0 auid=0 ses=32 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2201 suid=0 rport=60159 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.091:808): user pid=2211 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2211 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.092:809): user pid=2211 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2211 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665339.092:810): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2211 suid=74 rport=60160 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665339.092:811): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2211 suid=74 rport=60160 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665339.156:812): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60160 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665339.156:813): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60160 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665339.163:814): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.164:815): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2211 suid=74 rport=60160 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665339.165:816): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665339.165:817): user pid=2210 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665339.165:818): pid=2210 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=33 >type=USER_ROLE_CHANGE msg=audit(1362665339.295:819): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665339.299:820): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665339.304:821): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665339.305:822): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.306:823): user pid=2213 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2213 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.306:824): user pid=2213 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2213 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665339.307:825): user pid=2213 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665339.354:826): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665339.354:827): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665339.355:828): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665339.355:829): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.355:830): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2210 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.355:831): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2210 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665339.355:832): user pid=2210 uid=0 auid=0 ses=33 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2210 suid=0 rport=60160 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.395:833): user pid=2220 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2220 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.395:834): user pid=2220 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2220 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665342.396:835): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2220 suid=74 rport=60161 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665342.396:836): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2220 suid=74 rport=60161 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665342.459:837): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60161 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665342.459:838): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60161 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665342.466:839): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.466:840): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2220 suid=74 rport=60161 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665342.467:841): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665342.468:842): user pid=2219 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665342.468:843): pid=2219 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=34 >type=USER_ROLE_CHANGE msg=audit(1362665342.592:844): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665342.595:845): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665342.601:846): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665342.601:847): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.602:848): user pid=2222 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2222 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.602:849): user pid=2222 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2222 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665342.602:850): user pid=2222 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665342.652:851): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665342.652:852): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665342.652:853): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665342.652:854): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.652:855): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2219 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.653:856): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2219 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665342.653:857): user pid=2219 uid=0 auid=0 ses=34 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2219 suid=0 rport=60161 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665345.710:858): user pid=2232 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2232 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665345.711:859): user pid=2232 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2232 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665345.712:860): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2232 suid=74 rport=60162 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665345.712:861): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2232 suid=74 rport=60162 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665345.776:862): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60162 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665345.776:863): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60162 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665345.785:864): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665345.785:865): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2232 suid=74 rport=60162 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665345.786:866): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665345.787:867): user pid=2231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665345.787:868): pid=2231 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=35 >type=USER_ROLE_CHANGE msg=audit(1362665345.955:869): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665345.959:870): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665345.966:871): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665345.966:872): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665345.968:873): user pid=2234 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2234 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665345.968:874): user pid=2234 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2234 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665345.970:875): user pid=2234 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=MAC_POLICY_LOAD msg=audit(1362665344.288:876): policy loaded auid=0 ses=21 >type=SYSCALL msg=audit(1362665344.288:876): arch=c000003e syscall=1 success=yes exit=7258787 a0=4 a1=7f2f0cee7000 a2=6ec2a3 a3=7fffbdd54c90 items=0 ppid=2124 pid=2227 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=21 comm="load_policy" exe="/sbin/load_policy" subj=unconfined_u:system_r:load_policy_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362665346.637:877): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665346.637:878): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665346.637:879): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665346.638:880): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665346.638:881): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2231 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665346.638:882): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2231 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665346.638:883): user pid=2231 uid=0 auid=0 ses=35 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2231 suid=0 rport=60162 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.680:884): user pid=2244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2244 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.681:885): user pid=2244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2244 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665349.681:886): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2244 suid=74 rport=60163 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665349.682:887): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2244 suid=74 rport=60163 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665349.744:888): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60163 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665349.744:889): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60163 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665349.752:890): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.753:891): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2244 suid=74 rport=60163 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665349.754:892): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665349.754:893): user pid=2243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665349.754:894): pid=2243 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=36 >type=USER_ROLE_CHANGE msg=audit(1362665349.895:895): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665349.898:896): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665349.904:897): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665349.904:898): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.905:899): user pid=2246 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2246 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.905:900): user pid=2246 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2246 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665349.906:901): user pid=2246 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665349.945:902): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665349.945:903): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665349.945:904): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665349.946:905): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.946:906): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2243 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.946:907): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2243 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.946:908): user pid=2243 uid=0 auid=0 ses=36 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2243 suid=0 rport=60163 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.969:909): user pid=2251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665349.969:910): user pid=2251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665349.970:911): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2251 suid=74 rport=60164 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665349.970:912): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2251 suid=74 rport=60164 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.033:913): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60164 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.033:914): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60164 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665350.038:915): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.039:916): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2251 suid=74 rport=60164 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.039:917): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665350.040:918): user pid=2250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665350.040:919): pid=2250 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=37 >type=USER_ROLE_CHANGE msg=audit(1362665350.157:920): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665350.159:921): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665350.164:922): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665350.164:923): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.165:924): user pid=2253 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2253 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.165:925): user pid=2253 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2253 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665350.166:926): user pid=2253 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665350.219:927): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665350.219:928): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665350.220:929): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665350.220:930): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.220:931): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2250 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.220:932): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2250 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.220:933): user pid=2250 uid=0 auid=0 ses=37 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2250 suid=0 rport=60164 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.243:934): user pid=2263 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2263 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.244:935): user pid=2263 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2263 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665350.244:936): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2263 suid=74 rport=60165 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665350.244:937): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2263 suid=74 rport=60165 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.306:938): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60165 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.306:939): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60165 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665350.313:940): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.313:941): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2263 suid=74 rport=60165 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.314:942): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665350.314:943): user pid=2262 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665350.315:944): pid=2262 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=38 >type=USER_ROLE_CHANGE msg=audit(1362665350.463:945): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665350.471:946): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665350.478:947): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665350.479:948): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.480:949): user pid=2288 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2288 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.480:950): user pid=2288 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2288 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665350.481:951): user pid=2288 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665350.521:952): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665350.522:953): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665350.522:954): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665350.522:955): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.522:956): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2262 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.522:957): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2262 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.523:958): user pid=2262 uid=0 auid=0 ses=38 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2262 suid=0 rport=60165 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.562:959): user pid=2299 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2299 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.563:960): user pid=2299 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2299 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665350.564:961): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2299 suid=74 rport=60166 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665350.564:962): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2299 suid=74 rport=60166 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.644:963): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60166 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.644:964): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60166 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665350.653:965): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.653:966): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2299 suid=74 rport=60166 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665350.654:967): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665350.654:968): user pid=2298 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665350.654:969): pid=2298 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=39 >type=USER_ROLE_CHANGE msg=audit(1362665350.777:970): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665350.780:971): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665350.786:972): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665350.786:973): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.787:974): user pid=2301 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2301 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.787:975): user pid=2301 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2301 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665350.789:976): user pid=2301 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665350.834:977): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665350.834:978): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665350.835:979): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665350.835:980): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.835:981): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2298 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.835:982): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2298 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665350.835:983): user pid=2298 uid=0 auid=0 ses=39 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2298 suid=0 rport=60166 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665353.886:984): user pid=2534 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2534 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665353.886:985): user pid=2534 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2534 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665353.886:986): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2534 suid=74 rport=60167 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665353.887:987): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2534 suid=74 rport=60167 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665353.950:988): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60167 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665353.950:989): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60167 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665353.959:990): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665353.960:991): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2534 suid=74 rport=60167 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665353.960:992): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665353.961:993): user pid=2533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665353.961:994): pid=2533 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=40 >type=USER_ROLE_CHANGE msg=audit(1362665354.093:995): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665354.095:996): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665354.101:997): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665354.101:998): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665354.103:999): user pid=2536 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2536 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665354.103:1000): user pid=2536 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2536 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665354.104:1001): user pid=2536 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665354.148:1002): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665354.148:1003): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665354.149:1004): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665354.149:1005): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665354.149:1006): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2533 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665354.149:1007): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2533 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665354.149:1008): user pid=2533 uid=0 auid=0 ses=40 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2533 suid=0 rport=60167 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.194:1009): user pid=2543 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2543 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.194:1010): user pid=2543 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2543 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665357.196:1011): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2543 suid=74 rport=60169 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665357.196:1012): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2543 suid=74 rport=60169 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665357.258:1013): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60169 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665357.258:1014): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60169 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665357.266:1015): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.269:1016): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2543 suid=74 rport=60169 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665357.269:1017): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665357.269:1018): user pid=2542 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665357.270:1019): pid=2542 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=41 >type=USER_ROLE_CHANGE msg=audit(1362665357.407:1020): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665357.412:1021): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665357.417:1022): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665357.417:1023): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.418:1024): user pid=2545 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2545 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.418:1025): user pid=2545 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2545 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665357.419:1026): user pid=2545 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665357.468:1027): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665357.469:1028): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665357.469:1029): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665357.469:1030): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.469:1031): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2542 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.469:1032): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2542 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665357.470:1033): user pid=2542 uid=0 auid=0 ses=41 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2542 suid=0 rport=60169 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665359.783:1034): table=filter family=2 entries=10 >type=SYSCALL msg=audit(1362665359.783:1034): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=14f0f20 items=0 ppid=2261 pid=2551 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=37 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362665360.522:1035): user pid=2563 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2563 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.523:1036): user pid=2563 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2563 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665360.523:1037): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2563 suid=74 rport=60170 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665360.523:1038): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2563 suid=74 rport=60170 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665360.586:1039): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60170 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665360.586:1040): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60170 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665360.595:1041): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.598:1042): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2563 suid=74 rport=60170 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665360.599:1043): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665360.599:1044): user pid=2562 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665360.599:1045): pid=2562 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=42 >type=USER_ROLE_CHANGE msg=audit(1362665360.732:1046): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665360.737:1047): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665360.743:1048): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665360.743:1049): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.745:1050): user pid=2565 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2565 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.745:1051): user pid=2565 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2565 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665360.746:1052): user pid=2565 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665360.790:1053): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665360.790:1054): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665360.791:1055): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665360.791:1056): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.791:1057): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2562 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.791:1058): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2562 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665360.791:1059): user pid=2562 uid=0 auid=0 ses=42 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2562 suid=0 rport=60170 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665363.829:1060): user pid=2572 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2572 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665363.830:1061): user pid=2572 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2572 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665363.830:1062): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2572 suid=74 rport=60172 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665363.830:1063): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2572 suid=74 rport=60172 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665363.893:1064): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60172 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665363.893:1065): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60172 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665363.900:1066): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665363.901:1067): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2572 suid=74 rport=60172 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665363.901:1068): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665363.902:1069): user pid=2571 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665363.902:1070): pid=2571 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=43 >type=USER_ROLE_CHANGE msg=audit(1362665364.031:1071): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665364.036:1072): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665364.042:1073): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665364.043:1074): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665364.043:1075): user pid=2574 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2574 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665364.044:1076): user pid=2574 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2574 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665364.044:1077): user pid=2574 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665364.092:1078): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665364.092:1079): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665364.093:1080): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665364.093:1081): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665364.093:1082): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2571 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665364.093:1083): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2571 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665364.093:1084): user pid=2571 uid=0 auid=0 ses=43 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2571 suid=0 rport=60172 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.133:1085): user pid=2581 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2581 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.133:1086): user pid=2581 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2581 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665367.134:1087): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2581 suid=74 rport=60174 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665367.134:1088): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2581 suid=74 rport=60174 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665367.197:1089): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60174 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665367.198:1090): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60174 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665367.205:1091): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.205:1092): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2581 suid=74 rport=60174 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665367.206:1093): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665367.206:1094): user pid=2580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665367.206:1095): pid=2580 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=44 >type=USER_ROLE_CHANGE msg=audit(1362665367.332:1096): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665367.339:1097): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665367.346:1098): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665367.346:1099): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.348:1100): user pid=2583 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2583 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.348:1101): user pid=2583 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2583 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665367.349:1102): user pid=2583 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665367.392:1103): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665367.393:1104): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665367.393:1105): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665367.393:1106): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.393:1107): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2580 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.393:1108): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2580 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665367.394:1109): user pid=2580 uid=0 auid=0 ses=44 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2580 suid=0 rport=60174 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.433:1110): user pid=2590 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2590 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.434:1111): user pid=2590 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2590 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665370.434:1112): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2590 suid=74 rport=60175 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665370.434:1113): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2590 suid=74 rport=60175 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665370.497:1114): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60175 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665370.497:1115): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60175 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665370.505:1116): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.505:1117): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2590 suid=74 rport=60175 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665370.506:1118): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665370.506:1119): user pid=2589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665370.506:1120): pid=2589 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=45 >type=USER_ROLE_CHANGE msg=audit(1362665370.626:1121): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665370.631:1122): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665370.636:1123): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665370.636:1124): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.637:1125): user pid=2592 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2592 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.637:1126): user pid=2592 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2592 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665370.638:1127): user pid=2592 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665370.680:1128): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665370.681:1129): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665370.681:1130): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665370.681:1131): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.681:1132): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2589 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.681:1133): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2589 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665370.682:1134): user pid=2589 uid=0 auid=0 ses=45 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2589 suid=0 rport=60175 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.720:1135): user pid=2599 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2599 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.720:1136): user pid=2599 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2599 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665373.721:1137): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2599 suid=74 rport=60176 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665373.721:1138): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2599 suid=74 rport=60176 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665373.786:1139): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60176 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665373.786:1140): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60176 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665373.793:1141): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.794:1142): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2599 suid=74 rport=60176 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665373.795:1143): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665373.795:1144): user pid=2598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665373.795:1145): pid=2598 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=46 >type=USER_ROLE_CHANGE msg=audit(1362665373.925:1146): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665373.931:1147): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665373.937:1148): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665373.937:1149): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.938:1150): user pid=2601 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2601 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.938:1151): user pid=2601 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2601 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665373.939:1152): user pid=2601 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665373.985:1153): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665373.985:1154): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665373.986:1155): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665373.986:1156): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.986:1157): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2598 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.986:1158): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2598 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665373.987:1159): user pid=2598 uid=0 auid=0 ses=46 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2598 suid=0 rport=60176 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.030:1160): user pid=2608 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2608 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.030:1161): user pid=2608 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2608 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665377.033:1162): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2608 suid=74 rport=60178 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665377.033:1163): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2608 suid=74 rport=60178 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665377.094:1164): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60178 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665377.094:1165): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60178 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665377.102:1166): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.102:1167): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2608 suid=74 rport=60178 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665377.103:1168): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665377.104:1169): user pid=2607 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665377.104:1170): pid=2607 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=47 >type=USER_ROLE_CHANGE msg=audit(1362665377.231:1171): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665377.235:1172): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665377.235:1173): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665377.235:1174): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.236:1175): user pid=2610 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2610 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.236:1176): user pid=2610 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2610 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665377.237:1177): user pid=2610 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665377.284:1178): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665377.284:1179): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665377.284:1180): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665377.285:1181): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.285:1182): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2607 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.285:1183): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2607 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665377.285:1184): user pid=2607 uid=0 auid=0 ses=47 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2607 suid=0 rport=60178 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.337:1185): user pid=2617 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2617 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.337:1186): user pid=2617 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2617 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665380.340:1187): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2617 suid=74 rport=60180 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665380.340:1188): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2617 suid=74 rport=60180 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665380.403:1189): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60180 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665380.404:1190): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60180 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665380.412:1191): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.413:1192): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2617 suid=74 rport=60180 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665380.414:1193): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665380.414:1194): user pid=2616 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665380.414:1195): pid=2616 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=48 >type=USER_ROLE_CHANGE msg=audit(1362665380.532:1196): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665380.537:1197): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665380.537:1198): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665380.537:1199): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.538:1200): user pid=2619 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2619 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.538:1201): user pid=2619 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2619 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665380.539:1202): user pid=2619 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665380.586:1203): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665380.587:1204): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665380.589:1205): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665380.589:1206): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.589:1207): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2616 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.589:1208): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2616 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665380.590:1209): user pid=2616 uid=0 auid=0 ses=48 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2616 suid=0 rport=60180 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.632:1210): user pid=2626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2626 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.632:1211): user pid=2626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2626 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665383.634:1212): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2626 suid=74 rport=60181 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665383.634:1213): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2626 suid=74 rport=60181 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665383.697:1214): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60181 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665383.697:1215): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60181 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665383.706:1216): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.707:1217): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2626 suid=74 rport=60181 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665383.707:1218): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665383.708:1219): user pid=2625 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665383.708:1220): pid=2625 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=49 >type=USER_ROLE_CHANGE msg=audit(1362665383.838:1221): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665383.841:1222): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665383.847:1223): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665383.848:1224): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.848:1225): user pid=2628 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2628 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.849:1226): user pid=2628 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2628 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665383.849:1227): user pid=2628 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665383.894:1228): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665383.894:1229): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665383.895:1230): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665383.895:1231): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.895:1232): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2625 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.895:1233): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2625 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665383.895:1234): user pid=2625 uid=0 auid=0 ses=49 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2625 suid=0 rport=60181 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665386.239:1235): user pid=2632 uid=0 auid=0 ses=37 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=27 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665386.377:1236): user pid=2632 uid=0 auid=0 ses=37 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=27 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665386.378:1237): user pid=2632 uid=0 auid=0 ses=37 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=27 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665386.492:1238): user pid=2636 uid=0 auid=0 ses=37 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=27 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665386.950:1239): user pid=2645 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665386.950:1240): user pid=2645 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665386.951:1241): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2645 suid=74 rport=60182 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665386.951:1242): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2645 suid=74 rport=60182 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665387.014:1243): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60182 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665387.014:1244): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60182 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665387.021:1245): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665387.021:1246): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2645 suid=74 rport=60182 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665387.022:1247): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665387.023:1248): user pid=2644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665387.023:1249): pid=2644 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=50 >type=USER_ROLE_CHANGE msg=audit(1362665387.160:1250): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665387.165:1251): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665387.171:1252): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665387.171:1253): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665387.173:1254): user pid=2647 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2647 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665387.173:1255): user pid=2647 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2647 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665387.174:1256): user pid=2647 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665387.220:1257): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665387.221:1258): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665387.221:1259): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665387.221:1260): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665387.221:1261): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2644 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665387.221:1262): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2644 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665387.222:1263): user pid=2644 uid=0 auid=0 ses=50 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2644 suid=0 rport=60182 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.267:1264): user pid=2658 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2658 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.267:1265): user pid=2658 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2658 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665390.268:1266): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2658 suid=74 rport=60183 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665390.268:1267): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2658 suid=74 rport=60183 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665390.332:1268): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60183 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665390.333:1269): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60183 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665390.341:1270): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.341:1271): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2658 suid=74 rport=60183 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665390.342:1272): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665390.342:1273): user pid=2657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665390.342:1274): pid=2657 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=51 >type=USER_ROLE_CHANGE msg=audit(1362665390.479:1275): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665390.483:1276): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665390.489:1277): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665390.489:1278): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.490:1279): user pid=2660 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2660 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.491:1280): user pid=2660 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2660 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665390.491:1281): user pid=2660 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665390.536:1282): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665390.536:1283): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665390.536:1284): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665390.537:1285): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.537:1286): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2657 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.537:1287): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2657 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665390.537:1288): user pid=2657 uid=0 auid=0 ses=51 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2657 suid=0 rport=60183 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.591:1289): user pid=2750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2750 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.591:1290): user pid=2750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2750 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665393.592:1291): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2750 suid=74 rport=60184 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665393.592:1292): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2750 suid=74 rport=60184 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665393.658:1293): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60184 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665393.658:1294): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60184 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665393.666:1295): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.666:1296): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2750 suid=74 rport=60184 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665393.667:1297): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665393.668:1298): user pid=2749 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665393.668:1299): pid=2749 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=52 >type=USER_ROLE_CHANGE msg=audit(1362665393.799:1300): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665393.802:1301): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665393.808:1302): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665393.808:1303): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.809:1304): user pid=2752 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2752 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.809:1305): user pid=2752 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2752 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665393.809:1306): user pid=2752 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665393.855:1307): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665393.855:1308): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665393.856:1309): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665393.856:1310): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.856:1311): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2749 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.856:1312): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2749 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665393.856:1313): user pid=2749 uid=0 auid=0 ses=52 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2749 suid=0 rport=60184 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665396.911:1314): user pid=2925 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2925 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665396.911:1315): user pid=2925 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2925 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665396.914:1316): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2925 suid=74 rport=60185 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665396.914:1317): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2925 suid=74 rport=60185 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665396.981:1318): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60185 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665396.981:1319): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60185 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665396.989:1320): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665396.990:1321): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2925 suid=74 rport=60185 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665396.991:1322): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665396.991:1323): user pid=2924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665396.992:1324): pid=2924 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=53 >type=USER_ROLE_CHANGE msg=audit(1362665397.123:1325): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665397.128:1326): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665397.134:1327): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665397.135:1328): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665397.136:1329): user pid=2927 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2927 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665397.136:1330): user pid=2927 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2927 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665397.137:1331): user pid=2927 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665397.180:1332): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665397.180:1333): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665397.180:1334): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665397.181:1335): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665397.181:1336): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2924 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665397.181:1337): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2924 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665397.181:1338): user pid=2924 uid=0 auid=0 ses=53 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2924 suid=0 rport=60185 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.222:1339): user pid=2940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2940 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.223:1340): user pid=2940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2940 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665400.223:1341): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=2940 suid=74 rport=60186 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665400.223:1342): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=2940 suid=74 rport=60186 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665400.286:1343): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60186 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665400.286:1344): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60186 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665400.293:1345): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.294:1346): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2940 suid=74 rport=60186 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665400.294:1347): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665400.295:1348): user pid=2939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665400.295:1349): pid=2939 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=54 >type=USER_ROLE_CHANGE msg=audit(1362665400.425:1350): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665400.430:1351): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665400.435:1352): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665400.435:1353): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.436:1354): user pid=2943 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2943 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.436:1355): user pid=2943 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2943 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665400.437:1356): user pid=2943 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665400.484:1357): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665400.484:1358): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665400.485:1359): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665400.485:1360): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.485:1361): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=2939 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.485:1362): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=2939 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665400.485:1363): user pid=2939 uid=0 auid=0 ses=54 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=2939 suid=0 rport=60186 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.538:1364): user pid=3148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3148 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.538:1365): user pid=3148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3148 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665403.539:1366): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3148 suid=74 rport=60187 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665403.539:1367): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3148 suid=74 rport=60187 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665403.604:1368): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60187 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665403.604:1369): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60187 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665403.616:1370): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.616:1371): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3148 suid=74 rport=60187 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665403.617:1372): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665403.618:1373): user pid=3147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665403.618:1374): pid=3147 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=55 >type=USER_ROLE_CHANGE msg=audit(1362665403.756:1375): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665403.761:1376): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665403.771:1377): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665403.771:1378): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.772:1379): user pid=3155 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3155 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.772:1380): user pid=3155 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3155 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665403.773:1381): user pid=3155 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665403.811:1382): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665403.811:1383): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665403.812:1384): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665403.812:1385): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.812:1386): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3147 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.812:1387): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3147 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665403.812:1388): user pid=3147 uid=0 auid=0 ses=55 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3147 suid=0 rport=60187 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665406.847:1389): user pid=3398 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3398 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665406.847:1390): user pid=3398 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3398 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665406.848:1391): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3398 suid=74 rport=60188 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665406.848:1392): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3398 suid=74 rport=60188 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665406.913:1393): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60188 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665406.913:1394): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60188 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665406.925:1395): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665406.926:1396): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3398 suid=74 rport=60188 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665406.927:1397): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665406.927:1398): user pid=3393 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665406.927:1399): pid=3393 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=56 >type=USER_ROLE_CHANGE msg=audit(1362665407.065:1400): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665407.071:1401): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665407.077:1402): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665407.077:1403): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665407.078:1404): user pid=3459 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3459 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665407.078:1405): user pid=3459 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3459 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665407.079:1406): user pid=3459 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665407.110:1407): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665407.110:1408): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665407.110:1409): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665407.111:1410): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665407.111:1411): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3393 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665407.111:1412): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3393 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665407.111:1413): user pid=3393 uid=0 auid=0 ses=56 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3393 suid=0 rport=60188 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.156:1414): user pid=3491 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3491 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.157:1415): user pid=3491 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3491 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665410.159:1416): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3491 suid=74 rport=60190 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665410.159:1417): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3491 suid=74 rport=60190 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665410.222:1418): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60190 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665410.222:1419): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60190 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665410.234:1420): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.235:1421): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3491 suid=74 rport=60190 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665410.236:1422): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665410.237:1423): user pid=3490 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665410.237:1424): pid=3490 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=57 >type=USER_ROLE_CHANGE msg=audit(1362665410.359:1425): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665410.362:1426): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665410.364:1427): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665410.364:1428): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.365:1429): user pid=3493 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3493 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.365:1430): user pid=3493 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3493 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665410.366:1431): user pid=3493 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665410.419:1432): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665410.419:1433): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665410.420:1434): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665410.420:1435): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.420:1436): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3490 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.420:1437): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3490 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.421:1438): user pid=3490 uid=0 auid=0 ses=57 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3490 suid=0 rport=60190 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.456:1439): user pid=3500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3500 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.456:1440): user pid=3500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3500 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665410.456:1441): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3500 suid=74 rport=60191 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665410.456:1442): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3500 suid=74 rport=60191 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665410.520:1443): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60191 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665410.520:1444): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60191 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665410.527:1445): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.528:1446): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3500 suid=74 rport=60191 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665410.529:1447): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665410.529:1448): user pid=3499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665410.529:1449): pid=3499 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=58 >type=USER_ROLE_CHANGE msg=audit(1362665410.652:1450): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665410.654:1451): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665410.654:1452): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665410.654:1453): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.656:1454): user pid=3502 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3502 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.656:1455): user pid=3502 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3502 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665410.657:1456): user pid=3502 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665410.703:1457): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665410.703:1458): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665410.704:1459): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665410.704:1460): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.704:1461): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3499 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.705:1462): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3499 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665410.705:1463): user pid=3499 uid=0 auid=0 ses=58 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3499 suid=0 rport=60191 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.743:1464): user pid=3509 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3509 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.743:1465): user pid=3509 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3509 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665413.744:1466): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3509 suid=74 rport=60195 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665413.744:1467): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3509 suid=74 rport=60195 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665413.807:1468): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60195 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665413.807:1469): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60195 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665413.817:1470): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.818:1471): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3509 suid=74 rport=60195 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665413.819:1472): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665413.819:1473): user pid=3508 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665413.820:1474): pid=3508 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=59 >type=USER_ROLE_CHANGE msg=audit(1362665413.939:1475): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665413.941:1476): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665413.947:1477): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665413.948:1478): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.948:1479): user pid=3511 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3511 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.949:1480): user pid=3511 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3511 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665413.949:1481): user pid=3511 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665413.989:1482): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665413.989:1483): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665413.990:1484): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665413.990:1485): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.990:1486): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3508 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.990:1487): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3508 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665413.990:1488): user pid=3508 uid=0 auid=0 ses=59 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3508 suid=0 rport=60195 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.027:1489): user pid=3518 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3518 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.027:1490): user pid=3518 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3518 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665417.028:1491): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3518 suid=74 rport=60196 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665417.029:1492): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3518 suid=74 rport=60196 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665417.093:1493): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60196 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665417.093:1494): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60196 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665417.101:1495): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.102:1496): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3518 suid=74 rport=60196 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665417.103:1497): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665417.103:1498): user pid=3517 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665417.103:1499): pid=3517 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=60 >type=USER_ROLE_CHANGE msg=audit(1362665417.235:1500): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665417.237:1501): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665417.242:1502): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665417.242:1503): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.243:1504): user pid=3520 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3520 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.243:1505): user pid=3520 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3520 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665417.244:1506): user pid=3520 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665417.287:1507): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665417.287:1508): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665417.287:1509): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665417.288:1510): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.288:1511): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3517 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.288:1512): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3517 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665417.288:1513): user pid=3517 uid=0 auid=0 ses=60 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3517 suid=0 rport=60196 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.327:1514): user pid=3527 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3527 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.328:1515): user pid=3527 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3527 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665420.328:1516): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3527 suid=74 rport=60198 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665420.328:1517): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3527 suid=74 rport=60198 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665420.391:1518): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60198 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665420.391:1519): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60198 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665420.399:1520): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.400:1521): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3527 suid=74 rport=60198 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665420.400:1522): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665420.401:1523): user pid=3526 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665420.401:1524): pid=3526 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=61 >type=USER_ROLE_CHANGE msg=audit(1362665420.519:1525): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665420.525:1526): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665420.530:1527): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665420.530:1528): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.531:1529): user pid=3529 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3529 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.531:1530): user pid=3529 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3529 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665420.532:1531): user pid=3529 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665420.582:1532): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665420.582:1533): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665420.582:1534): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665420.582:1535): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.582:1536): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3526 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.583:1537): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3526 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665420.583:1538): user pid=3526 uid=0 auid=0 ses=61 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3526 suid=0 rport=60198 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.642:1539): user pid=3539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3539 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.643:1540): user pid=3539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3539 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665423.643:1541): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3539 suid=74 rport=60199 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665423.643:1542): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3539 suid=74 rport=60199 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665423.709:1543): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60199 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665423.709:1544): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60199 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665423.716:1545): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.717:1546): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3539 suid=74 rport=60199 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665423.718:1547): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665423.718:1548): user pid=3538 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665423.719:1549): pid=3538 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=62 >type=USER_ROLE_CHANGE msg=audit(1362665423.846:1550): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665423.849:1551): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665423.856:1552): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665423.856:1553): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.857:1554): user pid=3541 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3541 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.857:1555): user pid=3541 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3541 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665423.858:1556): user pid=3541 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665423.903:1557): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665423.903:1558): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665423.904:1559): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665423.904:1560): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.904:1561): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3538 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.904:1562): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3538 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665423.905:1563): user pid=3538 uid=0 auid=0 ses=62 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3538 suid=0 rport=60199 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665424.531:1564): user pid=3548 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=499 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665424.640:1565): user pid=3548 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=499 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665424.641:1566): user pid=3548 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=499 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665424.743:1567): user pid=3553 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=498 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665426.966:1568): user pid=3565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3565 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665426.966:1569): user pid=3565 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3565 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665426.968:1570): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3565 suid=74 rport=60200 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665426.968:1571): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3565 suid=74 rport=60200 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665427.030:1572): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60200 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665427.030:1573): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60200 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665427.036:1574): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665427.037:1575): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3565 suid=74 rport=60200 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665427.037:1576): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665427.038:1577): user pid=3564 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665427.038:1578): pid=3564 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=63 >type=USER_ROLE_CHANGE msg=audit(1362665427.171:1579): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665427.175:1580): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665427.181:1581): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665427.181:1582): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665427.183:1583): user pid=3567 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3567 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665427.183:1584): user pid=3567 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3567 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665427.183:1585): user pid=3567 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665427.231:1586): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665427.232:1587): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665427.232:1588): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665427.232:1589): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665427.232:1590): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3564 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665427.232:1591): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3564 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665427.232:1592): user pid=3564 uid=0 auid=0 ses=63 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3564 suid=0 rport=60200 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665427.800:1593): table=filter family=2 entries=11 >type=SYSCALL msg=audit(1362665427.800:1593): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=c04370 items=0 ppid=3226 pid=3575 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=38 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=USER_START msg=audit(1362665428.032:1594): user pid=3588 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.032:1595): user pid=3588 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.036:1596): user pid=3588 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.037:1597): user pid=3588 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665428.041:1598): user pid=3590 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.041:1599): user pid=3590 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.088:1600): user pid=3590 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.088:1601): user pid=3590 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665428.294:1602): user pid=3603 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.294:1603): user pid=3603 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.351:1604): user pid=3603 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.351:1605): user pid=3603 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665428.489:1606): user pid=3630 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.489:1607): user pid=3630 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.492:1608): user pid=3630 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.492:1609): user pid=3630 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665428.649:1610): user pid=3643 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.649:1611): user pid=3643 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.652:1612): user pid=3643 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.652:1613): user pid=3643 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665428.657:1614): user pid=3645 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.657:1615): user pid=3645 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.679:1616): user pid=3645 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.679:1617): user pid=3645 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665428.864:1618): user pid=3658 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665428.864:1619): user pid=3658 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665428.911:1620): user pid=3658 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665428.911:1621): user pid=3658 uid=0 auid=0 ses=38 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="qpidd" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.288:1622): user pid=3678 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3678 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.288:1623): user pid=3678 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3678 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665430.292:1624): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3678 suid=74 rport=60201 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665430.292:1625): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3678 suid=74 rport=60201 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.356:1626): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60201 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.356:1627): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60201 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665430.363:1628): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.364:1629): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3678 suid=74 rport=60201 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.365:1630): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665430.365:1631): user pid=3677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665430.365:1632): pid=3677 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=64 >type=USER_ROLE_CHANGE msg=audit(1362665430.498:1633): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665430.503:1634): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665430.509:1635): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665430.509:1636): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.510:1637): user pid=3680 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3680 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.510:1638): user pid=3680 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3680 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665430.512:1639): user pid=3680 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665430.557:1640): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665430.557:1641): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665430.558:1642): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665430.558:1643): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.558:1644): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3677 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.558:1645): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3677 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.558:1646): user pid=3677 uid=0 auid=0 ses=64 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3677 suid=0 rport=60201 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.586:1647): user pid=3685 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3685 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.587:1648): user pid=3685 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3685 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665430.587:1649): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3685 suid=74 rport=60202 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665430.588:1650): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3685 suid=74 rport=60202 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.652:1651): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60202 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.652:1652): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60202 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665430.658:1653): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.659:1654): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3685 suid=74 rport=60202 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.660:1655): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665430.660:1656): user pid=3684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665430.660:1657): pid=3684 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=65 >type=USER_ROLE_CHANGE msg=audit(1362665430.787:1658): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665430.790:1659): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665430.795:1660): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665430.795:1661): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.796:1662): user pid=3687 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3687 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.796:1663): user pid=3687 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3687 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665430.797:1664): user pid=3687 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665430.845:1665): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665430.845:1666): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665430.846:1667): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665430.846:1668): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.846:1669): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3684 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.846:1670): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3684 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.846:1671): user pid=3684 uid=0 auid=0 ses=65 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3684 suid=0 rport=60202 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.873:1672): user pid=3697 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3697 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.873:1673): user pid=3697 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3697 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665430.874:1674): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3697 suid=74 rport=60203 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665430.874:1675): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3697 suid=74 rport=60203 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.939:1676): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60203 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.939:1677): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60203 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665430.947:1678): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665430.947:1679): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3697 suid=74 rport=60203 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665430.948:1680): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665430.948:1681): user pid=3696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665430.948:1682): pid=3696 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=66 >type=USER_ROLE_CHANGE msg=audit(1362665431.091:1683): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665431.099:1684): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665431.106:1685): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665431.106:1686): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.107:1687): user pid=3722 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3722 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.108:1688): user pid=3722 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3722 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665431.109:1689): user pid=3722 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665431.151:1690): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665431.151:1691): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665431.152:1692): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665431.152:1693): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.152:1694): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3696 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.153:1695): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3696 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.153:1696): user pid=3696 uid=0 auid=0 ses=66 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3696 suid=0 rport=60203 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.179:1697): user pid=3731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3731 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.180:1698): user pid=3731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3731 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665431.181:1699): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3731 suid=74 rport=60204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665431.181:1700): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3731 suid=74 rport=60204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665431.244:1701): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60204 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665431.244:1702): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60204 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665431.251:1703): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.253:1704): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3731 suid=74 rport=60204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665431.253:1705): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665431.254:1706): user pid=3730 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665431.254:1707): pid=3730 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=67 >type=USER_ROLE_CHANGE msg=audit(1362665431.388:1708): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665431.392:1709): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665431.398:1710): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665431.398:1711): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.399:1712): user pid=3744 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3744 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.399:1713): user pid=3744 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3744 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665431.400:1714): user pid=3744 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665431.434:1715): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665431.434:1716): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665431.435:1717): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665431.435:1718): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.435:1719): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3730 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.435:1720): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3730 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.435:1721): user pid=3730 uid=0 auid=0 ses=67 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3730 suid=0 rport=60204 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.470:1722): user pid=3758 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3758 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.470:1723): user pid=3758 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3758 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665431.471:1724): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3758 suid=74 rport=60205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665431.471:1725): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3758 suid=74 rport=60205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665431.537:1726): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60205 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665431.537:1727): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60205 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665431.548:1728): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.548:1729): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3758 suid=74 rport=60205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665431.549:1730): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665431.549:1731): user pid=3756 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665431.549:1732): pid=3756 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=68 >type=USER_ROLE_CHANGE msg=audit(1362665431.677:1733): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665431.683:1734): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665431.684:1735): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665431.684:1736): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.685:1737): user pid=3795 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3795 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.685:1738): user pid=3795 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3795 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665431.686:1739): user pid=3795 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665431.716:1740): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665431.717:1741): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665431.717:1742): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665431.717:1743): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.718:1744): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3756 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.718:1745): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3756 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665431.718:1746): user pid=3756 uid=0 auid=0 ses=68 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3756 suid=0 rport=60205 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665434.760:1747): user pid=3980 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3980 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665434.760:1748): user pid=3980 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3980 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665434.760:1749): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3980 suid=74 rport=60206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665434.761:1750): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3980 suid=74 rport=60206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665434.823:1751): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60206 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665434.823:1752): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60206 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665434.833:1753): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665434.833:1754): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3980 suid=74 rport=60206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665434.834:1755): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665434.835:1756): user pid=3979 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665434.835:1757): pid=3979 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=69 >type=USER_ROLE_CHANGE msg=audit(1362665434.970:1758): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665434.975:1759): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665434.982:1760): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665434.982:1761): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665434.983:1762): user pid=3982 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665434.983:1763): user pid=3982 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665434.984:1764): user pid=3982 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665435.029:1765): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665435.029:1766): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665435.030:1767): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665435.030:1768): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665435.030:1769): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3979 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665435.030:1770): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3979 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665435.030:1771): user pid=3979 uid=0 auid=0 ses=69 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3979 suid=0 rport=60206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.073:1772): user pid=3989 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3989 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.073:1773): user pid=3989 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3989 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665438.073:1774): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3989 suid=74 rport=60209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665438.074:1775): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3989 suid=74 rport=60209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665438.136:1776): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60209 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665438.136:1777): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60209 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665438.144:1778): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.147:1779): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3989 suid=74 rport=60209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665438.147:1780): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665438.148:1781): user pid=3988 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665438.148:1782): pid=3988 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=70 >type=USER_ROLE_CHANGE msg=audit(1362665438.277:1783): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665438.281:1784): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665438.282:1785): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665438.283:1786): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.284:1787): user pid=3991 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.284:1788): user pid=3991 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665438.285:1789): user pid=3991 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665438.331:1790): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665438.331:1791): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665438.332:1792): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665438.332:1793): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.332:1794): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3988 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.332:1795): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3988 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665438.332:1796): user pid=3988 uid=0 auid=0 ses=70 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3988 suid=0 rport=60209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.375:1797): user pid=3998 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3998 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.376:1798): user pid=3998 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3998 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665441.378:1799): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=3998 suid=74 rport=60220 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665441.378:1800): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=3998 suid=74 rport=60220 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665441.442:1801): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60220 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665441.442:1802): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60220 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665441.449:1803): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.450:1804): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3998 suid=74 rport=60220 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665441.451:1805): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665441.451:1806): user pid=3997 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665441.451:1807): pid=3997 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=71 >type=USER_ROLE_CHANGE msg=audit(1362665441.579:1808): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665441.582:1809): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665441.583:1810): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665441.583:1811): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.584:1812): user pid=4000 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.584:1813): user pid=4000 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665441.584:1814): user pid=4000 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665441.630:1815): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665441.630:1816): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665441.631:1817): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665441.631:1818): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.631:1819): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=3997 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.631:1820): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=3997 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665441.632:1821): user pid=3997 uid=0 auid=0 ses=71 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=3997 suid=0 rport=60220 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.673:1822): user pid=4007 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4007 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.674:1823): user pid=4007 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4007 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665444.676:1824): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4007 suid=74 rport=60222 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665444.676:1825): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4007 suid=74 rport=60222 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665444.739:1826): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60222 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665444.739:1827): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60222 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665444.746:1828): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.748:1829): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4007 suid=74 rport=60222 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665444.748:1830): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665444.749:1831): user pid=4006 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665444.749:1832): pid=4006 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=72 >type=USER_ROLE_CHANGE msg=audit(1362665444.873:1833): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665444.877:1834): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665444.877:1835): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665444.878:1836): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.879:1837): user pid=4009 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.879:1838): user pid=4009 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665444.879:1839): user pid=4009 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665444.928:1840): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665444.928:1841): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665444.929:1842): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665444.929:1843): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.929:1844): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4006 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.929:1845): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4006 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665444.930:1846): user pid=4006 uid=0 auid=0 ses=72 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4006 suid=0 rport=60222 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665447.972:1847): user pid=4016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4016 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665447.972:1848): user pid=4016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4016 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665447.974:1849): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4016 suid=74 rport=60223 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665447.974:1850): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4016 suid=74 rport=60223 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665448.037:1851): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60223 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665448.037:1852): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60223 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665448.045:1853): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665448.047:1854): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4016 suid=74 rport=60223 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665448.047:1855): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665448.048:1856): user pid=4015 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665448.048:1857): pid=4015 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=73 >type=USER_ROLE_CHANGE msg=audit(1362665448.177:1858): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665448.179:1859): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665448.180:1860): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665448.180:1861): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665448.181:1862): user pid=4018 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665448.181:1863): user pid=4018 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665448.182:1864): user pid=4018 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665448.229:1865): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665448.229:1866): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665448.230:1867): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665448.230:1868): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665448.230:1869): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4015 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665448.230:1870): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4015 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665448.231:1871): user pid=4015 uid=0 auid=0 ses=73 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4015 suid=0 rport=60223 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.271:1872): user pid=4025 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4025 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.271:1873): user pid=4025 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4025 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665451.272:1874): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4025 suid=74 rport=60225 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665451.272:1875): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4025 suid=74 rport=60225 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665451.335:1876): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60225 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665451.335:1877): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60225 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665451.346:1878): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.347:1879): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4025 suid=74 rport=60225 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665451.347:1880): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665451.348:1881): user pid=4024 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665451.348:1882): pid=4024 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=74 >type=USER_ROLE_CHANGE msg=audit(1362665451.472:1883): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665451.474:1884): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665451.479:1885): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665451.479:1886): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.480:1887): user pid=4027 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.480:1888): user pid=4027 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665451.481:1889): user pid=4027 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665451.525:1890): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665451.525:1891): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665451.526:1892): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665451.526:1893): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.526:1894): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4024 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.526:1895): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4024 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665451.526:1896): user pid=4024 uid=0 auid=0 ses=74 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4024 suid=0 rport=60225 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.564:1897): user pid=4034 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4034 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.564:1898): user pid=4034 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4034 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665454.565:1899): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4034 suid=74 rport=60229 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665454.565:1900): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4034 suid=74 rport=60229 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665454.629:1901): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60229 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665454.629:1902): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60229 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665454.636:1903): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.637:1904): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4034 suid=74 rport=60229 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665454.638:1905): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665454.638:1906): user pid=4033 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665454.638:1907): pid=4033 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=75 >type=USER_ROLE_CHANGE msg=audit(1362665454.766:1908): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665454.770:1909): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665454.775:1910): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665454.775:1911): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.776:1912): user pid=4036 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.777:1913): user pid=4036 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665454.778:1914): user pid=4036 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665454.824:1915): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665454.825:1916): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665454.825:1917): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665454.825:1918): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.826:1919): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4033 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.826:1920): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4033 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665454.826:1921): user pid=4033 uid=0 auid=0 ses=75 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4033 suid=0 rport=60229 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665457.871:1922): user pid=4043 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4043 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665457.872:1923): user pid=4043 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4043 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665457.872:1924): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4043 suid=74 rport=60234 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665457.872:1925): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4043 suid=74 rport=60234 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665457.936:1926): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60234 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665457.936:1927): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60234 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665457.945:1928): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665457.946:1929): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4043 suid=74 rport=60234 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665457.947:1930): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665457.947:1931): user pid=4042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665457.947:1932): pid=4042 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=76 >type=USER_ROLE_CHANGE msg=audit(1362665458.071:1933): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665458.073:1934): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665458.079:1935): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665458.079:1936): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665458.080:1937): user pid=4045 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4045 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665458.080:1938): user pid=4045 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4045 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665458.083:1939): user pid=4045 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665458.129:1940): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665458.129:1941): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665458.130:1942): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665458.130:1943): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665458.130:1944): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4042 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665458.130:1945): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4042 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665458.130:1946): user pid=4042 uid=0 auid=0 ses=76 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4042 suid=0 rport=60234 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.183:1947): user pid=4052 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4052 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.183:1948): user pid=4052 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4052 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665461.183:1949): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4052 suid=74 rport=60238 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665461.183:1950): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4052 suid=74 rport=60238 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665461.247:1951): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60238 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665461.247:1952): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60238 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665461.257:1953): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.258:1954): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4052 suid=74 rport=60238 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665461.259:1955): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665461.259:1956): user pid=4051 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665461.259:1957): pid=4051 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=77 >type=USER_ROLE_CHANGE msg=audit(1362665461.393:1958): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665461.398:1959): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665461.403:1960): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665461.404:1961): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.405:1962): user pid=4054 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4054 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.405:1963): user pid=4054 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4054 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665461.406:1964): user pid=4054 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665461.451:1965): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665461.451:1966): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665461.451:1967): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665461.452:1968): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.452:1969): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4051 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.452:1970): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4051 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665461.452:1971): user pid=4051 uid=0 auid=0 ses=77 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4051 suid=0 rport=60238 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.499:1972): user pid=4061 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4061 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.499:1973): user pid=4061 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4061 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665464.500:1974): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4061 suid=74 rport=60239 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665464.500:1975): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4061 suid=74 rport=60239 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665464.565:1976): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60239 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665464.565:1977): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60239 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665464.574:1978): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.574:1979): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4061 suid=74 rport=60239 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665464.576:1980): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665464.576:1981): user pid=4060 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665464.576:1982): pid=4060 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=78 >type=USER_ROLE_CHANGE msg=audit(1362665464.706:1983): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665464.711:1984): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665464.717:1985): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665464.718:1986): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.718:1987): user pid=4063 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4063 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.718:1988): user pid=4063 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4063 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665464.719:1989): user pid=4063 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665464.769:1990): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665464.770:1991): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665464.770:1992): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665464.770:1993): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.770:1994): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4060 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.770:1995): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4060 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665464.771:1996): user pid=4060 uid=0 auid=0 ses=78 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4060 suid=0 rport=60239 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665467.820:1997): user pid=4070 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4070 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665467.820:1998): user pid=4070 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4070 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665467.821:1999): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4070 suid=74 rport=60240 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665467.821:2000): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4070 suid=74 rport=60240 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665467.886:2001): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60240 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665467.886:2002): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60240 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665467.894:2003): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665467.894:2004): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4070 suid=74 rport=60240 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665467.895:2005): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665467.895:2006): user pid=4069 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665467.896:2007): pid=4069 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=79 >type=USER_ROLE_CHANGE msg=audit(1362665468.024:2008): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665468.028:2009): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665468.034:2010): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665468.035:2011): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665468.036:2012): user pid=4072 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4072 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665468.036:2013): user pid=4072 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4072 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665468.037:2014): user pid=4072 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665468.080:2015): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665468.080:2016): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665468.081:2017): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665468.081:2018): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665468.081:2019): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4069 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665468.081:2020): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4069 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665468.081:2021): user pid=4069 uid=0 auid=0 ses=79 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4069 suid=0 rport=60240 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.130:2022): user pid=4081 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4081 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.130:2023): user pid=4081 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4081 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665471.130:2024): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4081 suid=74 rport=60241 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665471.131:2025): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4081 suid=74 rport=60241 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665471.193:2026): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60241 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665471.193:2027): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60241 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665471.200:2028): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.201:2029): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4081 suid=74 rport=60241 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665471.202:2030): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665471.202:2031): user pid=4080 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665471.202:2032): pid=4080 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=80 >type=USER_ROLE_CHANGE msg=audit(1362665471.332:2033): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665471.336:2034): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665471.341:2035): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665471.342:2036): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.343:2037): user pid=4083 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4083 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.343:2038): user pid=4083 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4083 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665471.344:2039): user pid=4083 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665471.393:2040): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665471.393:2041): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665471.394:2042): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665471.394:2043): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.394:2044): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4080 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.394:2045): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4080 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665471.394:2046): user pid=4080 uid=0 auid=0 ses=80 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4080 suid=0 rport=60241 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.439:2047): user pid=4090 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4090 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.440:2048): user pid=4090 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4090 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665474.440:2049): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4090 suid=74 rport=60242 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665474.440:2050): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4090 suid=74 rport=60242 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665474.507:2051): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60242 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665474.507:2052): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60242 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665474.515:2053): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.516:2054): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4090 suid=74 rport=60242 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665474.517:2055): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665474.517:2056): user pid=4089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665474.517:2057): pid=4089 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=81 >type=USER_ROLE_CHANGE msg=audit(1362665474.641:2058): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665474.646:2059): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665474.652:2060): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665474.653:2061): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.653:2062): user pid=4092 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.654:2063): user pid=4092 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665474.654:2064): user pid=4092 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665474.700:2065): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665474.700:2066): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665474.701:2067): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665474.701:2068): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.701:2069): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4089 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.701:2070): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4089 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665474.701:2071): user pid=4089 uid=0 auid=0 ses=81 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4089 suid=0 rport=60242 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665477.755:2072): user pid=4099 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4099 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665477.755:2073): user pid=4099 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4099 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665477.759:2074): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4099 suid=74 rport=60243 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665477.759:2075): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4099 suid=74 rport=60243 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665477.823:2076): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60243 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665477.823:2077): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60243 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665477.830:2078): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665477.831:2079): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4099 suid=74 rport=60243 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665477.832:2080): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665477.832:2081): user pid=4098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665477.832:2082): pid=4098 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=82 >type=USER_ROLE_CHANGE msg=audit(1362665477.960:2083): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665477.964:2084): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665477.965:2085): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665477.965:2086): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665477.966:2087): user pid=4101 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4101 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665477.966:2088): user pid=4101 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4101 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665477.967:2089): user pid=4101 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665478.018:2090): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665478.018:2091): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665478.019:2092): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665478.019:2093): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665478.019:2094): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4098 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665478.019:2095): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4098 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665478.019:2096): user pid=4098 uid=0 auid=0 ses=82 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4098 suid=0 rport=60243 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.067:2097): user pid=4108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4108 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.068:2098): user pid=4108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4108 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665481.068:2099): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4108 suid=74 rport=60244 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665481.068:2100): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4108 suid=74 rport=60244 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665481.131:2101): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60244 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665481.131:2102): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60244 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665481.140:2103): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.141:2104): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4108 suid=74 rport=60244 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665481.142:2105): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665481.142:2106): user pid=4107 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665481.142:2107): pid=4107 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=83 >type=USER_ROLE_CHANGE msg=audit(1362665481.265:2108): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665481.266:2109): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665481.268:2110): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665481.268:2111): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.269:2112): user pid=4110 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4110 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.269:2113): user pid=4110 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4110 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665481.270:2114): user pid=4110 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665481.319:2115): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665481.320:2116): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665481.320:2117): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665481.320:2118): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.320:2119): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4107 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.321:2120): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4107 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665481.321:2121): user pid=4107 uid=0 auid=0 ses=83 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4107 suid=0 rport=60244 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.363:2122): user pid=4117 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4117 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.363:2123): user pid=4117 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4117 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665484.364:2124): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4117 suid=74 rport=60245 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665484.364:2125): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4117 suid=74 rport=60245 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665484.427:2126): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60245 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665484.427:2127): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60245 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665484.435:2128): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.436:2129): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4117 suid=74 rport=60245 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665484.437:2130): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665484.437:2131): user pid=4116 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665484.437:2132): pid=4116 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=84 >type=USER_ROLE_CHANGE msg=audit(1362665484.564:2133): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665484.566:2134): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665484.566:2135): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665484.567:2136): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.568:2137): user pid=4119 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4119 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.568:2138): user pid=4119 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4119 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665484.568:2139): user pid=4119 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665484.615:2140): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665484.615:2141): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665484.615:2142): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665484.616:2143): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.616:2144): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4116 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.616:2145): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4116 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665484.616:2146): user pid=4116 uid=0 auid=0 ses=84 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4116 suid=0 rport=60245 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.660:2147): user pid=4126 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4126 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.660:2148): user pid=4126 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4126 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665487.661:2149): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4126 suid=74 rport=60246 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665487.661:2150): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4126 suid=74 rport=60246 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665487.724:2151): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60246 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665487.725:2152): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60246 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665487.732:2153): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.733:2154): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4126 suid=74 rport=60246 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665487.734:2155): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665487.734:2156): user pid=4125 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665487.735:2157): pid=4125 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=85 >type=USER_ROLE_CHANGE msg=audit(1362665487.859:2158): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665487.865:2159): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665487.870:2160): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665487.871:2161): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.872:2162): user pid=4128 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4128 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.872:2163): user pid=4128 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4128 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665487.872:2164): user pid=4128 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665487.913:2165): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665487.913:2166): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665487.913:2167): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665487.913:2168): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.913:2169): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4125 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.914:2170): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4125 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665487.914:2171): user pid=4125 uid=0 auid=0 ses=85 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4125 suid=0 rport=60246 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665488.331:2172): user pid=4133 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=163 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665488.415:2173): user pid=4133 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=163 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665488.415:2174): user pid=4133 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=163 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665488.549:2175): user pid=4138 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=163 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665490.976:2176): user pid=4149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4149 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665490.976:2177): user pid=4149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4149 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665490.977:2178): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4149 suid=74 rport=60247 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665490.977:2179): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4149 suid=74 rport=60247 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665491.042:2180): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60247 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665491.042:2181): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60247 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665491.050:2182): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665491.052:2183): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4149 suid=74 rport=60247 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665491.053:2184): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665491.053:2185): user pid=4148 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665491.053:2186): pid=4148 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=86 >type=USER_ROLE_CHANGE msg=audit(1362665491.181:2187): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665491.186:2188): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665491.191:2189): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665491.191:2190): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665491.193:2191): user pid=4151 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4151 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665491.193:2192): user pid=4151 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4151 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665491.194:2193): user pid=4151 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665491.238:2194): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665491.238:2195): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665491.239:2196): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665491.239:2197): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665491.239:2198): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4148 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665491.239:2199): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4148 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665491.239:2200): user pid=4148 uid=0 auid=0 ses=86 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4148 suid=0 rport=60247 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.287:2201): user pid=4167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4167 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.287:2202): user pid=4167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4167 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665494.288:2203): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4167 suid=74 rport=60248 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665494.288:2204): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4167 suid=74 rport=60248 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665494.354:2205): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60248 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665494.354:2206): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60248 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665494.364:2207): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.368:2208): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4167 suid=74 rport=60248 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665494.369:2209): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665494.369:2210): user pid=4166 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665494.369:2211): pid=4166 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=87 >type=USER_ROLE_CHANGE msg=audit(1362665494.502:2212): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665494.508:2213): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665494.509:2214): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665494.509:2215): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.510:2216): user pid=4170 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.510:2217): user pid=4170 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665494.511:2218): user pid=4170 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665494.550:2219): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665494.550:2220): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665494.551:2221): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665494.551:2222): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.551:2223): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4166 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.551:2224): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4166 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665494.552:2225): user pid=4166 uid=0 auid=0 ses=87 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4166 suid=0 rport=60248 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_START msg=audit(1362665495.879:2226): user pid=4191 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665495.880:2227): user pid=4191 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665495.884:2228): user pid=4191 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665495.884:2229): user pid=4191 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665496.141:2230): user pid=4217 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665496.141:2231): user pid=4217 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665496.146:2232): user pid=4217 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665496.146:2233): user pid=4217 uid=0 auid=0 ses=65 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="keystone" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.589:2234): user pid=4234 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4234 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.590:2235): user pid=4234 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4234 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665497.590:2236): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4234 suid=74 rport=60255 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665497.590:2237): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4234 suid=74 rport=60255 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665497.653:2238): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60255 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665497.653:2239): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60255 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665497.661:2240): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.664:2241): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4234 suid=74 rport=60255 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665497.664:2242): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665497.665:2243): user pid=4233 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665497.665:2244): pid=4233 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=88 >type=USER_ROLE_CHANGE msg=audit(1362665497.798:2245): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665497.800:2246): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665497.801:2247): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665497.801:2248): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.802:2249): user pid=4236 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4236 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.802:2250): user pid=4236 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4236 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665497.802:2251): user pid=4236 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665497.850:2252): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665497.851:2253): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665497.851:2254): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665497.851:2255): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.851:2256): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4233 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.851:2257): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4233 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665497.851:2258): user pid=4233 uid=0 auid=0 ses=88 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4233 suid=0 rport=60255 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665500.895:2259): user pid=4243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4243 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665500.895:2260): user pid=4243 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4243 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665500.898:2261): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4243 suid=74 rport=60256 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665500.898:2262): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4243 suid=74 rport=60256 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665500.961:2263): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60256 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665500.961:2264): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60256 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665500.969:2265): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665500.969:2266): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4243 suid=74 rport=60256 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665500.970:2267): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665500.970:2268): user pid=4242 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665500.970:2269): pid=4242 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=89 >type=USER_ROLE_CHANGE msg=audit(1362665501.096:2270): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665501.098:2271): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665501.100:2272): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665501.101:2273): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665501.101:2274): user pid=4245 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4245 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665501.102:2275): user pid=4245 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4245 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665501.102:2276): user pid=4245 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665501.154:2277): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665501.154:2278): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665501.155:2279): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665501.155:2280): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665501.155:2281): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4242 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665501.156:2282): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4242 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665501.156:2283): user pid=4242 uid=0 auid=0 ses=89 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4242 suid=0 rport=60256 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.197:2284): user pid=4252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4252 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.197:2285): user pid=4252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4252 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665504.198:2286): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4252 suid=74 rport=60257 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665504.199:2287): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4252 suid=74 rport=60257 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665504.261:2288): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60257 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665504.261:2289): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60257 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665504.269:2290): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.270:2291): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4252 suid=74 rport=60257 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665504.271:2292): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665504.271:2293): user pid=4251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665504.271:2294): pid=4251 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=90 >type=USER_ROLE_CHANGE msg=audit(1362665504.393:2295): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665504.396:2296): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665504.396:2297): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665504.397:2298): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.397:2299): user pid=4254 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4254 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.397:2300): user pid=4254 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4254 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665504.398:2301): user pid=4254 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665504.445:2302): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665504.445:2303): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665504.445:2304): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665504.445:2305): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.446:2306): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.446:2307): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665504.446:2308): user pid=4251 uid=0 auid=0 ses=90 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4251 suid=0 rport=60257 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.489:2309): user pid=4283 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4283 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.489:2310): user pid=4283 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4283 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665507.491:2311): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4283 suid=74 rport=60263 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665507.491:2312): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4283 suid=74 rport=60263 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665507.555:2313): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60263 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665507.555:2314): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60263 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665507.563:2315): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.564:2316): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4283 suid=74 rport=60263 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665507.565:2317): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665507.565:2318): user pid=4282 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665507.566:2319): pid=4282 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=91 >type=USER_ROLE_CHANGE msg=audit(1362665507.697:2320): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665507.700:2321): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665507.705:2322): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665507.706:2323): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.706:2324): user pid=4290 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4290 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.707:2325): user pid=4290 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4290 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665507.708:2326): user pid=4290 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665507.749:2327): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665507.749:2328): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665507.750:2329): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665507.750:2330): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.750:2331): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4282 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.750:2332): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4282 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665507.750:2333): user pid=4282 uid=0 auid=0 ses=91 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4282 suid=0 rport=60263 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665510.787:2334): user pid=4366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4366 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665510.787:2335): user pid=4366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4366 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665510.787:2336): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4366 suid=74 rport=60282 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665510.788:2337): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4366 suid=74 rport=60282 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665510.852:2338): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60282 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665510.852:2339): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60282 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665510.865:2340): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665510.866:2341): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4366 suid=74 rport=60282 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665510.867:2342): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665510.867:2343): user pid=4365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665510.867:2344): pid=4365 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=92 >type=USER_ROLE_CHANGE msg=audit(1362665510.994:2345): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665510.999:2346): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665511.006:2347): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665511.006:2348): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665511.007:2349): user pid=4372 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4372 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665511.008:2350): user pid=4372 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4372 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665511.009:2351): user pid=4372 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665511.050:2352): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665511.051:2353): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665511.051:2354): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665511.051:2355): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665511.051:2356): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4365 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665511.051:2357): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4365 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665511.052:2358): user pid=4365 uid=0 auid=0 ses=92 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4365 suid=0 rport=60282 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.102:2359): user pid=4426 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4426 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.102:2360): user pid=4426 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4426 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665514.103:2361): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4426 suid=74 rport=60294 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665514.103:2362): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4426 suid=74 rport=60294 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665514.171:2363): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60294 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665514.171:2364): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60294 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665514.181:2365): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.181:2366): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4426 suid=74 rport=60294 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665514.182:2367): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665514.183:2368): user pid=4425 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665514.183:2369): pid=4425 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=93 >type=USER_ROLE_CHANGE msg=audit(1362665514.313:2370): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665514.319:2371): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665514.321:2372): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665514.321:2373): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.322:2374): user pid=4432 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4432 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.322:2375): user pid=4432 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4432 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665514.323:2376): user pid=4432 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665514.368:2377): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665514.368:2378): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665514.368:2379): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665514.368:2380): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.369:2381): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4425 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.369:2382): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4425 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665514.369:2383): user pid=4425 uid=0 auid=0 ses=93 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4425 suid=0 rport=60294 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.405:2384): user pid=4500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4500 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.405:2385): user pid=4500 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4500 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665517.407:2386): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4500 suid=74 rport=60308 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665517.407:2387): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4500 suid=74 rport=60308 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665517.471:2388): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60308 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665517.471:2389): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60308 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665517.482:2390): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.485:2391): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4500 suid=74 rport=60308 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665517.486:2392): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665517.487:2393): user pid=4499 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665517.487:2394): pid=4499 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=94 >type=USER_ROLE_CHANGE msg=audit(1362665517.620:2395): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665517.626:2396): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665517.631:2397): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665517.631:2398): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.632:2399): user pid=4505 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4505 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.632:2400): user pid=4505 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4505 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665517.633:2401): user pid=4505 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665517.671:2402): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665517.671:2403): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665517.672:2404): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665517.672:2405): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.672:2406): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4499 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.672:2407): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4499 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665517.672:2408): user pid=4499 uid=0 auid=0 ses=94 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4499 suid=0 rport=60308 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.710:2409): user pid=4581 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4581 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.710:2410): user pid=4581 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4581 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665520.711:2411): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4581 suid=74 rport=60325 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665520.711:2412): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4581 suid=74 rport=60325 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665520.775:2413): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60325 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665520.775:2414): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60325 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665520.785:2415): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.786:2416): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4581 suid=74 rport=60325 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665520.786:2417): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665520.787:2418): user pid=4580 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665520.787:2419): pid=4580 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=95 >type=USER_ROLE_CHANGE msg=audit(1362665520.916:2420): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665520.921:2421): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665520.926:2422): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665520.927:2423): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.928:2424): user pid=4588 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4588 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.928:2425): user pid=4588 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4588 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665520.929:2426): user pid=4588 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665520.971:2427): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665520.971:2428): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665520.971:2429): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665520.972:2430): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.972:2431): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4580 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.972:2432): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4580 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665520.972:2433): user pid=4580 uid=0 auid=0 ses=95 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4580 suid=0 rport=60325 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.013:2434): user pid=4668 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4668 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.013:2435): user pid=4668 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4668 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665524.013:2436): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4668 suid=74 rport=60341 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665524.014:2437): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4668 suid=74 rport=60341 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665524.078:2438): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60341 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665524.078:2439): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60341 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665524.086:2440): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.087:2441): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4668 suid=74 rport=60341 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665524.087:2442): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665524.088:2443): user pid=4664 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665524.088:2444): pid=4664 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=96 >type=USER_ROLE_CHANGE msg=audit(1362665524.219:2445): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665524.224:2446): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665524.231:2447): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665524.231:2448): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.232:2449): user pid=4672 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4672 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.232:2450): user pid=4672 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4672 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665524.233:2451): user pid=4672 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665524.281:2452): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665524.281:2453): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665524.282:2454): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665524.282:2455): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.282:2456): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4664 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.282:2457): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4664 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665524.282:2458): user pid=4664 uid=0 auid=0 ses=96 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4664 suid=0 rport=60341 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665524.732:2459): table=filter family=2 entries=12 >type=SYSCALL msg=audit(1362665524.732:2459): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=e427d0 items=0 ppid=3694 pid=4688 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=65 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362665527.322:2460): user pid=4939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4939 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.322:2461): user pid=4939 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4939 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665527.323:2462): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4939 suid=74 rport=60345 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665527.323:2463): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4939 suid=74 rport=60345 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665527.390:2464): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60345 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665527.391:2465): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60345 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665527.400:2466): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.400:2467): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4939 suid=74 rport=60345 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665527.401:2468): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665527.401:2469): user pid=4938 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665527.402:2470): pid=4938 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=97 >type=USER_ROLE_CHANGE msg=audit(1362665527.535:2471): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665527.540:2472): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665527.546:2473): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665527.546:2474): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.547:2475): user pid=4941 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4941 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.547:2476): user pid=4941 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4941 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665527.548:2477): user pid=4941 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665527.578:2478): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665527.579:2479): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665527.579:2480): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665527.579:2481): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.579:2482): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4938 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.579:2483): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4938 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665527.579:2484): user pid=4938 uid=0 auid=0 ses=97 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4938 suid=0 rport=60345 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.625:2485): user pid=4955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.625:2486): user pid=4955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665530.628:2487): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4955 suid=74 rport=60348 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665530.628:2488): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4955 suid=74 rport=60348 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665530.690:2489): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60348 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665530.690:2490): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60348 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665530.698:2491): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.699:2492): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4955 suid=74 rport=60348 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665530.700:2493): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665530.701:2494): user pid=4954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665530.701:2495): pid=4954 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=98 >type=USER_ROLE_CHANGE msg=audit(1362665530.828:2496): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665530.832:2497): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665530.839:2498): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665530.839:2499): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.840:2500): user pid=4957 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.840:2501): user pid=4957 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665530.841:2502): user pid=4957 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665530.885:2503): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665530.885:2504): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665530.885:2505): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665530.885:2506): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.886:2507): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4954 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.886:2508): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4954 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.886:2509): user pid=4954 uid=0 auid=0 ses=98 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4954 suid=0 rport=60348 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.918:2510): user pid=4964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.918:2511): user pid=4964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665530.918:2512): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4964 suid=74 rport=60349 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665530.919:2513): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4964 suid=74 rport=60349 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665530.980:2514): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60349 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665530.980:2515): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60349 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665530.988:2516): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665530.989:2517): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4964 suid=74 rport=60349 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665530.990:2518): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665530.990:2519): user pid=4963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665530.991:2520): pid=4963 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=99 >type=USER_ROLE_CHANGE msg=audit(1362665531.116:2521): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665531.118:2522): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665531.122:2523): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665531.123:2524): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665531.124:2525): user pid=4966 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665531.124:2526): user pid=4966 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665531.125:2527): user pid=4966 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665531.174:2528): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665531.174:2529): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665531.175:2530): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665531.175:2531): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665531.175:2532): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4963 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665531.175:2533): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4963 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665531.175:2534): user pid=4963 uid=0 auid=0 ses=99 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4963 suid=0 rport=60349 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.214:2535): user pid=4973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4973 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.214:2536): user pid=4973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4973 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665534.215:2537): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4973 suid=74 rport=60351 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665534.215:2538): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4973 suid=74 rport=60351 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665534.278:2539): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60351 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665534.278:2540): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60351 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665534.285:2541): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.285:2542): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4973 suid=74 rport=60351 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665534.286:2543): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665534.287:2544): user pid=4972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665534.287:2545): pid=4972 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=100 >type=USER_ROLE_CHANGE msg=audit(1362665534.407:2546): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665534.411:2547): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665534.416:2548): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665534.416:2549): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.417:2550): user pid=4975 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4975 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.417:2551): user pid=4975 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4975 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665534.418:2552): user pid=4975 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665534.463:2553): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665534.463:2554): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665534.465:2555): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665534.466:2556): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.466:2557): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4972 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.466:2558): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4972 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665534.466:2559): user pid=4972 uid=0 auid=0 ses=100 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4972 suid=0 rport=60351 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.508:2560): user pid=4982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.508:2561): user pid=4982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665537.509:2562): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4982 suid=74 rport=60356 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665537.509:2563): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4982 suid=74 rport=60356 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665537.572:2564): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60356 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665537.572:2565): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60356 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665537.580:2566): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.581:2567): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4982 suid=74 rport=60356 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665537.582:2568): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665537.582:2569): user pid=4981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665537.582:2570): pid=4981 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=101 >type=USER_ROLE_CHANGE msg=audit(1362665537.701:2571): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665537.707:2572): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665537.712:2573): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665537.712:2574): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.713:2575): user pid=4984 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4984 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.714:2576): user pid=4984 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4984 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665537.715:2577): user pid=4984 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665537.761:2578): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665537.761:2579): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665537.762:2580): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665537.762:2581): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.762:2582): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.762:2583): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665537.762:2584): user pid=4981 uid=0 auid=0 ses=101 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4981 suid=0 rport=60356 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665540.801:2585): user pid=4991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665540.801:2586): user pid=4991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665540.802:2587): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=4991 suid=74 rport=60363 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665540.802:2588): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=4991 suid=74 rport=60363 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665540.871:2589): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60363 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665540.871:2590): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60363 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665540.878:2591): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665540.878:2592): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4991 suid=74 rport=60363 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665540.879:2593): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665540.879:2594): user pid=4990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665540.879:2595): pid=4990 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=102 >type=USER_ROLE_CHANGE msg=audit(1362665541.004:2596): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665541.010:2597): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665541.015:2598): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665541.016:2599): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665541.017:2600): user pid=4993 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4993 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665541.017:2601): user pid=4993 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4993 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665541.018:2602): user pid=4993 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665541.064:2603): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665541.064:2604): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665541.064:2605): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665541.064:2606): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665541.065:2607): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4990 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665541.065:2608): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4990 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665541.065:2609): user pid=4990 uid=0 auid=0 ses=102 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4990 suid=0 rport=60363 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.104:2610): user pid=5000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.105:2611): user pid=5000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665544.105:2612): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5000 suid=74 rport=60365 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665544.105:2613): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5000 suid=74 rport=60365 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665544.167:2614): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60365 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665544.167:2615): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60365 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665544.174:2616): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.175:2617): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5000 suid=74 rport=60365 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665544.176:2618): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665544.177:2619): user pid=4999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665544.177:2620): pid=4999 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=103 >type=USER_ROLE_CHANGE msg=audit(1362665544.298:2621): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665544.303:2622): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665544.307:2623): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665544.308:2624): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.309:2625): user pid=5002 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5002 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.309:2626): user pid=5002 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5002 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665544.310:2627): user pid=5002 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665544.355:2628): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665544.355:2629): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665544.356:2630): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665544.356:2631): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.356:2632): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=4999 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.356:2633): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=4999 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665544.356:2634): user pid=4999 uid=0 auid=0 ses=103 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=4999 suid=0 rport=60365 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.392:2635): user pid=5009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.392:2636): user pid=5009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665547.393:2637): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5009 suid=74 rport=60367 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665547.393:2638): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5009 suid=74 rport=60367 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665547.455:2639): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60367 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665547.455:2640): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60367 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665547.463:2641): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.463:2642): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5009 suid=74 rport=60367 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665547.464:2643): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665547.464:2644): user pid=5008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665547.465:2645): pid=5008 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=104 >type=USER_ROLE_CHANGE msg=audit(1362665547.592:2646): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665547.596:2647): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665547.602:2648): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665547.602:2649): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.603:2650): user pid=5011 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5011 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.603:2651): user pid=5011 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5011 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665547.603:2652): user pid=5011 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665547.649:2653): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665547.649:2654): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665547.650:2655): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665547.650:2656): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.650:2657): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5008 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.650:2658): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5008 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665547.650:2659): user pid=5008 uid=0 auid=0 ses=104 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5008 suid=0 rport=60367 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.689:2660): user pid=5018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.689:2661): user pid=5018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665550.690:2662): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5018 suid=74 rport=60369 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665550.690:2663): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5018 suid=74 rport=60369 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665550.752:2664): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60369 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665550.752:2665): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60369 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665550.759:2666): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.759:2667): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5018 suid=74 rport=60369 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665550.760:2668): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665550.760:2669): user pid=5017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665550.761:2670): pid=5017 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=105 >type=USER_ROLE_CHANGE msg=audit(1362665550.893:2671): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665550.898:2672): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665550.903:2673): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665550.904:2674): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.904:2675): user pid=5020 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5020 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.904:2676): user pid=5020 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5020 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665550.905:2677): user pid=5020 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665550.949:2678): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665550.949:2679): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665550.950:2680): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665550.950:2681): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.950:2682): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5017 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.950:2683): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5017 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665550.950:2684): user pid=5017 uid=0 auid=0 ses=105 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5017 suid=0 rport=60369 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665553.989:2685): user pid=5027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665553.989:2686): user pid=5027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665553.990:2687): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5027 suid=74 rport=60371 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665553.990:2688): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5027 suid=74 rport=60371 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665554.053:2689): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60371 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665554.053:2690): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60371 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665554.060:2691): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665554.060:2692): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5027 suid=74 rport=60371 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665554.061:2693): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665554.061:2694): user pid=5026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665554.062:2695): pid=5026 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=106 >type=USER_ROLE_CHANGE msg=audit(1362665554.193:2696): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665554.198:2697): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665554.203:2698): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665554.204:2699): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665554.205:2700): user pid=5029 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5029 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665554.205:2701): user pid=5029 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5029 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665554.205:2702): user pid=5029 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665554.249:2703): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665554.249:2704): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665554.249:2705): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665554.250:2706): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665554.250:2707): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5026 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665554.250:2708): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5026 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665554.250:2709): user pid=5026 uid=0 auid=0 ses=106 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5026 suid=0 rport=60371 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.287:2710): user pid=5036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.287:2711): user pid=5036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665557.288:2712): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5036 suid=74 rport=60376 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665557.288:2713): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5036 suid=74 rport=60376 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665557.355:2714): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60376 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665557.355:2715): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60376 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665557.362:2716): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.363:2717): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5036 suid=74 rport=60376 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665557.364:2718): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665557.364:2719): user pid=5035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665557.364:2720): pid=5035 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=107 >type=USER_ROLE_CHANGE msg=audit(1362665557.485:2721): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665557.490:2722): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665557.495:2723): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665557.495:2724): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.496:2725): user pid=5038 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5038 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.496:2726): user pid=5038 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5038 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665557.497:2727): user pid=5038 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665557.538:2728): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665557.538:2729): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665557.539:2730): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665557.539:2731): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.539:2732): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5035 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.539:2733): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5035 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665557.539:2734): user pid=5035 uid=0 auid=0 ses=107 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5035 suid=0 rport=60376 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.583:2735): user pid=5045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5045 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.583:2736): user pid=5045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5045 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665560.584:2737): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5045 suid=74 rport=60378 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665560.584:2738): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5045 suid=74 rport=60378 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665560.647:2739): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60378 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665560.647:2740): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60378 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665560.655:2741): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.656:2742): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5045 suid=74 rport=60378 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665560.656:2743): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665560.657:2744): user pid=5044 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665560.657:2745): pid=5044 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=108 >type=USER_ROLE_CHANGE msg=audit(1362665560.784:2746): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665560.788:2747): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665560.794:2748): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665560.794:2749): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.796:2750): user pid=5047 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5047 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.796:2751): user pid=5047 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5047 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665560.797:2752): user pid=5047 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665560.840:2753): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665560.840:2754): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665560.841:2755): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665560.841:2756): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.841:2757): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5044 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.841:2758): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5044 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665560.841:2759): user pid=5044 uid=0 auid=0 ses=108 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5044 suid=0 rport=60378 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665563.883:2760): user pid=5054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5054 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665563.883:2761): user pid=5054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5054 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665563.884:2762): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5054 suid=74 rport=60380 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665563.884:2763): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5054 suid=74 rport=60380 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665563.949:2764): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60380 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665563.949:2765): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60380 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665563.961:2766): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665563.962:2767): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5054 suid=74 rport=60380 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665563.963:2768): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665563.963:2769): user pid=5053 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665563.963:2770): pid=5053 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=109 >type=USER_ROLE_CHANGE msg=audit(1362665564.095:2771): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665564.100:2772): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665564.105:2773): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665564.105:2774): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665564.106:2775): user pid=5056 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5056 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665564.107:2776): user pid=5056 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5056 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665564.108:2777): user pid=5056 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665564.152:2778): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665564.152:2779): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665564.153:2780): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665564.153:2781): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665564.153:2782): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5053 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665564.153:2783): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5053 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665564.153:2784): user pid=5053 uid=0 auid=0 ses=109 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5053 suid=0 rport=60380 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.206:2785): user pid=5065 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5065 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.206:2786): user pid=5065 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5065 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665567.209:2787): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5065 suid=74 rport=60381 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665567.209:2788): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5065 suid=74 rport=60381 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665567.273:2789): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60381 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665567.273:2790): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60381 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665567.281:2791): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.281:2792): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5065 suid=74 rport=60381 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665567.282:2793): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665567.283:2794): user pid=5064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665567.283:2795): pid=5064 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=110 >type=USER_ROLE_CHANGE msg=audit(1362665567.406:2796): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665567.410:2797): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665567.411:2798): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665567.411:2799): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.412:2800): user pid=5067 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5067 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.412:2801): user pid=5067 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5067 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665567.413:2802): user pid=5067 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665567.461:2803): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665567.461:2804): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665567.464:2805): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665567.464:2806): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.464:2807): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5064 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.465:2808): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5064 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665567.465:2809): user pid=5064 uid=0 auid=0 ses=110 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5064 suid=0 rport=60381 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.505:2810): user pid=5075 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5075 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.505:2811): user pid=5075 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5075 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665570.506:2812): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5075 suid=74 rport=60382 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665570.506:2813): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5075 suid=74 rport=60382 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665570.569:2814): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60382 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665570.569:2815): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60382 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665570.577:2816): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.578:2817): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5075 suid=74 rport=60382 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665570.579:2818): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665570.580:2819): user pid=5074 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665570.580:2820): pid=5074 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=111 >type=USER_ROLE_CHANGE msg=audit(1362665570.710:2821): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665570.715:2822): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665570.721:2823): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665570.722:2824): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.723:2825): user pid=5077 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5077 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.723:2826): user pid=5077 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5077 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665570.724:2827): user pid=5077 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665570.766:2828): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665570.767:2829): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665570.767:2830): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665570.767:2831): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.767:2832): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5074 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.767:2833): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5074 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665570.768:2834): user pid=5074 uid=0 auid=0 ses=111 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5074 suid=0 rport=60382 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665573.823:2835): user pid=5084 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5084 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665573.823:2836): user pid=5084 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5084 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665573.823:2837): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5084 suid=74 rport=60383 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665573.823:2838): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5084 suid=74 rport=60383 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665573.886:2839): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60383 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665573.886:2840): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60383 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665573.897:2841): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665573.898:2842): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5084 suid=74 rport=60383 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665573.899:2843): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665573.899:2844): user pid=5083 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665573.899:2845): pid=5083 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=112 >type=USER_ROLE_CHANGE msg=audit(1362665574.022:2846): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665574.029:2847): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665574.036:2848): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665574.036:2849): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665574.038:2850): user pid=5086 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5086 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665574.038:2851): user pid=5086 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5086 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665574.038:2852): user pid=5086 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665574.087:2853): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665574.087:2854): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665574.088:2855): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665574.088:2856): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665574.088:2857): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5083 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665574.088:2858): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5083 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665574.088:2859): user pid=5083 uid=0 auid=0 ses=112 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5083 suid=0 rport=60383 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.149:2860): user pid=5093 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5093 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.150:2861): user pid=5093 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5093 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665577.150:2862): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5093 suid=74 rport=60384 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665577.150:2863): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5093 suid=74 rport=60384 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665577.218:2864): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60384 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665577.218:2865): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60384 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665577.227:2866): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.228:2867): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5093 suid=74 rport=60384 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665577.229:2868): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665577.229:2869): user pid=5092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665577.229:2870): pid=5092 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=113 >type=USER_ROLE_CHANGE msg=audit(1362665577.356:2871): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665577.361:2872): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665577.368:2873): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665577.368:2874): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.369:2875): user pid=5095 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5095 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.369:2876): user pid=5095 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5095 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665577.370:2877): user pid=5095 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665577.418:2878): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665577.418:2879): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665577.419:2880): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665577.419:2881): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.419:2882): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.419:2883): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665577.419:2884): user pid=5092 uid=0 auid=0 ses=113 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5092 suid=0 rport=60384 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.469:2885): user pid=5103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5103 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.469:2886): user pid=5103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5103 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665580.470:2887): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5103 suid=74 rport=60385 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665580.470:2888): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5103 suid=74 rport=60385 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665580.540:2889): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60385 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665580.540:2890): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60385 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665580.549:2891): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.550:2892): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5103 suid=74 rport=60385 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665580.551:2893): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665580.551:2894): user pid=5102 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665580.551:2895): pid=5102 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=114 >type=USER_ROLE_CHANGE msg=audit(1362665580.683:2896): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665580.688:2897): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665580.693:2898): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665580.694:2899): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.695:2900): user pid=5105 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5105 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.695:2901): user pid=5105 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5105 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665580.696:2902): user pid=5105 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665580.743:2903): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665580.743:2904): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665580.743:2905): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665580.743:2906): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.744:2907): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5102 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.744:2908): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5102 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665580.744:2909): user pid=5102 uid=0 auid=0 ses=114 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5102 suid=0 rport=60385 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665583.793:2910): user pid=5112 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5112 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665583.793:2911): user pid=5112 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5112 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665583.794:2912): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5112 suid=74 rport=60386 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665583.794:2913): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5112 suid=74 rport=60386 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665583.859:2914): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60386 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665583.859:2915): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60386 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665583.868:2916): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665583.869:2917): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5112 suid=74 rport=60386 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665583.870:2918): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665583.870:2919): user pid=5111 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665583.870:2920): pid=5111 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=115 >type=USER_ROLE_CHANGE msg=audit(1362665584.005:2921): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665584.009:2922): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665584.015:2923): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665584.015:2924): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665584.016:2925): user pid=5114 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5114 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665584.016:2926): user pid=5114 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5114 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665584.017:2927): user pid=5114 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665584.067:2928): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665584.068:2929): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665584.068:2930): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665584.068:2931): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665584.068:2932): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5111 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665584.068:2933): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5111 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665584.068:2934): user pid=5111 uid=0 auid=0 ses=115 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5111 suid=0 rport=60386 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665586.549:2935): user pid=5119 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5119 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665586.549:2936): user pid=5119 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5119 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665586.549:2937): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5119 suid=74 rport=56207 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665586.549:2938): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5119 suid=74 rport=56207 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665586.629:2939): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56207 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665586.629:2940): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56207 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362665586.635:2941): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665586.636:2942): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5119 suid=74 rport=56207 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362665586.637:2943): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665586.637:2944): user pid=5118 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362665586.637:2945): pid=5118 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=116 >type=USER_ROLE_CHANGE msg=audit(1362665586.766:2946): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362665586.771:2947): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665586.849:2948): user pid=5125 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=/dev/pts/0 res=success' >type=USER_START msg=audit(1362665586.849:2949): user pid=5125 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=/dev/pts/0 res=success' >type=CRYPTO_KEY_USER msg=audit(1362665586.849:2950): user pid=5125 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5125 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=pts/0 res=success' >type=CRYPTO_KEY_USER msg=audit(1362665586.850:2951): user pid=5125 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5125 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=pts/0 res=success' >type=CRED_REFR msg=audit(1362665586.850:2952): user pid=5125 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=ADD_GROUP msg=audit(1362665586.974:2953): user pid=5124 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=165 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665587.076:2954): user pid=5124 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=165 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665587.077:2955): user pid=5124 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=165 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.114:2956): user pid=5147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5147 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.114:2957): user pid=5147 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5147 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665587.116:2958): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5147 suid=74 rport=60387 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665587.116:2959): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5147 suid=74 rport=60387 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_USER msg=audit(1362665587.169:2960): user pid=5144 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=165 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665587.170:2961): user pid=5144 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="cinder" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665587.170:2962): user pid=5144 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="cinder" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665587.170:2963): user pid=5144 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="cinder" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665587.170:2964): user pid=5144 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="cinder" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=USER_AUTH msg=audit(1362665587.179:2965): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60387 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665587.179:2966): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60387 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665587.185:2967): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.186:2968): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5147 suid=74 rport=60387 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665587.187:2969): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665587.187:2970): user pid=5146 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665587.187:2971): pid=5146 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=117 >type=USER_ROLE_CHANGE msg=audit(1362665587.316:2972): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665587.320:2973): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665587.326:2974): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665587.326:2975): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.328:2976): user pid=5149 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5149 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.328:2977): user pid=5149 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5149 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665587.329:2978): user pid=5149 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665587.372:2979): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665587.372:2980): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665587.373:2981): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665587.373:2982): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.373:2983): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5146 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.373:2984): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5146 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665587.373:2985): user pid=5146 uid=0 auid=0 ses=117 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5146 suid=0 rport=60387 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.429:2986): user pid=5165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5165 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.429:2987): user pid=5165 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5165 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665590.430:2988): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5165 suid=74 rport=60388 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665590.430:2989): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5165 suid=74 rport=60388 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665590.494:2990): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60388 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665590.494:2991): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60388 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665590.501:2992): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.502:2993): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5165 suid=74 rport=60388 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665590.503:2994): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665590.503:2995): user pid=5164 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665590.503:2996): pid=5164 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=118 >type=USER_ROLE_CHANGE msg=audit(1362665590.632:2997): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665590.637:2998): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665590.642:2999): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665590.643:3000): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.644:3001): user pid=5167 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5167 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.644:3002): user pid=5167 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5167 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665590.645:3003): user pid=5167 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665590.692:3004): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665590.692:3005): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665590.692:3006): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665590.692:3007): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.693:3008): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5164 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.693:3009): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5164 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665590.693:3010): user pid=5164 uid=0 auid=0 ses=118 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5164 suid=0 rport=60388 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665593.739:3011): user pid=5186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5186 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665593.739:3012): user pid=5186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5186 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665593.740:3013): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5186 suid=74 rport=60390 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665593.741:3014): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5186 suid=74 rport=60390 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665593.804:3015): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60390 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665593.804:3016): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60390 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665593.812:3017): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665593.812:3018): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5186 suid=74 rport=60390 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665593.813:3019): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665593.814:3020): user pid=5185 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665593.814:3021): pid=5185 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=119 >type=USER_ROLE_CHANGE msg=audit(1362665593.952:3022): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665593.957:3023): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665593.959:3024): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665593.959:3025): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665593.960:3026): user pid=5188 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5188 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665593.960:3027): user pid=5188 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5188 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665593.961:3028): user pid=5188 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665594.004:3029): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665594.004:3030): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665594.004:3031): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665594.004:3032): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665594.004:3033): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5185 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665594.005:3034): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5185 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665594.005:3035): user pid=5185 uid=0 auid=0 ses=119 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5185 suid=0 rport=60390 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.046:3036): user pid=5195 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5195 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.046:3037): user pid=5195 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5195 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665597.046:3038): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5195 suid=74 rport=60391 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665597.046:3039): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5195 suid=74 rport=60391 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665597.111:3040): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60391 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665597.111:3041): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60391 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665597.118:3042): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.119:3043): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5195 suid=74 rport=60391 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665597.119:3044): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665597.120:3045): user pid=5194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665597.120:3046): pid=5194 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=120 >type=USER_ROLE_CHANGE msg=audit(1362665597.246:3047): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665597.251:3048): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665597.251:3049): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665597.252:3050): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.252:3051): user pid=5197 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5197 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.252:3052): user pid=5197 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5197 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665597.253:3053): user pid=5197 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665597.304:3054): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665597.304:3055): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665597.305:3056): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665597.305:3057): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.305:3058): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5194 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.305:3059): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5194 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665597.305:3060): user pid=5194 uid=0 auid=0 ses=120 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5194 suid=0 rport=60391 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_START msg=audit(1362665598.937:3061): user pid=5211 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665598.937:3062): user pid=5211 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665598.941:3063): user pid=5211 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665598.941:3064): user pid=5211 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665599.144:3065): user pid=5230 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665599.145:3066): user pid=5230 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665599.148:3067): user pid=5230 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665599.148:3068): user pid=5230 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665599.544:3069): user pid=5268 uid=165 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='cwd="/" cmd=63696E6465722D726F6F7477726170202F6574632F63696E6465722F726F6F74777261702E636F6E6620766773202D2D6E6F68656164696E6773202D6F206E616D65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665599.544:3070): user pid=5268 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665599.544:3071): user pid=5268 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665599.998:3072): user pid=5268 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665599.998:3073): user pid=5268 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.371:3074): user pid=5302 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5302 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.371:3075): user pid=5302 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5302 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665600.374:3076): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5302 suid=74 rport=60395 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665600.374:3077): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5302 suid=74 rport=60395 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665600.441:3078): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60395 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665600.441:3079): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60395 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665600.448:3080): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.449:3081): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5302 suid=74 rport=60395 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665600.450:3082): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665600.450:3083): user pid=5301 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665600.450:3084): pid=5301 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=121 >type=USER_ROLE_CHANGE msg=audit(1362665600.587:3085): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665600.591:3086): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665600.597:3087): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665600.597:3088): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.598:3089): user pid=5316 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5316 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.598:3090): user pid=5316 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5316 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665600.599:3091): user pid=5316 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665600.628:3092): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665600.628:3093): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665600.629:3094): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665600.629:3095): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.629:3096): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5301 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.629:3097): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5301 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665600.629:3098): user pid=5301 uid=0 auid=0 ses=121 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5301 suid=0 rport=60395 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_START msg=audit(1362665600.954:3099): user pid=5343 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665600.954:3100): user pid=5343 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665600.958:3101): user pid=5343 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665600.959:3102): user pid=5343 uid=0 auid=0 ses=67 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="cinder" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665601.126:3103): table=filter family=2 entries=13 >type=SYSCALL msg=audit(1362665601.126:3103): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=acdc20 items=0 ppid=4690 pid=5355 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=67 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362665603.680:3104): user pid=5610 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5610 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.680:3105): user pid=5610 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5610 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665603.683:3106): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5610 suid=74 rport=60397 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665603.683:3107): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5610 suid=74 rport=60397 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665603.748:3108): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60397 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665603.748:3109): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60397 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665603.757:3110): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.758:3111): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5610 suid=74 rport=60397 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665603.759:3112): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665603.759:3113): user pid=5609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665603.759:3114): pid=5609 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=122 >type=USER_ROLE_CHANGE msg=audit(1362665603.900:3115): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665603.903:3116): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665603.908:3117): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665603.908:3118): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.910:3119): user pid=5612 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5612 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.910:3120): user pid=5612 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5612 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665603.911:3121): user pid=5612 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665603.956:3122): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665603.957:3123): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665603.957:3124): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665603.957:3125): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.957:3126): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5609 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.957:3127): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5609 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.957:3128): user pid=5609 uid=0 auid=0 ses=122 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5609 suid=0 rport=60397 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.989:3129): user pid=5619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5619 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665603.990:3130): user pid=5619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5619 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665603.990:3131): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5619 suid=74 rport=60398 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665603.991:3132): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5619 suid=74 rport=60398 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665604.054:3133): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60398 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665604.054:3134): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60398 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665604.061:3135): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665604.063:3136): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5619 suid=74 rport=60398 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665604.064:3137): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665604.064:3138): user pid=5618 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665604.064:3139): pid=5618 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=123 >type=USER_ROLE_CHANGE msg=audit(1362665604.203:3140): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665604.207:3141): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665604.212:3142): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665604.213:3143): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665604.214:3144): user pid=5621 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5621 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665604.214:3145): user pid=5621 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5621 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665604.215:3146): user pid=5621 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665604.243:3147): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665604.243:3148): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665604.243:3149): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665604.243:3150): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665604.243:3151): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5618 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665604.244:3152): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5618 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665604.244:3153): user pid=5618 uid=0 auid=0 ses=123 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5618 suid=0 rport=60398 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665604.888:3154): table=filter family=2 entries=14 >type=SYSCALL msg=audit(1362665604.888:3154): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=dd6080 items=0 ppid=5361 pid=5633 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=66 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362665607.322:3155): user pid=5641 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5641 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.322:3156): user pid=5641 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5641 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665607.322:3157): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5641 suid=74 rport=60404 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665607.322:3158): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5641 suid=74 rport=60404 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665607.387:3159): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60404 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665607.387:3160): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60404 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665607.395:3161): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.396:3162): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5641 suid=74 rport=60404 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665607.397:3163): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665607.397:3164): user pid=5640 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665607.398:3165): pid=5640 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=124 >type=USER_ROLE_CHANGE msg=audit(1362665607.526:3166): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665607.530:3167): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665607.536:3168): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665607.536:3169): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.538:3170): user pid=5643 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5643 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.538:3171): user pid=5643 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5643 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665607.539:3172): user pid=5643 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665607.592:3173): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665607.592:3174): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665607.593:3175): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665607.593:3176): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.593:3177): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5640 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.593:3178): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5640 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665607.593:3179): user pid=5640 uid=0 auid=0 ses=124 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5640 suid=0 rport=60404 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.638:3180): user pid=5650 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5650 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.638:3181): user pid=5650 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5650 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665610.639:3182): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5650 suid=74 rport=60405 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665610.640:3183): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5650 suid=74 rport=60405 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665610.708:3184): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60405 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665610.708:3185): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60405 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665610.717:3186): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.719:3187): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5650 suid=74 rport=60405 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665610.720:3188): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665610.720:3189): user pid=5649 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665610.720:3190): pid=5649 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=125 >type=USER_ROLE_CHANGE msg=audit(1362665610.849:3191): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665610.854:3192): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665610.859:3193): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665610.859:3194): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.860:3195): user pid=5652 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5652 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.860:3196): user pid=5652 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5652 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665610.861:3197): user pid=5652 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665610.911:3198): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665610.911:3199): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665610.912:3200): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665610.912:3201): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.912:3202): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5649 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.912:3203): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5649 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665610.912:3204): user pid=5649 uid=0 auid=0 ses=125 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5649 suid=0 rport=60405 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665611.607:3205): user pid=5657 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=161 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665611.703:3206): user pid=5657 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=161 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665611.704:3207): user pid=5657 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=161 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665611.930:3208): user pid=5662 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=161 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665613.978:3209): user pid=5675 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5675 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665613.978:3210): user pid=5675 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5675 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665613.978:3211): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5675 suid=74 rport=60406 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665613.978:3212): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5675 suid=74 rport=60406 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665614.041:3213): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60406 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665614.041:3214): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60406 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665614.049:3215): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665614.049:3216): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5675 suid=74 rport=60406 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665614.050:3217): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665614.051:3218): user pid=5674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665614.051:3219): pid=5674 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=126 >type=USER_ROLE_CHANGE msg=audit(1362665614.178:3220): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665614.183:3221): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665614.188:3222): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665614.188:3223): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665614.189:3224): user pid=5677 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5677 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665614.189:3225): user pid=5677 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5677 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665614.190:3226): user pid=5677 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665614.239:3227): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665614.239:3228): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665614.239:3229): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665614.240:3230): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665614.240:3231): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5674 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665614.240:3232): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5674 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665614.240:3233): user pid=5674 uid=0 auid=0 ses=126 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5674 suid=0 rport=60406 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.280:3234): user pid=5695 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5695 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.280:3235): user pid=5695 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5695 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665617.284:3236): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5695 suid=74 rport=60410 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665617.285:3237): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5695 suid=74 rport=60410 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665617.347:3238): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60410 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665617.347:3239): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60410 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665617.357:3240): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.358:3241): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5695 suid=74 rport=60410 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665617.359:3242): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665617.359:3243): user pid=5694 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665617.359:3244): pid=5694 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=127 >type=USER_ROLE_CHANGE msg=audit(1362665617.482:3245): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665617.485:3246): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665617.485:3247): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665617.485:3248): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.487:3249): user pid=5697 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5697 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.487:3250): user pid=5697 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5697 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665617.488:3251): user pid=5697 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665617.537:3252): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665617.537:3253): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665617.538:3254): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665617.538:3255): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.538:3256): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5694 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.538:3257): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5694 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665617.538:3258): user pid=5694 uid=0 auid=0 ses=127 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5694 suid=0 rport=60410 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.581:3259): user pid=5705 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5705 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.582:3260): user pid=5705 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5705 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665620.583:3261): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5705 suid=74 rport=60412 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665620.584:3262): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5705 suid=74 rport=60412 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665620.645:3263): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60412 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665620.645:3264): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60412 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665620.654:3265): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.655:3266): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5705 suid=74 rport=60412 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665620.656:3267): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665620.657:3268): user pid=5704 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665620.657:3269): pid=5704 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=128 >type=USER_ROLE_CHANGE msg=audit(1362665620.781:3270): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665620.785:3271): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665620.790:3272): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665620.791:3273): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.792:3274): user pid=5707 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5707 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.792:3275): user pid=5707 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5707 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665620.793:3276): user pid=5707 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665620.840:3277): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665620.840:3278): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665620.840:3279): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665620.841:3280): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.841:3281): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5704 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.841:3282): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5704 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665620.841:3283): user pid=5704 uid=0 auid=0 ses=128 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5704 suid=0 rport=60412 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665623.893:3284): user pid=5719 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5719 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665623.893:3285): user pid=5719 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5719 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665623.895:3286): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5719 suid=74 rport=60413 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665623.895:3287): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5719 suid=74 rport=60413 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665623.957:3288): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60413 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665623.957:3289): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60413 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665623.965:3290): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665623.966:3291): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5719 suid=74 rport=60413 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665623.967:3292): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665623.968:3293): user pid=5714 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665623.968:3294): pid=5714 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=129 >type=USER_START msg=audit(1362665624.045:3295): user pid=5734 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665624.045:3296): user pid=5734 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665624.053:3297): user pid=5734 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665624.053:3298): user pid=5734 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_ROLE_CHANGE msg=audit(1362665624.088:3299): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665624.093:3300): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665624.098:3301): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665624.098:3302): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665624.100:3303): user pid=5739 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5739 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665624.100:3304): user pid=5739 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5739 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665624.100:3305): user pid=5739 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665624.139:3306): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665624.139:3307): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665624.139:3308): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665624.140:3309): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665624.140:3310): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5714 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665624.140:3311): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5714 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665624.140:3312): user pid=5714 uid=0 auid=0 ses=129 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5714 suid=0 rport=60413 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_START msg=audit(1362665624.383:3313): user pid=5763 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665624.383:3314): user pid=5763 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665624.387:3315): user pid=5763 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665624.388:3316): user pid=5763 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665624.504:3317): user pid=5785 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665624.504:3318): user pid=5785 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665624.507:3319): user pid=5785 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665624.507:3320): user pid=5785 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665624.794:3321): user pid=5819 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665624.794:3322): user pid=5819 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665624.805:3323): user pid=5819 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665624.805:3324): user pid=5819 uid=0 auid=0 ses=66 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="glance" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.196:3325): user pid=5847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5847 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.196:3326): user pid=5847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5847 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665627.197:3327): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5847 suid=74 rport=60422 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665627.197:3328): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5847 suid=74 rport=60422 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.259:3329): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60422 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.259:3330): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60422 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665627.269:3331): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.270:3332): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5847 suid=74 rport=60422 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.271:3333): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665627.271:3334): user pid=5846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665627.272:3335): pid=5846 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=130 >type=USER_ROLE_CHANGE msg=audit(1362665627.406:3336): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665627.412:3337): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665627.412:3338): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665627.412:3339): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.413:3340): user pid=5849 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5849 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.413:3341): user pid=5849 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5849 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665627.414:3342): user pid=5849 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665627.463:3343): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665627.463:3344): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665627.464:3345): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665627.464:3346): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.464:3347): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5846 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.464:3348): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5846 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.464:3349): user pid=5846 uid=0 auid=0 ses=130 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5846 suid=0 rport=60422 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.503:3350): user pid=5854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5854 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.503:3351): user pid=5854 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5854 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665627.503:3352): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5854 suid=74 rport=60423 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665627.504:3353): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5854 suid=74 rport=60423 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.566:3354): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60423 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.566:3355): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60423 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665627.573:3356): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.573:3357): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5854 suid=74 rport=60423 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.574:3358): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665627.574:3359): user pid=5853 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665627.575:3360): pid=5853 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=131 >type=USER_ROLE_CHANGE msg=audit(1362665627.700:3361): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665627.705:3362): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665627.710:3363): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665627.710:3364): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.711:3365): user pid=5856 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5856 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.711:3366): user pid=5856 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5856 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665627.712:3367): user pid=5856 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665627.758:3368): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665627.758:3369): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665627.759:3370): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665627.759:3371): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.759:3372): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5853 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.759:3373): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5853 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.759:3374): user pid=5853 uid=0 auid=0 ses=131 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5853 suid=0 rport=60423 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.792:3375): user pid=5868 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5868 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.793:3376): user pid=5868 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5868 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665627.793:3377): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=5868 suid=74 rport=60424 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665627.793:3378): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=5868 suid=74 rport=60424 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.859:3379): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60424 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.859:3380): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60424 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665627.865:3381): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665627.866:3382): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5868 suid=74 rport=60424 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665627.867:3383): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665627.867:3384): user pid=5867 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665627.867:3385): pid=5867 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=132 >type=USER_ROLE_CHANGE msg=audit(1362665627.991:3386): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665627.995:3387): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665628.001:3388): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665628.001:3389): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665628.002:3390): user pid=5893 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5893 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665628.002:3391): user pid=5893 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5893 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665628.003:3392): user pid=5893 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665628.037:3393): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665628.037:3394): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665628.037:3395): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665628.038:3396): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665628.038:3397): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5867 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665628.038:3398): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5867 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665628.038:3399): user pid=5867 uid=0 auid=0 ses=132 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5867 suid=0 rport=60424 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.081:3400): user pid=6126 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6126 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.082:3401): user pid=6126 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6126 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665631.082:3402): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6126 suid=74 rport=60425 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665631.082:3403): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6126 suid=74 rport=60425 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665631.134:3404): table=filter family=2 entries=15 >type=SYSCALL msg=audit(1362665631.134:3404): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1fae4d0 items=0 ppid=5863 pid=6130 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=131 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=USER_AUTH msg=audit(1362665631.148:3405): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60425 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665631.148:3406): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60425 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665631.159:3407): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.163:3408): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6126 suid=74 rport=60425 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665631.164:3409): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665631.165:3410): user pid=6124 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665631.165:3411): pid=6124 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=133 >type=USER_ROLE_CHANGE msg=audit(1362665631.298:3412): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665631.303:3413): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665631.310:3414): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665631.310:3415): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.311:3416): user pid=6135 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6135 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.311:3417): user pid=6135 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6135 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665631.312:3418): user pid=6135 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665631.362:3419): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665631.362:3420): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665631.363:3421): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665631.363:3422): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.363:3423): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6124 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.363:3424): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6124 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665631.363:3425): user pid=6124 uid=0 auid=0 ses=133 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6124 suid=0 rport=60425 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.413:3426): user pid=6142 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6142 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.413:3427): user pid=6142 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6142 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665634.416:3428): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6142 suid=74 rport=60436 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665634.416:3429): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6142 suid=74 rport=60436 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665634.482:3430): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60436 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665634.482:3431): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60436 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665634.491:3432): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.492:3433): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6142 suid=74 rport=60436 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665634.493:3434): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665634.493:3435): user pid=6141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665634.493:3436): pid=6141 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=134 >type=USER_ROLE_CHANGE msg=audit(1362665634.627:3437): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665634.629:3438): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665634.634:3439): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665634.634:3440): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.648:3441): user pid=6145 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6145 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.648:3442): user pid=6145 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6145 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665634.649:3443): user pid=6145 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665634.726:3444): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665634.726:3445): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665634.726:3446): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665634.727:3447): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.727:3448): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6141 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.727:3449): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6141 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665634.727:3450): user pid=6141 uid=0 auid=0 ses=134 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6141 suid=0 rport=60436 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665637.773:3451): user pid=6152 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6152 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665637.773:3452): user pid=6152 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6152 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665637.773:3453): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6152 suid=74 rport=60437 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665637.774:3454): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6152 suid=74 rport=60437 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665637.839:3455): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60437 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665637.839:3456): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60437 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665637.848:3457): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665637.849:3458): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6152 suid=74 rport=60437 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665637.850:3459): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665637.850:3460): user pid=6151 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665637.850:3461): pid=6151 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=135 >type=USER_ROLE_CHANGE msg=audit(1362665637.978:3462): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665637.981:3463): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665637.986:3464): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665637.986:3465): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665637.987:3466): user pid=6154 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6154 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665637.987:3467): user pid=6154 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6154 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665637.988:3468): user pid=6154 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665638.035:3469): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665638.035:3470): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665638.036:3471): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665638.036:3472): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665638.036:3473): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6151 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665638.036:3474): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6151 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665638.036:3475): user pid=6151 uid=0 auid=0 ses=135 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6151 suid=0 rport=60437 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.095:3476): user pid=6161 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6161 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.095:3477): user pid=6161 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6161 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665641.096:3478): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6161 suid=74 rport=60438 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665641.096:3479): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6161 suid=74 rport=60438 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665641.159:3480): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60438 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665641.159:3481): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60438 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665641.168:3482): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.169:3483): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6161 suid=74 rport=60438 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665641.170:3484): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665641.170:3485): user pid=6160 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665641.170:3486): pid=6160 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=136 >type=USER_ROLE_CHANGE msg=audit(1362665641.298:3487): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665641.301:3488): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665641.307:3489): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665641.308:3490): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.309:3491): user pid=6163 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6163 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.309:3492): user pid=6163 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6163 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665641.310:3493): user pid=6163 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665641.360:3494): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665641.361:3495): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665641.361:3496): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665641.361:3497): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.361:3498): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6160 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.361:3499): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6160 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665641.361:3500): user pid=6160 uid=0 auid=0 ses=136 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6160 suid=0 rport=60438 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.404:3501): user pid=6170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.404:3502): user pid=6170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665644.406:3503): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6170 suid=74 rport=60439 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665644.406:3504): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6170 suid=74 rport=60439 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665644.470:3505): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60439 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665644.470:3506): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60439 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665644.478:3507): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.481:3508): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6170 suid=74 rport=60439 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665644.482:3509): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665644.482:3510): user pid=6169 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665644.482:3511): pid=6169 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=137 >type=USER_ROLE_CHANGE msg=audit(1362665644.622:3512): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665644.625:3513): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665644.630:3514): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665644.630:3515): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.631:3516): user pid=6172 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6172 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.631:3517): user pid=6172 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6172 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665644.632:3518): user pid=6172 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665644.681:3519): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665644.681:3520): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665644.681:3521): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665644.681:3522): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.681:3523): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6169 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.682:3524): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6169 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665644.682:3525): user pid=6169 uid=0 auid=0 ses=137 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6169 suid=0 rport=60439 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.727:3526): user pid=6179 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6179 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.727:3527): user pid=6179 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6179 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665647.727:3528): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6179 suid=74 rport=60440 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665647.728:3529): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6179 suid=74 rport=60440 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665647.790:3530): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60440 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665647.790:3531): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60440 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665647.797:3532): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.797:3533): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6179 suid=74 rport=60440 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665647.798:3534): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665647.799:3535): user pid=6178 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665647.799:3536): pid=6178 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=138 >type=USER_ROLE_CHANGE msg=audit(1362665647.934:3537): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665647.939:3538): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665647.945:3539): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665647.945:3540): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.946:3541): user pid=6181 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6181 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.946:3542): user pid=6181 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6181 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665647.947:3543): user pid=6181 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665647.998:3544): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665647.998:3545): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665647.999:3546): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665647.999:3547): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.999:3548): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6178 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.999:3549): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6178 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665647.999:3550): user pid=6178 uid=0 auid=0 ses=138 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6178 suid=0 rport=60440 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665650.800:3551): user pid=6189 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=162 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665650.872:3552): user pid=6189 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=162 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665650.873:3553): user pid=6189 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=162 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665650.975:3554): user pid=6194 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=162 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665650.975:3555): user pid=6194 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="nova" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665650.975:3556): user pid=6194 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="nova" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665650.975:3557): user pid=6194 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="nova" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665650.976:3558): user pid=6194 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="nova" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.050:3559): user pid=6199 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6199 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.050:3560): user pid=6199 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6199 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665651.051:3561): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6199 suid=74 rport=60442 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665651.051:3562): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6199 suid=74 rport=60442 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665651.118:3563): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60442 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665651.118:3564): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60442 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665651.126:3565): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.129:3566): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6199 suid=74 rport=60442 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665651.129:3567): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665651.130:3568): user pid=6198 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665651.130:3569): pid=6198 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=139 >type=USER_ROLE_CHANGE msg=audit(1362665651.266:3570): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665651.269:3571): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665651.269:3572): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665651.270:3573): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.271:3574): user pid=6201 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6201 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.271:3575): user pid=6201 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6201 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665651.272:3576): user pid=6201 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665651.324:3577): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665651.324:3578): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665651.326:3579): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665651.327:3580): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.328:3581): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6198 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.329:3582): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6198 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665651.329:3583): user pid=6198 uid=0 auid=0 ses=139 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6198 suid=0 rport=60442 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.374:3584): user pid=6215 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6215 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.375:3585): user pid=6215 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6215 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665654.376:3586): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6215 suid=74 rport=60444 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665654.376:3587): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6215 suid=74 rport=60444 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665654.446:3588): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60444 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665654.446:3589): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60444 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665654.453:3590): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.454:3591): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6215 suid=74 rport=60444 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665654.454:3592): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665654.455:3593): user pid=6214 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665654.455:3594): pid=6214 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=140 >type=USER_ROLE_CHANGE msg=audit(1362665654.591:3595): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665654.594:3596): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665654.601:3597): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665654.601:3598): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.602:3599): user pid=6217 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6217 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.602:3600): user pid=6217 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6217 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665654.603:3601): user pid=6217 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665654.651:3602): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665654.651:3603): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665654.652:3604): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665654.652:3605): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.652:3606): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6214 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.652:3607): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6214 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665654.652:3608): user pid=6214 uid=0 auid=0 ses=140 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6214 suid=0 rport=60444 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.719:3609): user pid=6228 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6228 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.720:3610): user pid=6228 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6228 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665657.721:3611): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6228 suid=74 rport=60445 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665657.721:3612): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6228 suid=74 rport=60445 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665657.786:3613): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60445 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665657.786:3614): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60445 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665657.796:3615): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.797:3616): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6228 suid=74 rport=60445 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665657.798:3617): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665657.798:3618): user pid=6227 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665657.798:3619): pid=6227 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=141 >type=USER_ROLE_CHANGE msg=audit(1362665657.944:3620): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665657.946:3621): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665657.952:3622): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665657.952:3623): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.953:3624): user pid=6234 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6234 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.953:3625): user pid=6234 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6234 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665657.954:3626): user pid=6234 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665657.988:3627): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665657.988:3628): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665657.989:3629): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665657.989:3630): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.989:3631): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6227 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.989:3632): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6227 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665657.989:3633): user pid=6227 uid=0 auid=0 ses=141 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6227 suid=0 rport=60445 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.028:3634): user pid=6251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.028:3635): user pid=6251 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665661.029:3636): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6251 suid=74 rport=60447 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665661.029:3637): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6251 suid=74 rport=60447 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665661.101:3638): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60447 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665661.101:3639): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60447 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665661.109:3640): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.110:3641): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6251 suid=74 rport=60447 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665661.111:3642): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665661.111:3643): user pid=6250 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665661.111:3644): pid=6250 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=142 >type=USER_ROLE_CHANGE msg=audit(1362665661.244:3645): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665661.247:3646): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665661.248:3647): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665661.248:3648): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.250:3649): user pid=6253 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6253 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.250:3650): user pid=6253 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6253 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665661.250:3651): user pid=6253 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665661.296:3652): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665661.296:3653): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665661.297:3654): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665661.297:3655): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.297:3656): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6250 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.297:3657): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6250 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665661.297:3658): user pid=6250 uid=0 auid=0 ses=142 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6250 suid=0 rport=60447 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.342:3659): user pid=6260 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6260 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.342:3660): user pid=6260 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6260 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665664.342:3661): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6260 suid=74 rport=60448 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665664.342:3662): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6260 suid=74 rport=60448 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665664.405:3663): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60448 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665664.406:3664): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60448 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665664.414:3665): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.414:3666): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6260 suid=74 rport=60448 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665664.415:3667): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665664.416:3668): user pid=6259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665664.416:3669): pid=6259 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=143 >type=USER_ROLE_CHANGE msg=audit(1362665664.545:3670): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665664.550:3671): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665664.550:3672): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665664.551:3673): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.552:3674): user pid=6262 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6262 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.552:3675): user pid=6262 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6262 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665664.553:3676): user pid=6262 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665664.597:3677): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665664.597:3678): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665664.597:3679): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665664.597:3680): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.597:3681): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6259 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.597:3682): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6259 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665664.597:3683): user pid=6259 uid=0 auid=0 ses=143 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6259 suid=0 rport=60448 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.643:3684): user pid=6269 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6269 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.643:3685): user pid=6269 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6269 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665667.644:3686): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6269 suid=74 rport=60449 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665667.644:3687): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6269 suid=74 rport=60449 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665667.707:3688): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60449 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665667.707:3689): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60449 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665667.716:3690): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.716:3691): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6269 suid=74 rport=60449 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665667.717:3692): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665667.718:3693): user pid=6268 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665667.718:3694): pid=6268 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=144 >type=USER_ROLE_CHANGE msg=audit(1362665667.847:3695): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665667.853:3696): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665667.859:3697): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665667.859:3698): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.860:3699): user pid=6271 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6271 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.860:3700): user pid=6271 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6271 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665667.861:3701): user pid=6271 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665667.910:3702): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665667.910:3703): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665667.911:3704): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665667.911:3705): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.911:3706): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6268 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.912:3707): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6268 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665667.912:3708): user pid=6268 uid=0 auid=0 ses=144 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6268 suid=0 rport=60449 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665670.950:3709): user pid=6278 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6278 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665670.951:3710): user pid=6278 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6278 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665670.951:3711): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6278 suid=74 rport=60450 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665670.952:3712): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6278 suid=74 rport=60450 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665671.015:3713): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60450 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665671.015:3714): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60450 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665671.024:3715): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665671.025:3716): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6278 suid=74 rport=60450 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665671.026:3717): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665671.026:3718): user pid=6277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665671.026:3719): pid=6277 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=145 >type=USER_ROLE_CHANGE msg=audit(1362665671.156:3720): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665671.161:3721): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665671.166:3722): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665671.166:3723): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665671.168:3724): user pid=6280 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6280 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665671.168:3725): user pid=6280 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6280 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665671.169:3726): user pid=6280 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665671.215:3727): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665671.215:3728): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665671.216:3729): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665671.216:3730): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665671.216:3731): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6277 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665671.216:3732): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6277 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665671.216:3733): user pid=6277 uid=0 auid=0 ses=145 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6277 suid=0 rport=60450 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.259:3734): user pid=6287 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.260:3735): user pid=6287 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665674.260:3736): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6287 suid=74 rport=60451 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665674.260:3737): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6287 suid=74 rport=60451 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665674.323:3738): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60451 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665674.323:3739): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60451 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665674.333:3740): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.333:3741): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6287 suid=74 rport=60451 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665674.334:3742): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665674.335:3743): user pid=6286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665674.335:3744): pid=6286 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=146 >type=USER_ROLE_CHANGE msg=audit(1362665674.461:3745): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665674.467:3746): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665674.468:3747): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665674.468:3748): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.469:3749): user pid=6289 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6289 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.469:3750): user pid=6289 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6289 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665674.470:3751): user pid=6289 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665674.515:3752): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665674.515:3753): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665674.516:3754): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665674.516:3755): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.516:3756): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6286 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.516:3757): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6286 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665674.516:3758): user pid=6286 uid=0 auid=0 ses=146 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6286 suid=0 rport=60451 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.562:3759): user pid=6296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6296 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.563:3760): user pid=6296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6296 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665677.563:3761): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6296 suid=74 rport=60452 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665677.563:3762): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6296 suid=74 rport=60452 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665677.627:3763): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60452 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665677.627:3764): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60452 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665677.635:3765): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.638:3766): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6296 suid=74 rport=60452 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665677.639:3767): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665677.639:3768): user pid=6295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665677.639:3769): pid=6295 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=147 >type=USER_ROLE_CHANGE msg=audit(1362665677.767:3770): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665677.770:3771): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665677.771:3772): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665677.771:3773): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.772:3774): user pid=6298 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6298 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.773:3775): user pid=6298 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6298 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665677.773:3776): user pid=6298 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665677.824:3777): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665677.825:3778): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665677.825:3779): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665677.825:3780): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.825:3781): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6295 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.826:3782): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6295 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665677.826:3783): user pid=6295 uid=0 auid=0 ses=147 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6295 suid=0 rport=60452 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665680.867:3784): user pid=6305 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6305 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665680.867:3785): user pid=6305 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6305 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665680.867:3786): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6305 suid=74 rport=60453 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665680.868:3787): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6305 suid=74 rport=60453 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665680.932:3788): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60453 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665680.932:3789): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60453 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665680.941:3790): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665680.942:3791): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6305 suid=74 rport=60453 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665680.943:3792): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665680.944:3793): user pid=6304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665680.944:3794): pid=6304 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=148 >type=USER_ROLE_CHANGE msg=audit(1362665681.072:3795): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665681.075:3796): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665681.077:3797): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665681.077:3798): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665681.078:3799): user pid=6307 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6307 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665681.078:3800): user pid=6307 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6307 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665681.079:3801): user pid=6307 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665681.125:3802): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665681.126:3803): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665681.126:3804): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665681.126:3805): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665681.126:3806): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6304 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665681.127:3807): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6304 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665681.127:3808): user pid=6304 uid=0 auid=0 ses=148 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6304 suid=0 rport=60453 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.170:3809): user pid=6314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6314 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.170:3810): user pid=6314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6314 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665684.174:3811): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6314 suid=74 rport=60454 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665684.174:3812): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6314 suid=74 rport=60454 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665684.238:3813): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60454 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665684.238:3814): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60454 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665684.246:3815): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.247:3816): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6314 suid=74 rport=60454 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665684.248:3817): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665684.249:3818): user pid=6313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665684.249:3819): pid=6313 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=149 >type=USER_ROLE_CHANGE msg=audit(1362665684.379:3820): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665684.382:3821): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665684.382:3822): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665684.382:3823): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.383:3824): user pid=6316 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6316 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.384:3825): user pid=6316 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6316 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665684.384:3826): user pid=6316 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665684.433:3827): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665684.433:3828): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665684.436:3829): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665684.438:3830): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.438:3831): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6313 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.438:3832): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6313 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665684.438:3833): user pid=6313 uid=0 auid=0 ses=149 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6313 suid=0 rport=60454 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.483:3834): user pid=6323 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6323 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.483:3835): user pid=6323 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6323 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665687.484:3836): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6323 suid=74 rport=60455 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665687.484:3837): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6323 suid=74 rport=60455 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665687.548:3838): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60455 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665687.548:3839): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60455 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665687.561:3840): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.562:3841): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6323 suid=74 rport=60455 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665687.563:3842): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665687.564:3843): user pid=6322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665687.564:3844): pid=6322 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=150 >type=USER_ROLE_CHANGE msg=audit(1362665687.691:3845): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665687.695:3846): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665687.700:3847): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665687.700:3848): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.701:3849): user pid=6325 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6325 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.702:3850): user pid=6325 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6325 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665687.702:3851): user pid=6325 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665687.749:3852): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665687.749:3853): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665687.749:3854): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665687.750:3855): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.750:3856): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6322 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.750:3857): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6322 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665687.750:3858): user pid=6322 uid=0 auid=0 ses=150 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6322 suid=0 rport=60455 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665690.791:3859): user pid=6332 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6332 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665690.791:3860): user pid=6332 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6332 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665690.793:3861): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6332 suid=74 rport=60456 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665690.793:3862): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6332 suid=74 rport=60456 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665690.857:3863): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60456 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665690.857:3864): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60456 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665690.865:3865): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665690.866:3866): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6332 suid=74 rport=60456 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665690.866:3867): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665690.867:3868): user pid=6331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665690.867:3869): pid=6331 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=151 >type=USER_ROLE_CHANGE msg=audit(1362665690.993:3870): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665690.999:3871): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665691.004:3872): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665691.004:3873): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665691.006:3874): user pid=6334 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6334 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665691.006:3875): user pid=6334 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6334 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665691.007:3876): user pid=6334 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665691.053:3877): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665691.053:3878): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665691.053:3879): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665691.054:3880): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665691.054:3881): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6331 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665691.054:3882): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6331 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665691.054:3883): user pid=6331 uid=0 auid=0 ses=151 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6331 suid=0 rport=60456 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.098:3884): user pid=6341 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6341 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.099:3885): user pid=6341 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6341 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665694.099:3886): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6341 suid=74 rport=60457 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665694.099:3887): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6341 suid=74 rport=60457 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665694.163:3888): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60457 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665694.163:3889): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60457 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665694.172:3890): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.173:3891): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6341 suid=74 rport=60457 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665694.173:3892): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665694.174:3893): user pid=6340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665694.174:3894): pid=6340 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=152 >type=USER_ROLE_CHANGE msg=audit(1362665694.298:3895): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665694.300:3896): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665694.307:3897): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665694.307:3898): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.308:3899): user pid=6343 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6343 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.308:3900): user pid=6343 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6343 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665694.309:3901): user pid=6343 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665694.358:3902): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665694.358:3903): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665694.358:3904): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665694.359:3905): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.359:3906): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6340 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.359:3907): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6340 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665694.359:3908): user pid=6340 uid=0 auid=0 ses=152 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6340 suid=0 rport=60457 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.406:3909): user pid=6350 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6350 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.407:3910): user pid=6350 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6350 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665697.407:3911): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6350 suid=74 rport=60458 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665697.407:3912): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6350 suid=74 rport=60458 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665697.470:3913): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60458 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665697.470:3914): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60458 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665697.479:3915): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.479:3916): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6350 suid=74 rport=60458 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665697.480:3917): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665697.481:3918): user pid=6349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665697.482:3919): pid=6349 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=153 >type=USER_ROLE_CHANGE msg=audit(1362665697.610:3920): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665697.616:3921): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665697.622:3922): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665697.622:3923): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.623:3924): user pid=6352 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.624:3925): user pid=6352 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665697.624:3926): user pid=6352 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665697.672:3927): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665697.672:3928): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665697.672:3929): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665697.672:3930): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.673:3931): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6349 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.673:3932): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6349 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665697.673:3933): user pid=6349 uid=0 auid=0 ses=153 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6349 suid=0 rport=60458 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.716:3934): user pid=6359 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6359 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.716:3935): user pid=6359 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6359 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665700.716:3936): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6359 suid=74 rport=60459 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665700.717:3937): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6359 suid=74 rport=60459 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665700.780:3938): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60459 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665700.780:3939): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60459 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665700.791:3940): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.791:3941): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6359 suid=74 rport=60459 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665700.792:3942): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665700.793:3943): user pid=6358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665700.793:3944): pid=6358 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=154 >type=USER_ROLE_CHANGE msg=audit(1362665700.916:3945): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665700.922:3946): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665700.927:3947): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665700.928:3948): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.929:3949): user pid=6361 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.929:3950): user pid=6361 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665700.931:3951): user pid=6361 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665700.975:3952): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665700.976:3953): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665700.976:3954): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665700.976:3955): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.976:3956): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6358 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.977:3957): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6358 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665700.977:3958): user pid=6358 uid=0 auid=0 ses=154 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6358 suid=0 rport=60459 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.030:3959): user pid=6368 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6368 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.030:3960): user pid=6368 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6368 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665704.031:3961): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6368 suid=74 rport=60460 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665704.032:3962): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6368 suid=74 rport=60460 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665704.096:3963): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60460 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665704.096:3964): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60460 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665704.110:3965): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.110:3966): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6368 suid=74 rport=60460 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665704.111:3967): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665704.111:3968): user pid=6367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665704.112:3969): pid=6367 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=155 >type=USER_ROLE_CHANGE msg=audit(1362665704.252:3970): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665704.257:3971): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665704.262:3972): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665704.263:3973): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.264:3974): user pid=6372 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6372 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.264:3975): user pid=6372 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6372 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665704.265:3976): user pid=6372 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665704.292:3977): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665704.292:3978): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665704.293:3979): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665704.293:3980): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.293:3981): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6367 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.293:3982): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6367 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665704.293:3983): user pid=6367 uid=0 auid=0 ses=155 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6367 suid=0 rport=60460 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_START msg=audit(1362665704.396:3984): user pid=6384 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362665704.396:3985): user pid=6384 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665704.400:3986): user pid=6384 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665704.401:3987): user pid=6384 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665705.912:3988): user pid=6400 uid=162 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665705.914:3989): user pid=6400 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665705.915:3990): user pid=6400 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362665706.059:3991): user pid=6400 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665706.060:3992): user pid=6400 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665706.074:3993): user pid=6404 uid=162 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665706.075:3994): user pid=6404 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665706.075:3995): user pid=6404 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665706.197:3996): table=filter family=2 entries=16 >type=SYSCALL msg=audit(1362665706.197:3996): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1867ef0 items=0 ppid=6405 pid=6406 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=131 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362665706.203:3997): user pid=6404 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665706.204:3998): user pid=6404 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665706.215:3999): user pid=6408 uid=162 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665706.216:4000): user pid=6408 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665706.216:4001): user pid=6408 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665706.379:4002): table=mangle family=2 entries=0 >type=SYSCALL msg=audit(1362665706.379:4002): arch=c000003e syscall=175 success=yes exit=0 a0=a5d0c0 a1=22d0 a2=a554e0 a3=7fff8e7ea3b0 items=0 ppid=6411 pid=6412 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="modprobe" exe="/sbin/modprobe" subj=system_u:system_r:insmod_t:s0 key=(null) >type=USER_END msg=audit(1362665706.397:4003): user pid=6408 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665706.397:4004): user pid=6408 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665706.420:4005): user pid=6413 uid=162 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665706.420:4006): user pid=6413 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665706.421:4007): user pid=6413 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665706.539:4008): table=mangle family=2 entries=6 >type=SYSCALL msg=audit(1362665706.539:4008): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=97d190 items=0 ppid=6414 pid=6415 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=131 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362665706.546:4009): user pid=6413 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665706.546:4010): user pid=6413 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665706.558:4011): user pid=6416 uid=162 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665706.559:4012): user pid=6416 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665706.559:4013): user pid=6416 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665706.688:4014): table=nat family=2 entries=0 >type=SYSCALL msg=audit(1362665706.688:4014): arch=c000003e syscall=175 success=yes exit=0 a0=1df6bd0 a1=3ef0 a2=1de84e0 a3=7fff4e416e40 items=0 ppid=6419 pid=6420 auid=4294967295 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=4294967295 comm="modprobe" exe="/sbin/modprobe" subj=system_u:system_r:insmod_t:s0 key=(null) >type=USER_END msg=audit(1362665706.700:4015): user pid=6416 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665706.700:4016): user pid=6416 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362665706.712:4017): user pid=6421 uid=162 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362665706.712:4018): user pid=6421 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362665706.712:4019): user pid=6421 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665706.831:4020): table=nat family=2 entries=4 >type=SYSCALL msg=audit(1362665706.831:4020): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1e5e730 items=0 ppid=6422 pid=6423 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=131 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362665706.838:4021): user pid=6421 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362665706.839:4022): user pid=6421 uid=0 auid=0 ses=131 subj=unconfined_u:system_r:nova_api_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.345:4023): user pid=6428 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6428 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.345:4024): user pid=6428 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6428 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665707.346:4025): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6428 suid=74 rport=60461 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665707.346:4026): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6428 suid=74 rport=60461 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665707.410:4027): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60461 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665707.410:4028): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60461 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665707.417:4029): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.418:4030): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6428 suid=74 rport=60461 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665707.419:4031): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665707.419:4032): user pid=6427 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665707.419:4033): pid=6427 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=156 >type=USER_ROLE_CHANGE msg=audit(1362665707.554:4034): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665707.559:4035): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665707.564:4036): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665707.564:4037): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.565:4038): user pid=6430 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6430 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.565:4039): user pid=6430 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6430 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665707.566:4040): user pid=6430 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665707.620:4041): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665707.621:4042): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665707.621:4043): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665707.621:4044): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.621:4045): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6427 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.621:4046): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6427 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.621:4047): user pid=6427 uid=0 auid=0 ses=156 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6427 suid=0 rport=60461 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.647:4048): user pid=6435 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6435 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.647:4049): user pid=6435 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6435 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665707.648:4050): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6435 suid=74 rport=60462 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665707.648:4051): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6435 suid=74 rport=60462 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665707.710:4052): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60462 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665707.710:4053): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60462 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665707.719:4054): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.720:4055): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6435 suid=74 rport=60462 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665707.720:4056): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665707.721:4057): user pid=6434 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665707.721:4058): pid=6434 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=157 >type=USER_ROLE_CHANGE msg=audit(1362665707.849:4059): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665707.854:4060): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665707.859:4061): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665707.859:4062): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.860:4063): user pid=6437 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6437 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.860:4064): user pid=6437 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6437 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665707.861:4065): user pid=6437 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665707.911:4066): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665707.911:4067): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665707.912:4068): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665707.912:4069): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.912:4070): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6434 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.912:4071): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6434 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.912:4072): user pid=6434 uid=0 auid=0 ses=157 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6434 suid=0 rport=60462 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.939:4073): user pid=6447 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6447 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665707.939:4074): user pid=6447 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6447 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665707.940:4075): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6447 suid=74 rport=60463 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665707.940:4076): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6447 suid=74 rport=60463 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.006:4077): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60463 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.006:4078): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60463 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665708.012:4079): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.013:4080): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6447 suid=74 rport=60463 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.013:4081): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665708.014:4082): user pid=6446 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665708.014:4083): pid=6446 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=158 >type=USER_ROLE_CHANGE msg=audit(1362665708.142:4084): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665708.148:4085): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665708.153:4086): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665708.153:4087): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.154:4088): user pid=6472 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6472 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.154:4089): user pid=6472 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6472 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665708.155:4090): user pid=6472 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665708.197:4091): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665708.197:4092): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665708.198:4093): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665708.198:4094): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.198:4095): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6446 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.198:4096): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6446 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.198:4097): user pid=6446 uid=0 auid=0 ses=158 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6446 suid=0 rport=60463 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.222:4098): user pid=6481 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6481 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.222:4099): user pid=6481 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6481 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665708.222:4100): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6481 suid=74 rport=60464 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665708.223:4101): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6481 suid=74 rport=60464 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.286:4102): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60464 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.287:4103): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60464 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665708.292:4104): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.295:4105): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6481 suid=74 rport=60464 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.295:4106): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665708.296:4107): user pid=6480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665708.296:4108): pid=6480 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=159 >type=USER_ROLE_CHANGE msg=audit(1362665708.423:4109): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665708.426:4110): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665708.426:4111): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665708.426:4112): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.428:4113): user pid=6489 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6489 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.428:4114): user pid=6489 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6489 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665708.429:4115): user pid=6489 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665708.470:4116): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665708.470:4117): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665708.471:4118): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665708.471:4119): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.471:4120): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6480 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.471:4121): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6480 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.472:4122): user pid=6480 uid=0 auid=0 ses=159 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6480 suid=0 rport=60464 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.503:4123): user pid=6505 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6505 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.503:4124): user pid=6505 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6505 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665708.504:4125): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6505 suid=74 rport=60465 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665708.504:4126): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6505 suid=74 rport=60465 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.569:4127): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60465 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.569:4128): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60465 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665708.578:4129): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.580:4130): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6505 suid=74 rport=60465 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665708.581:4131): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665708.581:4132): user pid=6504 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665708.581:4133): pid=6504 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=160 >type=USER_ROLE_CHANGE msg=audit(1362665708.709:4134): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665708.713:4135): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665708.718:4136): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665708.719:4137): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.720:4138): user pid=6544 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6544 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.720:4139): user pid=6544 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6544 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665708.721:4140): user pid=6544 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665708.757:4141): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665708.757:4142): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665708.758:4143): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665708.758:4144): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.758:4145): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6504 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.758:4146): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6504 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665708.758:4147): user pid=6504 uid=0 auid=0 ses=160 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6504 suid=0 rport=60465 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665711.803:4148): user pid=6732 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6732 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665711.803:4149): user pid=6732 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6732 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665711.804:4150): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6732 suid=74 rport=60466 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665711.804:4151): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6732 suid=74 rport=60466 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665711.872:4152): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60466 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665711.873:4153): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60466 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665711.882:4154): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665711.883:4155): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6732 suid=74 rport=60466 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665711.884:4156): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665711.884:4157): user pid=6731 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665711.885:4158): pid=6731 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=161 >type=USER_ROLE_CHANGE msg=audit(1362665712.015:4159): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665712.021:4160): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665712.027:4161): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665712.027:4162): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665712.029:4163): user pid=6738 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6738 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665712.029:4164): user pid=6738 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6738 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665712.030:4165): user pid=6738 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665712.067:4166): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665712.067:4167): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665712.067:4168): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665712.068:4169): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665712.068:4170): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6731 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665712.068:4171): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6731 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665712.068:4172): user pid=6731 uid=0 auid=0 ses=161 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6731 suid=0 rport=60466 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362665712.087:4173): table=filter family=2 entries=33 >type=SYSCALL msg=audit(1362665712.087:4173): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=24fac60 items=0 ppid=6445 pid=6739 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362665715.112:4174): user pid=6751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6751 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.112:4175): user pid=6751 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6751 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665715.113:4176): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6751 suid=74 rport=60468 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665715.113:4177): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6751 suid=74 rport=60468 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665715.176:4178): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60468 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665715.177:4179): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60468 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665715.185:4180): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.187:4181): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6751 suid=74 rport=60468 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665715.188:4182): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665715.189:4183): user pid=6750 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665715.189:4184): pid=6750 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=162 >type=USER_ROLE_CHANGE msg=audit(1362665715.327:4185): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665715.332:4186): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665715.338:4187): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665715.338:4188): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.339:4189): user pid=6753 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6753 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.339:4190): user pid=6753 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6753 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665715.340:4191): user pid=6753 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665715.385:4192): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665715.385:4193): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665715.386:4194): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665715.386:4195): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.386:4196): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6750 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.386:4197): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6750 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665715.386:4198): user pid=6750 uid=0 auid=0 ses=162 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6750 suid=0 rport=60468 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.426:4199): user pid=6763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6763 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.427:4200): user pid=6763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6763 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665718.427:4201): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6763 suid=74 rport=60474 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665718.427:4202): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6763 suid=74 rport=60474 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665718.499:4203): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60474 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665718.499:4204): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60474 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665718.506:4205): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.507:4206): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6763 suid=74 rport=60474 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665718.507:4207): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665718.508:4208): user pid=6762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665718.508:4209): pid=6762 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=163 >type=USER_ROLE_CHANGE msg=audit(1362665718.638:4210): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665718.643:4211): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665718.648:4212): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665718.649:4213): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.650:4214): user pid=6765 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6765 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.650:4215): user pid=6765 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6765 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665718.651:4216): user pid=6765 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665718.698:4217): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665718.698:4218): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665718.698:4219): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665718.698:4220): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.699:4221): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6762 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.699:4222): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6762 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665718.699:4223): user pid=6762 uid=0 auid=0 ses=163 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6762 suid=0 rport=60474 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665721.742:4224): user pid=6772 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6772 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665721.742:4225): user pid=6772 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6772 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665721.743:4226): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6772 suid=74 rport=60477 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665721.743:4227): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6772 suid=74 rport=60477 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665721.807:4228): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60477 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665721.808:4229): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60477 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665721.813:4230): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665721.814:4231): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6772 suid=74 rport=60477 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665721.815:4232): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665721.815:4233): user pid=6771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665721.815:4234): pid=6771 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=164 >type=USER_ROLE_CHANGE msg=audit(1362665721.951:4235): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665721.956:4236): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665721.962:4237): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665721.963:4238): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665721.964:4239): user pid=6774 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6774 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665721.964:4240): user pid=6774 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6774 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665721.965:4241): user pid=6774 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665722.017:4242): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665722.018:4243): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665722.018:4244): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665722.018:4245): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665722.019:4246): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6771 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665722.019:4247): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6771 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665722.019:4248): user pid=6771 uid=0 auid=0 ses=164 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6771 suid=0 rport=60477 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665724.615:4249): user pid=6781 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=75 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665724.736:4250): user pid=6781 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=75 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665724.737:4251): user pid=6781 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=75 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665724.881:4252): user pid=6786 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=75 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.074:4253): user pid=6795 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6795 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.075:4254): user pid=6795 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6795 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665725.078:4255): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6795 suid=74 rport=60478 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665725.078:4256): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6795 suid=74 rport=60478 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665725.143:4257): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60478 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665725.144:4258): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60478 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665725.155:4259): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.155:4260): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6795 suid=74 rport=60478 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665725.156:4261): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665725.156:4262): user pid=6794 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665725.156:4263): pid=6794 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=165 >type=USER_ROLE_CHANGE msg=audit(1362665725.280:4264): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665725.286:4265): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665725.292:4266): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665725.292:4267): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.293:4268): user pid=6797 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6797 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.293:4269): user pid=6797 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6797 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665725.294:4270): user pid=6797 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665725.343:4271): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665725.343:4272): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665725.344:4273): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665725.344:4274): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.344:4275): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6794 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.345:4276): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6794 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665725.345:4277): user pid=6794 uid=0 auid=0 ses=165 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6794 suid=0 rport=60478 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.399:4278): user pid=6808 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6808 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.399:4279): user pid=6808 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6808 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665728.400:4280): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6808 suid=74 rport=60479 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665728.400:4281): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6808 suid=74 rport=60479 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665728.463:4282): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60479 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665728.463:4283): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60479 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665728.472:4284): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.472:4285): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6808 suid=74 rport=60479 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665728.473:4286): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665728.474:4287): user pid=6807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665728.474:4288): pid=6807 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=166 >type=USER_ROLE_CHANGE msg=audit(1362665728.598:4289): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665728.603:4290): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665728.608:4291): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665728.609:4292): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.610:4293): user pid=6810 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6810 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.611:4294): user pid=6810 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6810 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665728.612:4295): user pid=6810 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665728.675:4296): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665728.675:4297): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665728.676:4298): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665728.676:4299): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.676:4300): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6807 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.676:4301): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6807 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665728.676:4302): user pid=6807 uid=0 auid=0 ses=166 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6807 suid=0 rport=60479 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.721:4303): user pid=6820 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6820 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.721:4304): user pid=6820 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6820 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665731.722:4305): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6820 suid=74 rport=60481 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665731.722:4306): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6820 suid=74 rport=60481 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665731.784:4307): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60481 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665731.785:4308): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60481 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665731.792:4309): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.793:4310): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6820 suid=74 rport=60481 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665731.794:4311): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665731.794:4312): user pid=6819 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665731.794:4313): pid=6819 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=167 >type=USER_ROLE_CHANGE msg=audit(1362665731.926:4314): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665731.931:4315): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665731.935:4316): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665731.936:4317): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.937:4318): user pid=6822 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6822 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.937:4319): user pid=6822 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6822 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665731.937:4320): user pid=6822 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665731.984:4321): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665731.984:4322): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665731.984:4323): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665731.984:4324): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.984:4325): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6819 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.984:4326): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6819 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665731.984:4327): user pid=6819 uid=0 auid=0 ses=167 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6819 suid=0 rport=60481 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.028:4328): user pid=6829 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6829 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.028:4329): user pid=6829 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6829 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665735.029:4330): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6829 suid=74 rport=60485 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665735.029:4331): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6829 suid=74 rport=60485 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665735.091:4332): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60485 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665735.091:4333): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60485 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665735.097:4334): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.100:4335): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6829 suid=74 rport=60485 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665735.101:4336): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665735.101:4337): user pid=6828 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665735.101:4338): pid=6828 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=168 >type=USER_ROLE_CHANGE msg=audit(1362665735.226:4339): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665735.230:4340): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665735.235:4341): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665735.235:4342): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.236:4343): user pid=6831 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6831 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.236:4344): user pid=6831 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6831 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665735.237:4345): user pid=6831 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665735.282:4346): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665735.282:4347): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665735.283:4348): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665735.283:4349): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.283:4350): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6828 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.283:4351): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6828 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665735.283:4352): user pid=6828 uid=0 auid=0 ses=168 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6828 suid=0 rport=60485 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.326:4353): user pid=6838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6838 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.326:4354): user pid=6838 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6838 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665738.327:4355): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6838 suid=74 rport=60488 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665738.327:4356): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6838 suid=74 rport=60488 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665738.390:4357): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60488 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665738.390:4358): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60488 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665738.396:4359): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.397:4360): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6838 suid=74 rport=60488 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665738.398:4361): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665738.398:4362): user pid=6837 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665738.398:4363): pid=6837 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=169 >type=USER_ROLE_CHANGE msg=audit(1362665738.522:4364): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665738.527:4365): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665738.532:4366): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665738.532:4367): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.534:4368): user pid=6840 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6840 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.534:4369): user pid=6840 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6840 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665738.534:4370): user pid=6840 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665738.586:4371): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665738.586:4372): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665738.586:4373): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665738.586:4374): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.586:4375): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6837 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.587:4376): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6837 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665738.587:4377): user pid=6837 uid=0 auid=0 ses=169 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6837 suid=0 rport=60488 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.625:4378): user pid=6847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6847 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.625:4379): user pid=6847 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6847 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665741.625:4380): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6847 suid=74 rport=60490 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665741.625:4381): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6847 suid=74 rport=60490 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665741.690:4382): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60490 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665741.690:4383): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60490 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665741.696:4384): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.697:4385): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6847 suid=74 rport=60490 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665741.698:4386): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665741.698:4387): user pid=6846 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665741.698:4388): pid=6846 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=170 >type=USER_ROLE_CHANGE msg=audit(1362665741.828:4389): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665741.832:4390): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665741.837:4391): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665741.837:4392): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.838:4393): user pid=6849 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6849 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.838:4394): user pid=6849 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6849 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665741.839:4395): user pid=6849 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665741.886:4396): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665741.886:4397): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665741.887:4398): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665741.887:4399): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.887:4400): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6846 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.887:4401): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6846 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665741.887:4402): user pid=6846 uid=0 auid=0 ses=170 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6846 suid=0 rport=60490 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665744.927:4403): user pid=6856 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6856 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665744.927:4404): user pid=6856 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6856 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665744.928:4405): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6856 suid=74 rport=60493 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665744.928:4406): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6856 suid=74 rport=60493 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665744.992:4407): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60493 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665744.992:4408): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60493 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665744.999:4409): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665745.001:4410): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6856 suid=74 rport=60493 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665745.002:4411): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665745.002:4412): user pid=6855 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665745.002:4413): pid=6855 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=171 >type=USER_ROLE_CHANGE msg=audit(1362665745.127:4414): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665745.133:4415): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665745.138:4416): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665745.139:4417): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665745.139:4418): user pid=6858 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6858 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665745.140:4419): user pid=6858 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6858 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665745.140:4420): user pid=6858 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665745.189:4421): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665745.189:4422): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665745.189:4423): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665745.190:4424): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665745.190:4425): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6855 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665745.190:4426): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6855 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665745.190:4427): user pid=6855 uid=0 auid=0 ses=171 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6855 suid=0 rport=60493 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.237:4428): user pid=6865 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6865 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.237:4429): user pid=6865 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6865 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665748.239:4430): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6865 suid=74 rport=60496 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665748.239:4431): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6865 suid=74 rport=60496 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665748.303:4432): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60496 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665748.303:4433): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60496 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665748.310:4434): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.310:4435): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6865 suid=74 rport=60496 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665748.311:4436): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665748.311:4437): user pid=6864 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665748.311:4438): pid=6864 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=172 >type=USER_ROLE_CHANGE msg=audit(1362665748.437:4439): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665748.440:4440): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665748.441:4441): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665748.441:4442): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.442:4443): user pid=6867 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6867 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.442:4444): user pid=6867 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6867 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665748.443:4445): user pid=6867 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665748.493:4446): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665748.493:4447): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665748.496:4448): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665748.496:4449): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.496:4450): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6864 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.496:4451): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6864 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665748.496:4452): user pid=6864 uid=0 auid=0 ses=172 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6864 suid=0 rport=60496 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.532:4453): user pid=6874 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6874 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.532:4454): user pid=6874 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6874 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665751.535:4455): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6874 suid=74 rport=60497 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665751.535:4456): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6874 suid=74 rport=60497 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665751.597:4457): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60497 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665751.598:4458): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60497 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665751.605:4459): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.606:4460): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6874 suid=74 rport=60497 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665751.607:4461): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665751.607:4462): user pid=6873 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665751.607:4463): pid=6873 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=173 >type=USER_ROLE_CHANGE msg=audit(1362665751.728:4464): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665751.731:4465): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665751.732:4466): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665751.733:4467): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.733:4468): user pid=6876 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6876 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.734:4469): user pid=6876 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6876 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665751.734:4470): user pid=6876 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665751.783:4471): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665751.783:4472): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665751.785:4473): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665751.785:4474): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.786:4475): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6873 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.786:4476): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6873 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665751.786:4477): user pid=6873 uid=0 auid=0 ses=173 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6873 suid=0 rport=60497 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665754.826:4478): user pid=6883 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6883 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665754.826:4479): user pid=6883 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6883 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665754.828:4480): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6883 suid=74 rport=60499 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665754.829:4481): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6883 suid=74 rport=60499 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665754.891:4482): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60499 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665754.891:4483): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60499 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665754.898:4484): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665754.899:4485): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6883 suid=74 rport=60499 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665754.900:4486): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665754.901:4487): user pid=6882 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665754.901:4488): pid=6882 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=174 >type=USER_ROLE_CHANGE msg=audit(1362665755.025:4489): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665755.028:4490): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665755.028:4491): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665755.028:4492): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665755.030:4493): user pid=6885 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6885 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665755.030:4494): user pid=6885 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6885 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665755.030:4495): user pid=6885 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665755.079:4496): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665755.079:4497): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665755.082:4498): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665755.083:4499): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665755.083:4500): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6882 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665755.083:4501): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6882 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665755.083:4502): user pid=6882 uid=0 auid=0 ses=174 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6882 suid=0 rport=60499 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.138:4503): user pid=6892 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6892 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.138:4504): user pid=6892 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6892 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665758.139:4505): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6892 suid=74 rport=60502 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665758.139:4506): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6892 suid=74 rport=60502 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665758.202:4507): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60502 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665758.202:4508): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60502 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665758.208:4509): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.209:4510): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6892 suid=74 rport=60502 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665758.210:4511): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665758.210:4512): user pid=6891 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665758.210:4513): pid=6891 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=175 >type=USER_ROLE_CHANGE msg=audit(1362665758.331:4514): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665758.332:4515): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665758.337:4516): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665758.337:4517): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.339:4518): user pid=6894 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6894 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.339:4519): user pid=6894 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6894 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665758.340:4520): user pid=6894 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665758.389:4521): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665758.389:4522): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665758.389:4523): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665758.390:4524): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.390:4525): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6891 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.390:4526): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6891 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665758.390:4527): user pid=6891 uid=0 auid=0 ses=175 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6891 suid=0 rport=60502 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.427:4528): user pid=6901 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6901 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.427:4529): user pid=6901 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6901 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665761.428:4530): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6901 suid=74 rport=60504 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665761.428:4531): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6901 suid=74 rport=60504 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665761.492:4532): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60504 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665761.492:4533): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60504 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665761.499:4534): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.500:4535): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6901 suid=74 rport=60504 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665761.500:4536): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665761.501:4537): user pid=6900 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665761.501:4538): pid=6900 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=176 >type=USER_ROLE_CHANGE msg=audit(1362665761.627:4539): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665761.632:4540): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665761.638:4541): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665761.638:4542): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.639:4543): user pid=6903 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6903 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.640:4544): user pid=6903 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6903 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665761.640:4545): user pid=6903 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665761.686:4546): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665761.686:4547): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665761.686:4548): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665761.686:4549): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.686:4550): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6900 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.687:4551): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6900 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665761.687:4552): user pid=6900 uid=0 auid=0 ses=176 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6900 suid=0 rport=60504 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.729:4553): user pid=6910 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6910 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.729:4554): user pid=6910 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6910 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665764.730:4555): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6910 suid=74 rport=60508 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665764.730:4556): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6910 suid=74 rport=60508 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665764.794:4557): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60508 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665764.794:4558): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60508 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665764.803:4559): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.804:4560): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6910 suid=74 rport=60508 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665764.805:4561): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665764.805:4562): user pid=6909 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665764.805:4563): pid=6909 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=177 >type=USER_ROLE_CHANGE msg=audit(1362665764.924:4564): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665764.929:4565): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665764.935:4566): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665764.935:4567): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.936:4568): user pid=6912 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6912 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.936:4569): user pid=6912 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6912 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665764.938:4570): user pid=6912 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665764.984:4571): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665764.985:4572): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665764.985:4573): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665764.985:4574): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.985:4575): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6909 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.986:4576): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6909 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665764.986:4577): user pid=6909 uid=0 auid=0 ses=177 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6909 suid=0 rport=60508 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.022:4578): user pid=6919 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6919 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.022:4579): user pid=6919 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6919 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665768.022:4580): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6919 suid=74 rport=60510 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665768.023:4581): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6919 suid=74 rport=60510 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665768.088:4582): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60510 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665768.088:4583): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60510 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665768.094:4584): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.095:4585): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6919 suid=74 rport=60510 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665768.096:4586): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665768.096:4587): user pid=6918 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665768.096:4588): pid=6918 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=178 >type=USER_ROLE_CHANGE msg=audit(1362665768.221:4589): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665768.227:4590): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665768.232:4591): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665768.232:4592): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.233:4593): user pid=6921 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6921 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.233:4594): user pid=6921 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6921 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665768.234:4595): user pid=6921 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665768.281:4596): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665768.282:4597): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665768.282:4598): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665768.282:4599): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.282:4600): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6918 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.283:4601): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6918 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665768.283:4602): user pid=6918 uid=0 auid=0 ses=178 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6918 suid=0 rport=60510 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.324:4603): user pid=6928 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6928 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.324:4604): user pid=6928 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6928 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665771.324:4605): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6928 suid=74 rport=60513 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665771.325:4606): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6928 suid=74 rport=60513 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665771.388:4607): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60513 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665771.388:4608): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60513 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665771.395:4609): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.396:4610): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6928 suid=74 rport=60513 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665771.397:4611): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665771.397:4612): user pid=6927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665771.397:4613): pid=6927 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=179 >type=USER_ROLE_CHANGE msg=audit(1362665771.524:4614): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665771.528:4615): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665771.535:4616): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665771.535:4617): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.536:4618): user pid=6930 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6930 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.536:4619): user pid=6930 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6930 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665771.537:4620): user pid=6930 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665771.582:4621): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665771.582:4622): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665771.583:4623): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665771.583:4624): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.583:4625): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6927 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.583:4626): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6927 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665771.583:4627): user pid=6927 uid=0 auid=0 ses=179 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6927 suid=0 rport=60513 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.625:4628): user pid=6937 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6937 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.625:4629): user pid=6937 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6937 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665774.626:4630): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6937 suid=74 rport=60516 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665774.626:4631): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6937 suid=74 rport=60516 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665774.688:4632): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60516 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665774.688:4633): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60516 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665774.697:4634): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.697:4635): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6937 suid=74 rport=60516 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665774.698:4636): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665774.699:4637): user pid=6936 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665774.699:4638): pid=6936 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=180 >type=USER_ROLE_CHANGE msg=audit(1362665774.829:4639): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665774.832:4640): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665774.837:4641): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665774.838:4642): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.838:4643): user pid=6939 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6939 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.839:4644): user pid=6939 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6939 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665774.839:4645): user pid=6939 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665774.886:4646): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665774.886:4647): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665774.887:4648): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665774.887:4649): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.887:4650): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6936 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.887:4651): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6936 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665774.887:4652): user pid=6936 uid=0 auid=0 ses=180 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6936 suid=0 rport=60516 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665777.926:4653): user pid=6946 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6946 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665777.926:4654): user pid=6946 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6946 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665777.927:4655): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6946 suid=74 rport=60520 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665777.927:4656): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6946 suid=74 rport=60520 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665777.993:4657): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60520 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665777.993:4658): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60520 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665778.000:4659): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665778.002:4660): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6946 suid=74 rport=60520 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665778.003:4661): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665778.003:4662): user pid=6945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665778.003:4663): pid=6945 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=181 >type=USER_ROLE_CHANGE msg=audit(1362665778.131:4664): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665778.136:4665): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665778.141:4666): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665778.141:4667): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665778.142:4668): user pid=6948 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6948 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665778.142:4669): user pid=6948 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6948 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665778.143:4670): user pid=6948 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665778.189:4671): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665778.189:4672): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665778.189:4673): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665778.190:4674): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665778.190:4675): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6945 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665778.190:4676): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6945 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665778.190:4677): user pid=6945 uid=0 auid=0 ses=181 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6945 suid=0 rport=60520 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.229:4678): user pid=6955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.229:4679): user pid=6955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665781.230:4680): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6955 suid=74 rport=60522 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665781.230:4681): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6955 suid=74 rport=60522 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665781.292:4682): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60522 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665781.292:4683): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60522 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665781.299:4684): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.300:4685): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6955 suid=74 rport=60522 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665781.301:4686): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665781.301:4687): user pid=6954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665781.301:4688): pid=6954 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=182 >type=USER_ROLE_CHANGE msg=audit(1362665781.432:4689): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665781.436:4690): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665781.441:4691): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665781.441:4692): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.442:4693): user pid=6957 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.442:4694): user pid=6957 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665781.443:4695): user pid=6957 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665781.491:4696): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665781.491:4697): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665781.492:4698): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665781.492:4699): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.492:4700): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6954 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.492:4701): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6954 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665781.492:4702): user pid=6954 uid=0 auid=0 ses=182 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6954 suid=0 rport=60522 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.530:4703): user pid=6964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.531:4704): user pid=6964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665784.531:4705): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6964 suid=74 rport=60525 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665784.532:4706): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6964 suid=74 rport=60525 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665784.595:4707): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60525 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665784.595:4708): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60525 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665784.602:4709): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.603:4710): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6964 suid=74 rport=60525 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665784.604:4711): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665784.604:4712): user pid=6963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665784.604:4713): pid=6963 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=183 >type=USER_ROLE_CHANGE msg=audit(1362665784.732:4714): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665784.737:4715): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665784.743:4716): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665784.743:4717): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.744:4718): user pid=6966 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.744:4719): user pid=6966 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665784.745:4720): user pid=6966 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665784.792:4721): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665784.792:4722): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665784.792:4723): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665784.792:4724): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.793:4725): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6963 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.793:4726): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6963 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665784.793:4727): user pid=6963 uid=0 auid=0 ses=183 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6963 suid=0 rport=60525 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665787.832:4728): user pid=6973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6973 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665787.833:4729): user pid=6973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6973 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665787.833:4730): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6973 suid=74 rport=60526 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665787.833:4731): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6973 suid=74 rport=60526 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665787.896:4732): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60526 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665787.896:4733): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60526 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665787.903:4734): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665787.903:4735): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6973 suid=74 rport=60526 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665787.904:4736): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665787.904:4737): user pid=6972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665787.905:4738): pid=6972 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=184 >type=USER_ROLE_CHANGE msg=audit(1362665788.032:4739): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665788.037:4740): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665788.043:4741): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665788.043:4742): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665788.044:4743): user pid=6975 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6975 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665788.044:4744): user pid=6975 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6975 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665788.045:4745): user pid=6975 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665788.087:4746): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665788.088:4747): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665788.088:4748): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665788.088:4749): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665788.088:4750): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6972 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665788.088:4751): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6972 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665788.088:4752): user pid=6972 uid=0 auid=0 ses=184 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6972 suid=0 rport=60526 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.128:4753): user pid=6982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.128:4754): user pid=6982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665791.129:4755): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6982 suid=74 rport=60527 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665791.129:4756): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6982 suid=74 rport=60527 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665791.191:4757): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60527 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665791.191:4758): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60527 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665791.199:4759): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.200:4760): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6982 suid=74 rport=60527 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665791.201:4761): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665791.201:4762): user pid=6981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665791.201:4763): pid=6981 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=185 >type=USER_ROLE_CHANGE msg=audit(1362665791.326:4764): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665791.332:4765): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665791.337:4766): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665791.338:4767): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.339:4768): user pid=6984 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6984 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.339:4769): user pid=6984 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6984 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665791.339:4770): user pid=6984 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665791.392:4771): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665791.392:4772): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665791.393:4773): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665791.393:4774): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.393:4775): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.393:4776): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665791.393:4777): user pid=6981 uid=0 auid=0 ses=185 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6981 suid=0 rport=60527 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.446:4778): user pid=6992 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6992 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.446:4779): user pid=6992 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6992 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665794.447:4780): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=6992 suid=74 rport=60529 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665794.447:4781): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=6992 suid=74 rport=60529 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665794.508:4782): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60529 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665794.509:4783): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60529 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665794.516:4784): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.516:4785): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6992 suid=74 rport=60529 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665794.517:4786): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665794.517:4787): user pid=6991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665794.517:4788): pid=6991 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=186 >type=USER_ROLE_CHANGE msg=audit(1362665794.653:4789): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665794.658:4790): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665794.663:4791): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665794.664:4792): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.665:4793): user pid=6994 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6994 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.665:4794): user pid=6994 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6994 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665794.666:4795): user pid=6994 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665794.716:4796): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665794.716:4797): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665794.717:4798): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665794.717:4799): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.717:4800): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=6991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.717:4801): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=6991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665794.717:4802): user pid=6991 uid=0 auid=0 ses=186 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=6991 suid=0 rport=60529 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665797.756:4803): user pid=7001 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7001 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665797.756:4804): user pid=7001 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7001 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665797.757:4805): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7001 suid=74 rport=60530 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665797.757:4806): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7001 suid=74 rport=60530 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665797.819:4807): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60530 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665797.819:4808): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60530 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665797.826:4809): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665797.827:4810): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7001 suid=74 rport=60530 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665797.828:4811): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665797.828:4812): user pid=7000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665797.828:4813): pid=7000 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=187 >type=USER_ROLE_CHANGE msg=audit(1362665797.952:4814): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665797.957:4815): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665797.963:4816): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665797.963:4817): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665797.964:4818): user pid=7003 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7003 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665797.964:4819): user pid=7003 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7003 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665797.965:4820): user pid=7003 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665798.015:4821): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665798.015:4822): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665798.015:4823): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665798.015:4824): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665798.015:4825): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665798.016:4826): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665798.016:4827): user pid=7000 uid=0 auid=0 ses=187 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7000 suid=0 rport=60530 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.059:4828): user pid=7010 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7010 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.059:4829): user pid=7010 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7010 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665801.060:4830): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7010 suid=74 rport=60532 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665801.060:4831): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7010 suid=74 rport=60532 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665801.122:4832): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60532 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665801.122:4833): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60532 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665801.129:4834): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.133:4835): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7010 suid=74 rport=60532 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665801.134:4836): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665801.134:4837): user pid=7009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665801.134:4838): pid=7009 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=188 >type=USER_ROLE_CHANGE msg=audit(1362665801.259:4839): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665801.262:4840): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665801.262:4841): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665801.263:4842): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.263:4843): user pid=7012 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7012 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.263:4844): user pid=7012 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7012 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665801.264:4845): user pid=7012 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665801.313:4846): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665801.313:4847): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665801.314:4848): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665801.314:4849): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.314:4850): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.314:4851): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665801.314:4852): user pid=7009 uid=0 auid=0 ses=188 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7009 suid=0 rport=60532 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.355:4853): user pid=7019 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7019 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.356:4854): user pid=7019 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7019 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665804.356:4855): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7019 suid=74 rport=60535 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665804.356:4856): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7019 suid=74 rport=60535 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665804.418:4857): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60535 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665804.419:4858): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60535 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665804.426:4859): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.428:4860): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7019 suid=74 rport=60535 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665804.429:4861): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665804.429:4862): user pid=7018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665804.429:4863): pid=7018 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=189 >type=USER_ROLE_CHANGE msg=audit(1362665804.553:4864): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665804.555:4865): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665804.557:4866): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665804.557:4867): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.559:4868): user pid=7021 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7021 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.559:4869): user pid=7021 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7021 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665804.559:4870): user pid=7021 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665804.608:4871): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665804.608:4872): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665804.610:4873): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665804.610:4874): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.611:4875): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.611:4876): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665804.611:4877): user pid=7018 uid=0 auid=0 ses=189 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7018 suid=0 rport=60535 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.648:4878): user pid=7028 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7028 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.649:4879): user pid=7028 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7028 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665807.652:4880): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7028 suid=74 rport=60538 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665807.652:4881): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7028 suid=74 rport=60538 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665807.716:4882): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60538 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665807.716:4883): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60538 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665807.723:4884): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.724:4885): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7028 suid=74 rport=60538 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665807.725:4886): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665807.725:4887): user pid=7027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665807.725:4888): pid=7027 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=190 >type=USER_ROLE_CHANGE msg=audit(1362665807.852:4889): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665807.855:4890): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665807.856:4891): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665807.856:4892): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.857:4893): user pid=7030 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7030 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.857:4894): user pid=7030 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7030 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665807.858:4895): user pid=7030 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665807.907:4896): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665807.907:4897): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665807.908:4898): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665807.908:4899): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.908:4900): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.908:4901): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665807.908:4902): user pid=7027 uid=0 auid=0 ses=190 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7027 suid=0 rport=60538 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665810.944:4903): user pid=7037 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7037 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665810.944:4904): user pid=7037 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7037 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665810.945:4905): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7037 suid=74 rport=60541 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665810.945:4906): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7037 suid=74 rport=60541 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665811.011:4907): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60541 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665811.011:4908): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60541 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665811.019:4909): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665811.019:4910): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7037 suid=74 rport=60541 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665811.020:4911): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665811.020:4912): user pid=7036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665811.020:4913): pid=7036 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=191 >type=USER_ROLE_CHANGE msg=audit(1362665811.141:4914): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665811.145:4915): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665811.151:4916): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665811.151:4917): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665811.152:4918): user pid=7039 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7039 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665811.152:4919): user pid=7039 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7039 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665811.153:4920): user pid=7039 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665811.199:4921): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665811.199:4922): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665811.200:4923): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665811.200:4924): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665811.200:4925): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665811.200:4926): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665811.200:4927): user pid=7036 uid=0 auid=0 ses=191 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7036 suid=0 rport=60541 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.243:4928): user pid=7046 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7046 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.243:4929): user pid=7046 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7046 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665814.243:4930): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7046 suid=74 rport=60544 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665814.244:4931): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7046 suid=74 rport=60544 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665814.308:4932): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60544 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665814.308:4933): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60544 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665814.315:4934): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.316:4935): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7046 suid=74 rport=60544 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665814.317:4936): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665814.317:4937): user pid=7045 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665814.318:4938): pid=7045 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=192 >type=USER_ROLE_CHANGE msg=audit(1362665814.448:4939): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665814.450:4940): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665814.454:4941): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665814.455:4942): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.456:4943): user pid=7048 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7048 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.456:4944): user pid=7048 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7048 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665814.457:4945): user pid=7048 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665814.503:4946): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665814.503:4947): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665814.503:4948): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665814.503:4949): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.504:4950): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7045 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.504:4951): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7045 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665814.504:4952): user pid=7045 uid=0 auid=0 ses=192 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7045 suid=0 rport=60544 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.544:4953): user pid=7055 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7055 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.544:4954): user pid=7055 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7055 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665817.544:4955): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7055 suid=74 rport=60547 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665817.545:4956): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7055 suid=74 rport=60547 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665817.607:4957): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60547 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665817.607:4958): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60547 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665817.615:4959): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.616:4960): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7055 suid=74 rport=60547 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665817.617:4961): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665817.617:4962): user pid=7054 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665817.617:4963): pid=7054 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=193 >type=USER_ROLE_CHANGE msg=audit(1362665817.741:4964): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665817.747:4965): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665817.751:4966): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665817.752:4967): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.753:4968): user pid=7057 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7057 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.753:4969): user pid=7057 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7057 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665817.754:4970): user pid=7057 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665817.801:4971): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665817.801:4972): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665817.802:4973): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665817.802:4974): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.802:4975): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7054 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.802:4976): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7054 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665817.802:4977): user pid=7054 uid=0 auid=0 ses=193 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7054 suid=0 rport=60547 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665820.843:4978): user pid=7064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7064 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665820.843:4979): user pid=7064 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7064 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665820.843:4980): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7064 suid=74 rport=60551 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665820.843:4981): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7064 suid=74 rport=60551 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665820.907:4982): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60551 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665820.907:4983): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60551 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665820.914:4984): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665820.915:4985): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7064 suid=74 rport=60551 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665820.915:4986): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665820.916:4987): user pid=7063 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665820.916:4988): pid=7063 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=194 >type=USER_ROLE_CHANGE msg=audit(1362665821.047:4989): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665821.052:4990): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665821.058:4991): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665821.058:4992): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665821.059:4993): user pid=7066 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7066 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665821.060:4994): user pid=7066 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7066 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665821.060:4995): user pid=7066 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665821.105:4996): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665821.105:4997): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665821.106:4998): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665821.106:4999): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665821.106:5000): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7063 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665821.106:5001): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7063 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665821.106:5002): user pid=7063 uid=0 auid=0 ses=194 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7063 suid=0 rport=60551 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.151:5003): user pid=7073 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7073 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.152:5004): user pid=7073 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7073 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665824.153:5005): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7073 suid=74 rport=60554 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665824.153:5006): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7073 suid=74 rport=60554 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665824.215:5007): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60554 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665824.215:5008): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60554 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665824.222:5009): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.223:5010): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7073 suid=74 rport=60554 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665824.224:5011): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665824.224:5012): user pid=7072 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665824.224:5013): pid=7072 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=195 >type=USER_ROLE_CHANGE msg=audit(1362665824.346:5014): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665824.351:5015): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665824.356:5016): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665824.357:5017): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.358:5018): user pid=7075 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7075 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.358:5019): user pid=7075 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7075 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665824.359:5020): user pid=7075 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665824.403:5021): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665824.404:5022): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665824.404:5023): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665824.404:5024): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.404:5025): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7072 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.404:5026): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7072 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665824.405:5027): user pid=7072 uid=0 auid=0 ses=195 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7072 suid=0 rport=60554 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665826.856:5028): user pid=7079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=81 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665826.922:5029): user pid=7079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=81 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665826.923:5030): user pid=7079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=81 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665827.031:5031): user pid=7083 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=81 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.462:5032): user pid=7092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.462:5033): user pid=7092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665827.463:5034): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7092 suid=74 rport=60555 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665827.463:5035): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7092 suid=74 rport=60555 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665827.526:5036): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60555 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665827.526:5037): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60555 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665827.532:5038): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.534:5039): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7092 suid=74 rport=60555 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665827.536:5040): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665827.536:5041): user pid=7091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665827.536:5042): pid=7091 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=196 >type=USER_ROLE_CHANGE msg=audit(1362665827.667:5043): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665827.672:5044): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665827.678:5045): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665827.678:5046): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.679:5047): user pid=7094 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7094 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.679:5048): user pid=7094 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7094 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665827.680:5049): user pid=7094 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665827.723:5050): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665827.723:5051): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665827.724:5052): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665827.724:5053): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.724:5054): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7091 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.724:5055): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7091 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665827.724:5056): user pid=7091 uid=0 auid=0 ses=196 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7091 suid=0 rport=60555 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665830.776:5057): user pid=7109 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7109 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665830.776:5058): user pid=7109 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7109 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665830.777:5059): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7109 suid=74 rport=60556 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665830.777:5060): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7109 suid=74 rport=60556 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665830.841:5061): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60556 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665830.841:5062): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60556 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665830.849:5063): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665830.852:5064): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7109 suid=74 rport=60556 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665830.853:5065): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665830.853:5066): user pid=7108 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665830.853:5067): pid=7108 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=197 >type=USER_ROLE_CHANGE msg=audit(1362665830.986:5068): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665830.989:5069): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665830.990:5070): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665830.991:5071): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665831.004:5072): user pid=7112 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7112 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665831.005:5073): user pid=7112 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7112 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665831.006:5074): user pid=7112 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665831.057:5075): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665831.058:5076): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665831.059:5077): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665831.059:5078): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665831.060:5079): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7108 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665831.060:5080): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7108 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665831.060:5081): user pid=7108 uid=0 auid=0 ses=197 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7108 suid=0 rport=60556 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665832.008:5082): user pid=7118 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=498 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665832.111:5083): user pid=7118 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=498 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665832.112:5084): user pid=7118 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=498 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.117:5085): user pid=7130 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7130 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.117:5086): user pid=7130 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7130 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665834.118:5087): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7130 suid=74 rport=60557 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665834.118:5088): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7130 suid=74 rport=60557 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665834.182:5089): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60557 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665834.182:5090): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60557 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665834.190:5091): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.190:5092): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7130 suid=74 rport=60557 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665834.191:5093): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665834.191:5094): user pid=7129 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665834.192:5095): pid=7129 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=198 >type=USER_ROLE_CHANGE msg=audit(1362665834.320:5096): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665834.325:5097): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665834.331:5098): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665834.331:5099): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.333:5100): user pid=7132 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7132 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.333:5101): user pid=7132 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7132 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665834.334:5102): user pid=7132 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665834.381:5103): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665834.381:5104): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665834.382:5105): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665834.382:5106): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.382:5107): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7129 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.382:5108): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7129 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665834.382:5109): user pid=7129 uid=0 auid=0 ses=198 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7129 suid=0 rport=60557 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665835.314:5110): user pid=7141 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=32 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665835.411:5111): user pid=7141 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=32 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665835.414:5112): user pid=7141 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=32 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665835.457:5113): user pid=7145 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=32 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.451:5114): user pid=7156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7156 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.451:5115): user pid=7156 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7156 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665837.452:5116): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7156 suid=74 rport=60558 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665837.453:5117): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7156 suid=74 rport=60558 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665837.517:5118): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60558 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665837.517:5119): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60558 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665837.524:5120): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.525:5121): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7156 suid=74 rport=60558 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665837.526:5122): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665837.526:5123): user pid=7155 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665837.526:5124): pid=7155 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=199 >type=USER_ROLE_CHANGE msg=audit(1362665837.660:5125): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665837.664:5126): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665837.669:5127): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665837.670:5128): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.671:5129): user pid=7158 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7158 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.671:5130): user pid=7158 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7158 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665837.672:5131): user pid=7158 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665837.720:5132): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665837.720:5133): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665837.721:5134): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665837.721:5135): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.721:5136): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7155 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.721:5137): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7155 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665837.721:5138): user pid=7155 uid=0 auid=0 ses=199 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7155 suid=0 rport=60558 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665840.770:5139): user pid=7171 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7171 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665840.770:5140): user pid=7171 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7171 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665840.773:5141): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7171 suid=74 rport=60559 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665840.773:5142): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7171 suid=74 rport=60559 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665840.835:5143): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60559 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665840.835:5144): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60559 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665840.845:5145): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665840.845:5146): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7171 suid=74 rport=60559 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665840.846:5147): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665840.847:5148): user pid=7170 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665840.847:5149): pid=7170 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=200 >type=USER_ROLE_CHANGE msg=audit(1362665840.973:5150): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665840.976:5151): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665840.981:5152): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665840.981:5153): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665840.983:5154): user pid=7176 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7176 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665840.983:5155): user pid=7176 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7176 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665840.983:5156): user pid=7176 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665841.030:5157): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665841.030:5158): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665841.031:5159): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665841.031:5160): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665841.031:5161): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665841.031:5162): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665841.031:5163): user pid=7170 uid=0 auid=0 ses=200 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7170 suid=0 rport=60559 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.086:5164): user pid=7187 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7187 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.087:5165): user pid=7187 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7187 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665844.087:5166): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7187 suid=74 rport=60560 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665844.087:5167): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7187 suid=74 rport=60560 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665844.152:5168): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60560 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665844.152:5169): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60560 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665844.160:5170): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.161:5171): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7187 suid=74 rport=60560 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665844.162:5172): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665844.162:5173): user pid=7186 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665844.162:5174): pid=7186 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=201 >type=USER_ROLE_CHANGE msg=audit(1362665844.289:5175): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665844.293:5176): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665844.298:5177): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665844.299:5178): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.300:5179): user pid=7190 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7190 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.300:5180): user pid=7190 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7190 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665844.301:5181): user pid=7190 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665844.351:5182): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665844.352:5183): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665844.352:5184): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665844.353:5185): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.353:5186): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7186 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.353:5187): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7186 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665844.353:5188): user pid=7186 uid=0 auid=0 ses=201 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7186 suid=0 rport=60560 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.401:5189): user pid=7204 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7204 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.402:5190): user pid=7204 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7204 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665847.403:5191): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7204 suid=74 rport=60561 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665847.403:5192): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7204 suid=74 rport=60561 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665847.465:5193): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60561 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665847.465:5194): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60561 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665847.471:5195): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.474:5196): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7204 suid=74 rport=60561 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665847.475:5197): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665847.475:5198): user pid=7203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665847.475:5199): pid=7203 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=202 >type=USER_ROLE_CHANGE msg=audit(1362665847.608:5200): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665847.613:5201): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665847.619:5202): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665847.619:5203): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.620:5204): user pid=7206 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7206 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.620:5205): user pid=7206 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7206 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665847.621:5206): user pid=7206 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665847.669:5207): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665847.669:5208): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665847.670:5209): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665847.670:5210): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.670:5211): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7203 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.670:5212): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7203 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665847.670:5213): user pid=7203 uid=0 auid=0 ses=202 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7203 suid=0 rport=60561 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665847.810:5214): user pid=7211 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding group acct="rpcuser" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665847.811:5215): user pid=7211 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=29 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665848.106:5216): user pid=7220 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=65534 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665848.155:5217): user pid=7220 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=65534 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665848.156:5218): user pid=7220 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=65534 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665848.167:5219): user pid=7227 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=65534 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665850.734:5220): user pid=7245 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7245 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665850.734:5221): user pid=7245 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7245 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665850.736:5222): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7245 suid=74 rport=60562 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665850.737:5223): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7245 suid=74 rport=60562 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665850.803:5224): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60562 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665850.803:5225): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60562 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665850.810:5226): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665850.811:5227): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7245 suid=74 rport=60562 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665850.813:5228): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665850.813:5229): user pid=7244 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665850.813:5230): pid=7244 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=203 >type=USER_ROLE_CHANGE msg=audit(1362665850.947:5231): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665850.952:5232): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665850.958:5233): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665850.958:5234): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665850.959:5235): user pid=7247 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7247 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665850.959:5236): user pid=7247 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7247 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665850.960:5237): user pid=7247 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665851.009:5238): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665851.010:5239): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665851.010:5240): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665851.010:5241): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665851.010:5242): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7244 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665851.010:5243): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7244 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665851.010:5244): user pid=7244 uid=0 auid=0 ses=203 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7244 suid=0 rport=60562 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.065:5245): user pid=7259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7259 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.065:5246): user pid=7259 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7259 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665854.066:5247): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7259 suid=74 rport=60563 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665854.066:5248): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7259 suid=74 rport=60563 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665854.131:5249): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60563 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665854.131:5250): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60563 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665854.139:5251): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.141:5252): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7259 suid=74 rport=60563 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665854.141:5253): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665854.142:5254): user pid=7258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665854.142:5255): pid=7258 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=204 >type=USER_ROLE_CHANGE msg=audit(1362665854.273:5256): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665854.277:5257): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665854.282:5258): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665854.282:5259): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.283:5260): user pid=7261 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7261 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.284:5261): user pid=7261 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7261 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665854.284:5262): user pid=7261 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665854.330:5263): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665854.330:5264): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665854.331:5265): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665854.331:5266): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.331:5267): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7258 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.331:5268): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7258 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665854.331:5269): user pid=7258 uid=0 auid=0 ses=204 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7258 suid=0 rport=60563 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665856.162:5270): user pid=7269 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=68 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665856.210:5271): user pid=7269 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=68 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665856.211:5272): user pid=7269 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=68 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665856.298:5273): user pid=7274 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=68 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665856.298:5274): user pid=7274 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="haldaemon" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665856.298:5275): user pid=7274 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="haldaemon" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.374:5276): user pid=7285 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7285 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.374:5277): user pid=7285 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7285 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665857.377:5278): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7285 suid=74 rport=60564 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665857.377:5279): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7285 suid=74 rport=60564 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665857.440:5280): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60564 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665857.440:5281): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60564 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665857.448:5282): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.450:5283): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7285 suid=74 rport=60564 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665857.450:5284): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665857.451:5285): user pid=7284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665857.451:5286): pid=7284 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=205 >type=USER_ROLE_CHANGE msg=audit(1362665857.584:5287): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665857.588:5288): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665857.590:5289): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665857.590:5290): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.591:5291): user pid=7287 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.591:5292): user pid=7287 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665857.592:5293): user pid=7287 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665857.632:5294): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665857.632:5295): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665857.632:5296): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665857.632:5297): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.633:5298): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7284 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.633:5299): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7284 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665857.633:5300): user pid=7284 uid=0 auid=0 ses=205 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7284 suid=0 rport=60564 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.699:5301): user pid=7297 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7297 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.700:5302): user pid=7297 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7297 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665860.702:5303): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7297 suid=74 rport=60565 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665860.702:5304): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7297 suid=74 rport=60565 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665860.766:5305): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60565 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665860.766:5306): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60565 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665860.774:5307): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.774:5308): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7297 suid=74 rport=60565 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665860.775:5309): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665860.776:5310): user pid=7296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665860.776:5311): pid=7296 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=206 >type=USER_ROLE_CHANGE msg=audit(1362665860.912:5312): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665860.917:5313): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665860.923:5314): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665860.923:5315): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.924:5316): user pid=7299 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7299 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.924:5317): user pid=7299 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7299 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665860.925:5318): user pid=7299 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665860.968:5319): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665860.968:5320): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665860.969:5321): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665860.969:5322): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.969:5323): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7296 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.969:5324): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7296 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665860.969:5325): user pid=7296 uid=0 auid=0 ses=206 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7296 suid=0 rport=60565 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362665861.454:5326): user pid=7307 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=36 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665861.502:5327): user pid=7307 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=36 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665861.503:5328): user pid=7307 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=36 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665861.557:5329): user pid=7312 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=107 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665861.605:5330): user pid=7312 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=107 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362665861.606:5331): user pid=7312 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=107 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665861.682:5332): user pid=7317 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=107 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665861.682:5333): user pid=7317 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="qemu" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362665861.682:5334): user pid=7317 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="qemu" exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.017:5335): user pid=7352 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.017:5336): user pid=7352 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665864.021:5337): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7352 suid=74 rport=60566 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665864.021:5338): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7352 suid=74 rport=60566 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665864.084:5339): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60566 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665864.084:5340): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60566 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665864.094:5341): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.095:5342): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7352 suid=74 rport=60566 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665864.096:5343): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665864.096:5344): user pid=7351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665864.096:5345): pid=7351 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=207 >type=USER_ROLE_CHANGE msg=audit(1362665864.239:5346): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665864.243:5347): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665864.245:5348): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665864.245:5349): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.246:5350): user pid=7354 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7354 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.246:5351): user pid=7354 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7354 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665864.247:5352): user pid=7354 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665864.299:5353): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665864.299:5354): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665864.302:5355): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665864.302:5356): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.302:5357): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7351 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.302:5358): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7351 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665864.303:5359): user pid=7351 uid=0 auid=0 ses=207 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7351 suid=0 rport=60566 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.351:5360): user pid=7361 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.351:5361): user pid=7361 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665867.353:5362): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7361 suid=74 rport=60567 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665867.353:5363): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7361 suid=74 rport=60567 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665867.415:5364): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60567 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665867.416:5365): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60567 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665867.423:5366): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.424:5367): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7361 suid=74 rport=60567 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665867.425:5368): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665867.426:5369): user pid=7360 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665867.426:5370): pid=7360 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=208 >type=USER_ROLE_CHANGE msg=audit(1362665867.553:5371): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665867.558:5372): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665867.564:5373): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665867.565:5374): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.566:5375): user pid=7363 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7363 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.566:5376): user pid=7363 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7363 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665867.567:5377): user pid=7363 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665867.617:5378): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665867.618:5379): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665867.618:5380): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665867.618:5381): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.618:5382): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7360 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.618:5383): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7360 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665867.619:5384): user pid=7360 uid=0 auid=0 ses=208 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7360 suid=0 rport=60567 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ANOM_PROMISCUOUS msg=audit(1362665869.815:5385): dev=virbr0-nic prom=256 old_prom=0 auid=0 uid=0 gid=0 ses=157 >type=SYSCALL msg=audit(1362665869.815:5385): arch=c000003e syscall=16 success=yes exit=0 a0=f a1=89a2 a2=7f2991663ae0 a3=7f2991663840 items=0 ppid=1 pid=7390 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="libvirtd" exe="/usr/sbin/libvirtd" subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665869.832:5386): table=filter family=2 entries=34 >type=SYSCALL msg=audit(1362665869.832:5386): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=17e96c0 items=0 ppid=7379 pid=7435 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665869.859:5387): table=filter family=2 entries=35 >type=SYSCALL msg=audit(1362665869.859:5387): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=21d3840 items=0 ppid=7379 pid=7438 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665869.923:5388): table=mangle family=2 entries=9 >type=SYSCALL msg=audit(1362665869.923:5388): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=180d070 items=0 ppid=7379 pid=7450 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665869.993:5389): table=filter family=2 entries=36 >type=SYSCALL msg=audit(1362665869.993:5389): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=248ba70 items=0 ppid=7379 pid=7453 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665869.996:5390): table=filter family=2 entries=37 >type=SYSCALL msg=audit(1362665869.996:5390): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=160ebf0 items=0 ppid=7379 pid=7454 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665869.998:5391): table=filter family=2 entries=38 >type=SYSCALL msg=audit(1362665869.998:5391): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1bcc510 items=0 ppid=7379 pid=7455 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.001:5392): table=filter family=2 entries=39 >type=SYSCALL msg=audit(1362665870.001:5392): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=10f0690 items=0 ppid=7379 pid=7456 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.004:5393): table=filter family=2 entries=40 >type=SYSCALL msg=audit(1362665870.004:5393): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=13643b0 items=0 ppid=7379 pid=7457 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.007:5394): table=filter family=2 entries=41 >type=SYSCALL msg=audit(1362665870.007:5394): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=146d530 items=0 ppid=7379 pid=7458 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.010:5395): table=filter family=2 entries=42 >type=SYSCALL msg=audit(1362665870.010:5395): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1645170 items=0 ppid=7379 pid=7459 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.083:5396): table=nat family=2 entries=22 >type=SYSCALL msg=audit(1362665870.083:5396): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=11ff5e0 items=0 ppid=7379 pid=7460 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.162:5397): table=nat family=2 entries=23 >type=SYSCALL msg=audit(1362665870.162:5397): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=2136930 items=0 ppid=7379 pid=7463 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362665870.166:5398): table=nat family=2 entries=24 >type=SYSCALL msg=audit(1362665870.166:5398): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=8ebad0 items=0 ppid=7379 pid=7464 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362665870.671:5399): user pid=7477 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7477 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.672:5400): user pid=7477 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7477 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665870.674:5401): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7477 suid=74 rport=60569 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665870.674:5402): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7477 suid=74 rport=60569 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665870.736:5403): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60569 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665870.737:5404): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60569 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665870.747:5405): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.749:5406): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7477 suid=74 rport=60569 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665870.750:5407): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665870.750:5408): user pid=7475 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665870.750:5409): pid=7475 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=209 >type=USER_ROLE_CHANGE msg=audit(1362665870.892:5410): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665870.898:5411): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665870.904:5412): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665870.904:5413): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.906:5414): user pid=7513 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7513 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.906:5415): user pid=7513 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7513 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665870.909:5416): user pid=7513 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=NETFILTER_CFG msg=audit(1362665870.921:5417): table=filter family=10 entries=0 >type=NETFILTER_CFG msg=audit(1362665870.921:5417): table=filter family=2 entries=0 >type=NETFILTER_CFG msg=audit(1362665870.921:5417): table=mangle family=2 entries=0 >type=NETFILTER_CFG msg=audit(1362665870.921:5417): table=nat family=2 entries=0 >type=SYSCALL msg=audit(1362665870.921:5417): arch=c000003e syscall=56 success=yes exit=7515 a0=6c020011 a1=7f298c0c28c0 a2=8 a3=a7373 items=0 ppid=1 pid=7390 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="libvirtd" exe="/usr/sbin/libvirtd" subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 key=(null) >type=SYSCALL msg=audit(1362665870.921:5418): arch=c000003e syscall=56 success=yes exit=0 a0=6c020011 a1=7f298c0c28c0 a2=8 a3=a7373 items=0 ppid=7390 pid=7515 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="libvirtd" exe="/usr/sbin/libvirtd" subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 key=(null) >type=FD_PAIR msg=audit(1362665870.921:5418): fd0=0 fd1=0 >type=USER_END msg=audit(1362665870.980:5419): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665870.980:5420): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665870.981:5421): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665870.981:5422): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.981:5423): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7475 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.981:5424): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7475 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665870.982:5425): user pid=7475 uid=0 auid=0 ses=209 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7475 suid=0 rport=60569 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.026:5426): user pid=7522 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7522 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.026:5427): user pid=7522 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7522 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665874.026:5428): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7522 suid=74 rport=60570 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665874.027:5429): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7522 suid=74 rport=60570 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665874.089:5430): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60570 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665874.089:5431): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60570 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665874.098:5432): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.099:5433): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7522 suid=74 rport=60570 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665874.099:5434): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665874.100:5435): user pid=7521 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665874.100:5436): pid=7521 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=210 >type=USER_ROLE_CHANGE msg=audit(1362665874.234:5437): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665874.239:5438): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665874.244:5439): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665874.245:5440): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.246:5441): user pid=7524 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7524 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.246:5442): user pid=7524 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7524 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665874.247:5443): user pid=7524 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665874.293:5444): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665874.294:5445): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665874.294:5446): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665874.294:5447): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.295:5448): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7521 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.295:5449): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7521 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665874.295:5450): user pid=7521 uid=0 auid=0 ses=210 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7521 suid=0 rport=60570 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.335:5451): user pid=7531 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7531 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.335:5452): user pid=7531 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7531 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665877.337:5453): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7531 suid=74 rport=60572 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665877.337:5454): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7531 suid=74 rport=60572 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665877.400:5455): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60572 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665877.400:5456): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60572 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665877.406:5457): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.406:5458): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7531 suid=74 rport=60572 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665877.407:5459): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665877.408:5460): user pid=7530 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665877.408:5461): pid=7530 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=211 >type=USER_ROLE_CHANGE msg=audit(1362665877.539:5462): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665877.543:5463): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665877.549:5464): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665877.549:5465): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.551:5466): user pid=7533 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7533 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.551:5467): user pid=7533 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7533 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665877.551:5468): user pid=7533 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665877.592:5469): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665877.592:5470): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665877.593:5471): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665877.593:5472): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.593:5473): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7530 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.593:5474): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7530 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665877.593:5475): user pid=7530 uid=0 auid=0 ses=211 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7530 suid=0 rport=60572 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.635:5476): user pid=7540 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7540 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.635:5477): user pid=7540 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7540 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665880.636:5478): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7540 suid=74 rport=60574 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665880.636:5479): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7540 suid=74 rport=60574 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665880.699:5480): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60574 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665880.699:5481): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60574 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665880.708:5482): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.708:5483): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7540 suid=74 rport=60574 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665880.709:5484): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665880.710:5485): user pid=7539 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665880.710:5486): pid=7539 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=212 >type=USER_ROLE_CHANGE msg=audit(1362665880.841:5487): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665880.847:5488): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665880.852:5489): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665880.852:5490): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.853:5491): user pid=7542 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7542 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.854:5492): user pid=7542 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7542 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665880.854:5493): user pid=7542 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665880.900:5494): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665880.900:5495): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665880.900:5496): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665880.901:5497): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.901:5498): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7539 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.901:5499): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7539 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665880.901:5500): user pid=7539 uid=0 auid=0 ses=212 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7539 suid=0 rport=60574 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665883.940:5501): user pid=7549 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7549 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665883.940:5502): user pid=7549 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7549 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665883.941:5503): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7549 suid=74 rport=60575 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665883.941:5504): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7549 suid=74 rport=60575 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665884.005:5505): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60575 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665884.005:5506): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60575 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665884.011:5507): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665884.011:5508): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7549 suid=74 rport=60575 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665884.012:5509): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665884.013:5510): user pid=7548 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665884.013:5511): pid=7548 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=213 >type=USER_ROLE_CHANGE msg=audit(1362665884.141:5512): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665884.146:5513): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665884.151:5514): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665884.152:5515): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665884.152:5516): user pid=7551 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7551 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665884.153:5517): user pid=7551 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7551 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665884.154:5518): user pid=7551 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665884.203:5519): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665884.203:5520): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665884.204:5521): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665884.204:5522): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665884.204:5523): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7548 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665884.204:5524): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7548 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665884.204:5525): user pid=7548 uid=0 auid=0 ses=213 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7548 suid=0 rport=60575 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.252:5526): user pid=7558 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7558 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.253:5527): user pid=7558 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7558 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665887.255:5528): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7558 suid=74 rport=60577 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665887.256:5529): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7558 suid=74 rport=60577 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665887.318:5530): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60577 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665887.318:5531): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60577 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665887.325:5532): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.326:5533): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7558 suid=74 rport=60577 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665887.327:5534): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665887.328:5535): user pid=7557 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665887.328:5536): pid=7557 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=214 >type=USER_ROLE_CHANGE msg=audit(1362665887.479:5537): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665887.482:5538): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665887.483:5539): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665887.483:5540): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.484:5541): user pid=7560 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7560 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.484:5542): user pid=7560 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7560 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665887.485:5543): user pid=7560 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665887.536:5544): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665887.536:5545): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665887.537:5546): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665887.538:5547): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.538:5548): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7557 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.538:5549): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7557 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665887.538:5550): user pid=7557 uid=0 auid=0 ses=214 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7557 suid=0 rport=60577 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.596:5551): user pid=7569 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7569 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.596:5552): user pid=7569 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7569 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665890.597:5553): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7569 suid=74 rport=60578 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665890.597:5554): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7569 suid=74 rport=60578 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665890.662:5555): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60578 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665890.663:5556): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60578 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665890.671:5557): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.671:5558): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7569 suid=74 rport=60578 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665890.672:5559): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665890.672:5560): user pid=7568 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665890.673:5561): pid=7568 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=215 >type=USER_ROLE_CHANGE msg=audit(1362665890.807:5562): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665890.813:5563): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665890.813:5564): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665890.813:5565): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.815:5566): user pid=7571 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7571 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.815:5567): user pid=7571 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7571 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665890.816:5568): user pid=7571 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665890.867:5569): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665890.867:5570): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665890.867:5571): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665890.867:5572): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.868:5573): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7568 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.868:5574): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7568 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665890.868:5575): user pid=7568 uid=0 auid=0 ses=215 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7568 suid=0 rport=60578 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665893.912:5576): user pid=7578 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7578 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665893.913:5577): user pid=7578 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7578 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665893.914:5578): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7578 suid=74 rport=60579 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665893.914:5579): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7578 suid=74 rport=60579 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665893.976:5580): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60579 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665893.976:5581): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60579 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665893.984:5582): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665893.984:5583): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7578 suid=74 rport=60579 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665893.985:5584): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665893.986:5585): user pid=7577 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665893.986:5586): pid=7577 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=216 >type=USER_ROLE_CHANGE msg=audit(1362665894.118:5587): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665894.123:5588): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665894.128:5589): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665894.128:5590): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665894.129:5591): user pid=7580 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7580 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665894.129:5592): user pid=7580 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7580 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665894.131:5593): user pid=7580 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665894.183:5594): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665894.183:5595): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665894.183:5596): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665894.184:5597): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665894.184:5598): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7577 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665894.184:5599): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7577 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665894.184:5600): user pid=7577 uid=0 auid=0 ses=216 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7577 suid=0 rport=60579 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.236:5601): user pid=7590 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7590 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.236:5602): user pid=7590 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7590 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665897.236:5603): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7590 suid=74 rport=60580 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665897.237:5604): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7590 suid=74 rport=60580 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665897.301:5605): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60580 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665897.301:5606): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60580 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665897.310:5607): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.311:5608): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7590 suid=74 rport=60580 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665897.312:5609): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665897.312:5610): user pid=7589 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665897.312:5611): pid=7589 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=217 >type=USER_ROLE_CHANGE msg=audit(1362665897.443:5612): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665897.449:5613): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665897.455:5614): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665897.456:5615): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.456:5616): user pid=7592 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7592 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.457:5617): user pid=7592 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7592 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665897.457:5618): user pid=7592 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665897.506:5619): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665897.506:5620): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665897.507:5621): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665897.507:5622): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.507:5623): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7589 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.507:5624): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7589 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665897.507:5625): user pid=7589 uid=0 auid=0 ses=217 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7589 suid=0 rport=60580 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.561:5626): user pid=7601 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7601 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.561:5627): user pid=7601 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7601 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665900.564:5628): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7601 suid=74 rport=60584 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665900.564:5629): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7601 suid=74 rport=60584 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665900.629:5630): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60584 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665900.630:5631): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60584 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665900.639:5632): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.639:5633): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7601 suid=74 rport=60584 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665900.640:5634): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665900.641:5635): user pid=7600 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665900.641:5636): pid=7600 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=218 >type=USER_ROLE_CHANGE msg=audit(1362665900.772:5637): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665900.778:5638): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665900.783:5639): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665900.784:5640): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.785:5641): user pid=7603 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7603 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.785:5642): user pid=7603 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7603 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665900.786:5643): user pid=7603 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665900.832:5644): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665900.832:5645): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665900.832:5646): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665900.833:5647): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.833:5648): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7600 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.833:5649): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7600 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665900.833:5650): user pid=7600 uid=0 auid=0 ses=218 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7600 suid=0 rport=60584 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665903.887:5651): user pid=7615 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7615 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665903.887:5652): user pid=7615 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7615 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665903.889:5653): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7615 suid=74 rport=60586 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665903.889:5654): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7615 suid=74 rport=60586 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665903.953:5655): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60586 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665903.953:5656): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60586 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665903.961:5657): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665903.961:5658): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7615 suid=74 rport=60586 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665903.962:5659): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665903.962:5660): user pid=7614 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665903.963:5661): pid=7614 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=219 >type=USER_ROLE_CHANGE msg=audit(1362665904.100:5662): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665904.106:5663): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665904.112:5664): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665904.112:5665): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665904.114:5666): user pid=7617 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7617 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665904.114:5667): user pid=7617 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7617 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665904.115:5668): user pid=7617 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665904.155:5669): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665904.155:5670): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665904.156:5671): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665904.156:5672): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665904.156:5673): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7614 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665904.156:5674): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7614 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665904.156:5675): user pid=7614 uid=0 auid=0 ses=219 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7614 suid=0 rport=60586 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.206:5676): user pid=7627 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7627 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.206:5677): user pid=7627 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7627 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665907.207:5678): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7627 suid=74 rport=60588 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665907.207:5679): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7627 suid=74 rport=60588 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665907.274:5680): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60588 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665907.274:5681): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60588 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665907.282:5682): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.284:5683): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7627 suid=74 rport=60588 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665907.285:5684): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665907.285:5685): user pid=7626 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665907.286:5686): pid=7626 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=220 >type=USER_ROLE_CHANGE msg=audit(1362665907.424:5687): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665907.429:5688): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665907.429:5689): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665907.429:5690): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.430:5691): user pid=7633 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7633 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.430:5692): user pid=7633 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7633 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665907.431:5693): user pid=7633 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665907.479:5694): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665907.479:5695): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665907.481:5696): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665907.482:5697): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.482:5698): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7626 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.482:5699): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7626 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665907.482:5700): user pid=7626 uid=0 auid=0 ses=220 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7626 suid=0 rport=60588 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.538:5701): user pid=7645 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.538:5702): user pid=7645 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665910.539:5703): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7645 suid=74 rport=60591 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665910.540:5704): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7645 suid=74 rport=60591 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665910.603:5705): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60591 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665910.603:5706): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60591 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665910.611:5707): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.612:5708): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7645 suid=74 rport=60591 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665910.613:5709): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665910.613:5710): user pid=7644 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665910.614:5711): pid=7644 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=221 >type=USER_ROLE_CHANGE msg=audit(1362665910.744:5712): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665910.749:5713): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665910.750:5714): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665910.750:5715): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.751:5716): user pid=7647 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7647 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.751:5717): user pid=7647 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7647 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665910.752:5718): user pid=7647 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665910.798:5719): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665910.798:5720): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665910.798:5721): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665910.798:5722): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.798:5723): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7644 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.798:5724): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7644 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665910.799:5725): user pid=7644 uid=0 auid=0 ses=221 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7644 suid=0 rport=60591 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665913.836:5726): user pid=7654 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7654 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665913.836:5727): user pid=7654 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7654 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665913.838:5728): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7654 suid=74 rport=60592 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665913.838:5729): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7654 suid=74 rport=60592 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665913.900:5730): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60592 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665913.900:5731): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60592 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665913.907:5732): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665913.909:5733): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7654 suid=74 rport=60592 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665913.910:5734): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665913.910:5735): user pid=7653 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665913.910:5736): pid=7653 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=222 >type=USER_ROLE_CHANGE msg=audit(1362665914.039:5737): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665914.043:5738): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665914.048:5739): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665914.049:5740): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665914.049:5741): user pid=7656 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7656 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665914.050:5742): user pid=7656 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7656 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665914.050:5743): user pid=7656 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665914.098:5744): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665914.098:5745): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665914.099:5746): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665914.099:5747): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665914.099:5748): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7653 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665914.099:5749): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7653 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665914.099:5750): user pid=7653 uid=0 auid=0 ses=222 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7653 suid=0 rport=60592 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.138:5751): user pid=7663 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7663 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.139:5752): user pid=7663 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7663 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665917.139:5753): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7663 suid=74 rport=60593 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665917.139:5754): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7663 suid=74 rport=60593 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665917.202:5755): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60593 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665917.202:5756): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60593 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665917.210:5757): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.211:5758): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7663 suid=74 rport=60593 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665917.212:5759): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665917.212:5760): user pid=7662 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665917.212:5761): pid=7662 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=223 >type=USER_ROLE_CHANGE msg=audit(1362665917.345:5762): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665917.348:5763): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665917.354:5764): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665917.355:5765): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.356:5766): user pid=7665 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7665 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.356:5767): user pid=7665 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7665 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665917.356:5768): user pid=7665 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665917.403:5769): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665917.403:5770): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665917.403:5771): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665917.403:5772): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.404:5773): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7662 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.404:5774): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7662 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665917.404:5775): user pid=7662 uid=0 auid=0 ses=223 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7662 suid=0 rport=60593 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.443:5776): user pid=7672 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7672 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.443:5777): user pid=7672 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7672 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665920.444:5778): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7672 suid=74 rport=60595 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665920.444:5779): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7672 suid=74 rport=60595 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665920.508:5780): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60595 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665920.508:5781): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60595 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665920.515:5782): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.516:5783): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7672 suid=74 rport=60595 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665920.516:5784): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665920.517:5785): user pid=7671 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665920.517:5786): pid=7671 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=224 >type=USER_ROLE_CHANGE msg=audit(1362665920.645:5787): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665920.649:5788): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665920.654:5789): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665920.655:5790): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.655:5791): user pid=7674 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7674 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.656:5792): user pid=7674 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7674 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665920.657:5793): user pid=7674 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665920.705:5794): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665920.705:5795): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665920.705:5796): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665920.705:5797): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.706:5798): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7671 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.706:5799): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7671 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665920.706:5800): user pid=7671 uid=0 auid=0 ses=224 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7671 suid=0 rport=60595 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665923.749:5801): user pid=7681 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7681 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665923.749:5802): user pid=7681 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7681 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665923.750:5803): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7681 suid=74 rport=60596 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665923.750:5804): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7681 suid=74 rport=60596 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665923.818:5805): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60596 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665923.818:5806): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60596 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665923.826:5807): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665923.827:5808): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7681 suid=74 rport=60596 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665923.828:5809): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665923.828:5810): user pid=7680 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665923.828:5811): pid=7680 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=225 >type=USER_ROLE_CHANGE msg=audit(1362665923.953:5812): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665923.957:5813): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665923.962:5814): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665923.962:5815): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665923.964:5816): user pid=7683 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665923.964:5817): user pid=7683 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665923.964:5818): user pid=7683 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665924.016:5819): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665924.016:5820): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665924.017:5821): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665924.017:5822): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665924.017:5823): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7680 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665924.017:5824): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7680 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665924.017:5825): user pid=7680 uid=0 auid=0 ses=225 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7680 suid=0 rport=60596 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.062:5826): user pid=7690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7690 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.062:5827): user pid=7690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7690 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665927.065:5828): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7690 suid=74 rport=60598 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665927.065:5829): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7690 suid=74 rport=60598 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665927.127:5830): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60598 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665927.127:5831): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60598 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665927.134:5832): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.134:5833): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7690 suid=74 rport=60598 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665927.135:5834): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665927.136:5835): user pid=7689 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665927.136:5836): pid=7689 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=226 >type=USER_ROLE_CHANGE msg=audit(1362665927.264:5837): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665927.266:5838): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665927.267:5839): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665927.267:5840): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.268:5841): user pid=7692 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7692 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.268:5842): user pid=7692 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7692 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665927.269:5843): user pid=7692 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665927.322:5844): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665927.322:5845): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665927.322:5846): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665927.322:5847): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.323:5848): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7689 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.323:5849): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7689 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665927.323:5850): user pid=7689 uid=0 auid=0 ses=226 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7689 suid=0 rport=60598 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.367:5851): user pid=7699 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7699 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.368:5852): user pid=7699 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7699 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665930.368:5853): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7699 suid=74 rport=60600 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665930.369:5854): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7699 suid=74 rport=60600 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665930.433:5855): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60600 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665930.433:5856): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60600 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665930.440:5857): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.440:5858): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7699 suid=74 rport=60600 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665930.441:5859): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665930.442:5860): user pid=7698 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665930.442:5861): pid=7698 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=227 >type=USER_ROLE_CHANGE msg=audit(1362665930.571:5862): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665930.574:5863): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665930.579:5864): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665930.580:5865): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.581:5866): user pid=7701 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7701 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.581:5867): user pid=7701 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7701 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665930.582:5868): user pid=7701 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665930.625:5869): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665930.625:5870): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665930.626:5871): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665930.626:5872): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.626:5873): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7698 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.626:5874): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7698 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665930.626:5875): user pid=7698 uid=0 auid=0 ses=227 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7698 suid=0 rport=60600 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.674:5876): user pid=7708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7708 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.674:5877): user pid=7708 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7708 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665933.675:5878): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7708 suid=74 rport=60603 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665933.675:5879): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7708 suid=74 rport=60603 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665933.739:5880): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60603 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665933.740:5881): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60603 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665933.746:5882): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.747:5883): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7708 suid=74 rport=60603 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665933.748:5884): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665933.748:5885): user pid=7707 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665933.748:5886): pid=7707 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=228 >type=USER_ROLE_CHANGE msg=audit(1362665933.880:5887): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665933.885:5888): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665933.890:5889): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665933.890:5890): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.891:5891): user pid=7710 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7710 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.891:5892): user pid=7710 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7710 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665933.892:5893): user pid=7710 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665933.938:5894): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665933.939:5895): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665933.939:5896): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665933.940:5897): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.940:5898): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7707 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.940:5899): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7707 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665933.940:5900): user pid=7707 uid=0 auid=0 ses=228 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7707 suid=0 rport=60603 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665936.977:5901): user pid=7717 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7717 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665936.978:5902): user pid=7717 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7717 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665936.979:5903): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7717 suid=74 rport=60606 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665936.979:5904): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7717 suid=74 rport=60606 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665937.042:5905): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60606 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665937.042:5906): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60606 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665937.049:5907): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665937.050:5908): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7717 suid=74 rport=60606 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665937.051:5909): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665937.051:5910): user pid=7716 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665937.051:5911): pid=7716 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=229 >type=USER_ROLE_CHANGE msg=audit(1362665937.182:5912): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665937.186:5913): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665937.192:5914): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665937.192:5915): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665937.193:5916): user pid=7719 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7719 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665937.193:5917): user pid=7719 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7719 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665937.194:5918): user pid=7719 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665937.233:5919): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665937.234:5920): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665937.234:5921): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665937.235:5922): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665937.235:5923): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7716 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665937.235:5924): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7716 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665937.235:5925): user pid=7716 uid=0 auid=0 ses=229 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7716 suid=0 rport=60606 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.273:5926): user pid=7726 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7726 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.273:5927): user pid=7726 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7726 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665940.274:5928): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7726 suid=74 rport=60608 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665940.274:5929): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7726 suid=74 rport=60608 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665940.338:5930): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60608 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665940.338:5931): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60608 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665940.346:5932): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.347:5933): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7726 suid=74 rport=60608 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665940.348:5934): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665940.348:5935): user pid=7725 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665940.349:5936): pid=7725 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=230 >type=USER_ROLE_CHANGE msg=audit(1362665940.480:5937): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665940.486:5938): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665940.491:5939): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665940.491:5940): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.492:5941): user pid=7728 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7728 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.492:5942): user pid=7728 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7728 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665940.493:5943): user pid=7728 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665940.540:5944): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665940.540:5945): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665940.541:5946): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665940.541:5947): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.541:5948): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7725 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.541:5949): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7725 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665940.541:5950): user pid=7725 uid=0 auid=0 ses=230 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7725 suid=0 rport=60608 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.586:5951): user pid=7735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7735 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.586:5952): user pid=7735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7735 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665943.587:5953): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7735 suid=74 rport=60611 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665943.587:5954): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7735 suid=74 rport=60611 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665943.651:5955): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60611 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665943.651:5956): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60611 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665943.657:5957): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.658:5958): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7735 suid=74 rport=60611 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665943.659:5959): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665943.659:5960): user pid=7734 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665943.659:5961): pid=7734 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=231 >type=USER_ROLE_CHANGE msg=audit(1362665943.786:5962): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665943.790:5963): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665943.796:5964): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665943.796:5965): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.797:5966): user pid=7737 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7737 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.797:5967): user pid=7737 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7737 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665943.798:5968): user pid=7737 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665943.846:5969): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665943.846:5970): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665943.846:5971): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665943.846:5972): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.846:5973): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7734 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.846:5974): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7734 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665943.847:5975): user pid=7734 uid=0 auid=0 ses=231 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7734 suid=0 rport=60611 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665946.901:5976): user pid=7744 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7744 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665946.901:5977): user pid=7744 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7744 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665946.904:5978): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7744 suid=74 rport=60613 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665946.905:5979): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7744 suid=74 rport=60613 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665946.969:5980): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60613 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665946.969:5981): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60613 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665946.975:5982): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665946.976:5983): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7744 suid=74 rport=60613 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665946.977:5984): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665946.977:5985): user pid=7743 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665946.977:5986): pid=7743 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=232 >type=USER_ROLE_CHANGE msg=audit(1362665947.102:5987): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665947.105:5988): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665947.105:5989): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665947.105:5990): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665947.106:5991): user pid=7746 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7746 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665947.107:5992): user pid=7746 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7746 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665947.107:5993): user pid=7746 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665947.156:5994): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665947.157:5995): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665947.159:5996): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665947.159:5997): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665947.160:5998): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7743 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665947.160:5999): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7743 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665947.160:6000): user pid=7743 uid=0 auid=0 ses=232 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7743 suid=0 rport=60613 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.199:6001): user pid=7753 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7753 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.199:6002): user pid=7753 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7753 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665950.201:6003): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7753 suid=74 rport=60616 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665950.201:6004): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7753 suid=74 rport=60616 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665950.264:6005): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60616 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665950.264:6006): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60616 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665950.271:6007): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.272:6008): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7753 suid=74 rport=60616 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665950.274:6009): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665950.274:6010): user pid=7752 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665950.274:6011): pid=7752 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=233 >type=USER_ROLE_CHANGE msg=audit(1362665950.396:6012): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665950.401:6013): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665950.406:6014): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665950.406:6015): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.407:6016): user pid=7755 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7755 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.407:6017): user pid=7755 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7755 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665950.408:6018): user pid=7755 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665950.456:6019): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665950.456:6020): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665950.456:6021): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665950.457:6022): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.457:6023): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7752 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.457:6024): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7752 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665950.457:6025): user pid=7752 uid=0 auid=0 ses=233 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7752 suid=0 rport=60616 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.502:6026): user pid=7762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7762 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.502:6027): user pid=7762 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7762 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665953.503:6028): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7762 suid=74 rport=60619 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665953.503:6029): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7762 suid=74 rport=60619 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665953.565:6030): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60619 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665953.566:6031): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60619 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665953.574:6032): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.574:6033): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7762 suid=74 rport=60619 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665953.575:6034): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665953.576:6035): user pid=7761 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665953.576:6036): pid=7761 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=234 >type=USER_ROLE_CHANGE msg=audit(1362665953.704:6037): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665953.707:6038): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665953.712:6039): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665953.712:6040): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.713:6041): user pid=7764 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7764 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.713:6042): user pid=7764 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7764 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665953.714:6043): user pid=7764 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665953.761:6044): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665953.761:6045): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665953.762:6046): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665953.762:6047): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.762:6048): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7761 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.762:6049): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7761 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665953.762:6050): user pid=7761 uid=0 auid=0 ses=234 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7761 suid=0 rport=60619 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665956.818:6051): user pid=7771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7771 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665956.818:6052): user pid=7771 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7771 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665956.819:6053): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7771 suid=74 rport=60622 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665956.819:6054): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7771 suid=74 rport=60622 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665956.882:6055): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60622 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665956.882:6056): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60622 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665956.891:6057): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665956.891:6058): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7771 suid=74 rport=60622 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665956.892:6059): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665956.893:6060): user pid=7770 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665956.893:6061): pid=7770 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=235 >type=USER_ROLE_CHANGE msg=audit(1362665957.034:6062): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665957.039:6063): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665957.044:6064): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665957.044:6065): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665957.046:6066): user pid=7773 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7773 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665957.046:6067): user pid=7773 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7773 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665957.047:6068): user pid=7773 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665957.092:6069): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665957.092:6070): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665957.093:6071): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665957.093:6072): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665957.093:6073): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7770 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665957.093:6074): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7770 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665957.093:6075): user pid=7770 uid=0 auid=0 ses=235 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7770 suid=0 rport=60622 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.132:6076): user pid=7780 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7780 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.132:6077): user pid=7780 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7780 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665960.133:6078): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7780 suid=74 rport=60625 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665960.133:6079): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7780 suid=74 rport=60625 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665960.196:6080): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60625 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665960.197:6081): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60625 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665960.204:6082): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.204:6083): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7780 suid=74 rport=60625 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665960.205:6084): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665960.205:6085): user pid=7779 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665960.205:6086): pid=7779 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=236 >type=USER_ROLE_CHANGE msg=audit(1362665960.328:6087): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665960.332:6088): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665960.336:6089): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665960.337:6090): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.337:6091): user pid=7782 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7782 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.337:6092): user pid=7782 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7782 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665960.338:6093): user pid=7782 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665960.389:6094): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665960.389:6095): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665960.390:6096): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665960.390:6097): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.390:6098): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7779 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.390:6099): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7779 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665960.390:6100): user pid=7779 uid=0 auid=0 ses=236 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7779 suid=0 rport=60625 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.431:6101): user pid=7789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7789 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.431:6102): user pid=7789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7789 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665963.431:6103): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7789 suid=74 rport=60629 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665963.431:6104): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7789 suid=74 rport=60629 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665963.496:6105): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60629 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665963.496:6106): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60629 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665963.505:6107): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.506:6108): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7789 suid=74 rport=60629 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665963.506:6109): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665963.507:6110): user pid=7788 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665963.507:6111): pid=7788 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=237 >type=USER_ROLE_CHANGE msg=audit(1362665963.637:6112): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665963.642:6113): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665963.647:6114): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665963.647:6115): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.648:6116): user pid=7791 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7791 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.648:6117): user pid=7791 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7791 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665963.649:6118): user pid=7791 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665963.701:6119): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665963.702:6120): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665963.702:6121): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665963.703:6122): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.703:6123): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7788 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.703:6124): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7788 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665963.703:6125): user pid=7788 uid=0 auid=0 ses=237 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7788 suid=0 rport=60629 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665966.744:6126): user pid=7798 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7798 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665966.744:6127): user pid=7798 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7798 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665966.747:6128): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7798 suid=74 rport=60631 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665966.748:6129): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7798 suid=74 rport=60631 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665966.810:6130): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60631 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665966.810:6131): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60631 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665966.820:6132): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665966.821:6133): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7798 suid=74 rport=60631 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665966.821:6134): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665966.822:6135): user pid=7797 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665966.822:6136): pid=7797 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=238 >type=USER_ROLE_CHANGE msg=audit(1362665966.949:6137): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665966.952:6138): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665966.953:6139): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665966.954:6140): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665966.955:6141): user pid=7800 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7800 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665966.955:6142): user pid=7800 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7800 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665966.956:6143): user pid=7800 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665967.005:6144): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665967.005:6145): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665967.006:6146): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665967.006:6147): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665967.007:6148): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7797 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665967.007:6149): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7797 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665967.007:6150): user pid=7797 uid=0 auid=0 ses=238 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7797 suid=0 rport=60631 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.054:6151): user pid=7807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7807 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.054:6152): user pid=7807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7807 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665970.054:6153): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7807 suid=74 rport=60633 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665970.055:6154): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7807 suid=74 rport=60633 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665970.120:6155): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60633 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665970.120:6156): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60633 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665970.128:6157): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.129:6158): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7807 suid=74 rport=60633 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665970.130:6159): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665970.130:6160): user pid=7806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665970.130:6161): pid=7806 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=239 >type=USER_ROLE_CHANGE msg=audit(1362665970.254:6162): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665970.258:6163): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665970.264:6164): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665970.264:6165): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.266:6166): user pid=7809 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7809 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.266:6167): user pid=7809 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7809 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665970.266:6168): user pid=7809 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665970.314:6169): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665970.314:6170): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665970.315:6171): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665970.315:6172): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.315:6173): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7806 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.315:6174): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7806 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665970.315:6175): user pid=7806 uid=0 auid=0 ses=239 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7806 suid=0 rport=60633 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.358:6176): user pid=7816 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7816 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.358:6177): user pid=7816 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7816 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665973.358:6178): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7816 suid=74 rport=60635 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665973.358:6179): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7816 suid=74 rport=60635 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665973.423:6180): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60635 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665973.423:6181): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60635 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665973.430:6182): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.431:6183): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7816 suid=74 rport=60635 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665973.432:6184): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665973.432:6185): user pid=7815 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665973.433:6186): pid=7815 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=240 >type=USER_ROLE_CHANGE msg=audit(1362665973.556:6187): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665973.559:6188): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665973.564:6189): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665973.564:6190): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.565:6191): user pid=7818 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7818 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.566:6192): user pid=7818 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7818 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665973.566:6193): user pid=7818 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665973.608:6194): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665973.608:6195): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665973.609:6196): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665973.609:6197): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.609:6198): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7815 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.609:6199): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7815 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665973.609:6200): user pid=7815 uid=0 auid=0 ses=240 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7815 suid=0 rport=60635 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.652:6201): user pid=7825 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7825 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.653:6202): user pid=7825 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7825 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665976.654:6203): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7825 suid=74 rport=60638 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665976.654:6204): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7825 suid=74 rport=60638 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665976.716:6205): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60638 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665976.716:6206): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60638 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665976.723:6207): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.725:6208): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7825 suid=74 rport=60638 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665976.726:6209): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665976.726:6210): user pid=7824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665976.726:6211): pid=7824 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=241 >type=USER_ROLE_CHANGE msg=audit(1362665976.859:6212): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665976.864:6213): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665976.869:6214): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665976.869:6215): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.870:6216): user pid=7827 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7827 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.870:6217): user pid=7827 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7827 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665976.871:6218): user pid=7827 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665976.919:6219): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665976.919:6220): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665976.920:6221): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665976.920:6222): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.920:6223): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7824 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.920:6224): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7824 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665976.920:6225): user pid=7824 uid=0 auid=0 ses=241 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7824 suid=0 rport=60638 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665979.961:6226): user pid=7834 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7834 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665979.962:6227): user pid=7834 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7834 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665979.962:6228): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7834 suid=74 rport=60640 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665979.962:6229): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7834 suid=74 rport=60640 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665980.027:6230): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60640 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665980.027:6231): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60640 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665980.034:6232): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665980.035:6233): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7834 suid=74 rport=60640 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665980.036:6234): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665980.036:6235): user pid=7833 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665980.036:6236): pid=7833 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=242 >type=USER_ROLE_CHANGE msg=audit(1362665980.167:6237): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665980.170:6238): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665980.175:6239): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665980.176:6240): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665980.176:6241): user pid=7836 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7836 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665980.177:6242): user pid=7836 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7836 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665980.178:6243): user pid=7836 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665980.222:6244): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665980.222:6245): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665980.223:6246): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665980.223:6247): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665980.223:6248): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7833 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665980.223:6249): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7833 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665980.223:6250): user pid=7833 uid=0 auid=0 ses=242 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7833 suid=0 rport=60640 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.264:6251): user pid=7843 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7843 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.264:6252): user pid=7843 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7843 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665983.265:6253): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7843 suid=74 rport=60643 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665983.265:6254): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7843 suid=74 rport=60643 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665983.328:6255): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60643 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665983.328:6256): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60643 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665983.335:6257): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.336:6258): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7843 suid=74 rport=60643 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665983.336:6259): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665983.337:6260): user pid=7842 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665983.337:6261): pid=7842 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=243 >type=USER_ROLE_CHANGE msg=audit(1362665983.467:6262): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665983.472:6263): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665983.477:6264): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665983.477:6265): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.478:6266): user pid=7845 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7845 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.478:6267): user pid=7845 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7845 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665983.479:6268): user pid=7845 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665983.523:6269): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665983.524:6270): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665983.524:6271): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665983.524:6272): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.524:6273): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7842 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.525:6274): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7842 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665983.525:6275): user pid=7842 uid=0 auid=0 ses=243 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7842 suid=0 rport=60643 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.568:6276): user pid=7852 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7852 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.569:6277): user pid=7852 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7852 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665986.569:6278): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7852 suid=74 rport=60645 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665986.569:6279): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7852 suid=74 rport=60645 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665986.632:6280): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60645 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665986.632:6281): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60645 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665986.640:6282): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.644:6283): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7852 suid=74 rport=60645 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665986.645:6284): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665986.646:6285): user pid=7851 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665986.646:6286): pid=7851 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=244 >type=USER_ROLE_CHANGE msg=audit(1362665986.771:6287): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665986.774:6288): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665986.776:6289): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665986.776:6290): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.777:6291): user pid=7854 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7854 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.777:6292): user pid=7854 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7854 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665986.778:6293): user pid=7854 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665986.827:6294): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665986.828:6295): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665986.828:6296): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665986.828:6297): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.828:6298): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7851 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.829:6299): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7851 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665986.829:6300): user pid=7851 uid=0 auid=0 ses=244 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7851 suid=0 rport=60645 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665989.869:6301): user pid=7861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7861 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665989.869:6302): user pid=7861 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7861 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665989.872:6303): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7861 suid=74 rport=60647 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665989.872:6304): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7861 suid=74 rport=60647 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665989.936:6305): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60647 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665989.936:6306): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60647 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665989.943:6307): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665989.944:6308): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7861 suid=74 rport=60647 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665989.945:6309): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665989.945:6310): user pid=7860 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665989.945:6311): pid=7860 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=245 >type=USER_ROLE_CHANGE msg=audit(1362665990.070:6312): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665990.075:6313): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665990.080:6314): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665990.080:6315): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665990.081:6316): user pid=7863 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7863 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665990.081:6317): user pid=7863 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7863 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665990.082:6318): user pid=7863 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665990.133:6319): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665990.133:6320): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665990.133:6321): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665990.134:6322): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665990.134:6323): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7860 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665990.134:6324): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7860 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665990.134:6325): user pid=7860 uid=0 auid=0 ses=245 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7860 suid=0 rport=60647 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.181:6326): user pid=7870 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7870 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.181:6327): user pid=7870 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7870 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665993.182:6328): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7870 suid=74 rport=60651 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665993.182:6329): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7870 suid=74 rport=60651 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665993.250:6330): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60651 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665993.250:6331): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60651 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665993.257:6332): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.258:6333): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7870 suid=74 rport=60651 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665993.258:6334): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665993.259:6335): user pid=7869 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665993.259:6336): pid=7869 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=246 >type=USER_ROLE_CHANGE msg=audit(1362665993.391:6337): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665993.393:6338): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665993.399:6339): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665993.400:6340): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.401:6341): user pid=7872 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7872 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.401:6342): user pid=7872 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7872 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665993.402:6343): user pid=7872 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665993.452:6344): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665993.453:6345): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665993.453:6346): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665993.453:6347): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.453:6348): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7869 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.454:6349): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7869 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665993.454:6350): user pid=7869 uid=0 auid=0 ses=246 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7869 suid=0 rport=60651 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.500:6351): user pid=7879 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7879 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.500:6352): user pid=7879 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7879 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665996.501:6353): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7879 suid=74 rport=60654 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665996.501:6354): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7879 suid=74 rport=60654 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665996.568:6355): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60654 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665996.568:6356): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60654 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665996.577:6357): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.577:6358): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7879 suid=74 rport=60654 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665996.578:6359): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665996.579:6360): user pid=7878 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665996.579:6361): pid=7878 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=247 >type=USER_ROLE_CHANGE msg=audit(1362665996.713:6362): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665996.717:6363): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362665996.722:6364): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362665996.722:6365): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.723:6366): user pid=7881 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7881 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.723:6367): user pid=7881 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7881 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362665996.724:6368): user pid=7881 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665996.768:6369): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362665996.768:6370): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362665996.769:6371): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362665996.769:6372): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.769:6373): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7878 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.769:6374): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7878 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665996.769:6375): user pid=7878 uid=0 auid=0 ses=247 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7878 suid=0 rport=60654 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665999.815:6376): user pid=7888 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7888 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362665999.815:6377): user pid=7888 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7888 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665999.816:6378): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7888 suid=74 rport=60657 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362665999.816:6379): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7888 suid=74 rport=60657 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665999.879:6380): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60657 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665999.879:6381): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60657 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362665999.887:6382): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362665999.888:6383): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7888 suid=74 rport=60657 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362665999.889:6384): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362665999.889:6385): user pid=7887 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362665999.889:6386): pid=7887 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=248 >type=USER_ROLE_CHANGE msg=audit(1362666000.019:6387): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666000.025:6388): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666000.026:6389): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666000.027:6390): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666000.028:6391): user pid=7890 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7890 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666000.028:6392): user pid=7890 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7890 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666000.029:6393): user pid=7890 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666000.076:6394): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666000.077:6395): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666000.077:6396): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666000.077:6397): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666000.077:6398): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7887 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666000.078:6399): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7887 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666000.078:6400): user pid=7887 uid=0 auid=0 ses=248 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7887 suid=0 rport=60657 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.119:6401): user pid=7897 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7897 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.119:6402): user pid=7897 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7897 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666003.120:6403): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7897 suid=74 rport=60660 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666003.120:6404): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7897 suid=74 rport=60660 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666003.182:6405): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60660 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666003.182:6406): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60660 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666003.188:6407): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.188:6408): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7897 suid=74 rport=60660 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666003.189:6409): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666003.189:6410): user pid=7896 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666003.190:6411): pid=7896 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=249 >type=USER_ROLE_CHANGE msg=audit(1362666003.316:6412): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666003.321:6413): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666003.326:6414): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666003.326:6415): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.327:6416): user pid=7899 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7899 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.327:6417): user pid=7899 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7899 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666003.327:6418): user pid=7899 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666003.376:6419): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666003.376:6420): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666003.377:6421): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666003.377:6422): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.377:6423): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7896 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.377:6424): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7896 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666003.377:6425): user pid=7896 uid=0 auid=0 ses=249 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7896 suid=0 rport=60660 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.421:6426): user pid=7906 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7906 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.421:6427): user pid=7906 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7906 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666006.422:6428): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7906 suid=74 rport=60663 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666006.422:6429): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7906 suid=74 rport=60663 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666006.483:6430): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60663 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666006.483:6431): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60663 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666006.491:6432): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.493:6433): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7906 suid=74 rport=60663 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666006.494:6434): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666006.495:6435): user pid=7905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666006.495:6436): pid=7905 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=250 >type=USER_ROLE_CHANGE msg=audit(1362666006.628:6437): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666006.631:6438): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666006.631:6439): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666006.632:6440): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.633:6441): user pid=7908 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7908 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.633:6442): user pid=7908 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7908 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666006.634:6443): user pid=7908 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666006.681:6444): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666006.682:6445): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666006.682:6446): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666006.682:6447): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.682:6448): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7905 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.683:6449): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7905 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666006.683:6450): user pid=7905 uid=0 auid=0 ses=250 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7905 suid=0 rport=60663 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.724:6451): user pid=7915 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7915 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.724:6452): user pid=7915 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7915 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666009.725:6453): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7915 suid=74 rport=60666 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666009.725:6454): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7915 suid=74 rport=60666 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666009.788:6455): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60666 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666009.788:6456): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60666 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666009.795:6457): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.797:6458): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7915 suid=74 rport=60666 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666009.798:6459): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666009.798:6460): user pid=7914 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666009.798:6461): pid=7914 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=251 >type=USER_ROLE_CHANGE msg=audit(1362666009.920:6462): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666009.925:6463): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666009.930:6464): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666009.931:6465): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.932:6466): user pid=7917 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7917 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.932:6467): user pid=7917 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7917 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666009.932:6468): user pid=7917 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666009.976:6469): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666009.976:6470): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666009.977:6471): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666009.977:6472): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.977:6473): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7914 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.977:6474): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7914 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666009.977:6475): user pid=7914 uid=0 auid=0 ses=251 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7914 suid=0 rport=60666 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.039:6476): user pid=7924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7924 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.039:6477): user pid=7924 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7924 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666013.040:6478): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7924 suid=74 rport=60668 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666013.040:6479): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7924 suid=74 rport=60668 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666013.104:6480): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60668 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666013.104:6481): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60668 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666013.113:6482): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.113:6483): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7924 suid=74 rport=60668 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666013.114:6484): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666013.115:6485): user pid=7923 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666013.115:6486): pid=7923 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=252 >type=USER_ROLE_CHANGE msg=audit(1362666013.246:6487): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666013.249:6488): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666013.256:6489): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666013.256:6490): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.257:6491): user pid=7926 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7926 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.257:6492): user pid=7926 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7926 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666013.258:6493): user pid=7926 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666013.301:6494): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666013.301:6495): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666013.302:6496): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666013.302:6497): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.302:6498): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7923 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.302:6499): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7923 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666013.302:6500): user pid=7923 uid=0 auid=0 ses=252 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7923 suid=0 rport=60668 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362666014.713:6501): user pid=7932 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=497 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362666014.810:6502): user pid=7932 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=497 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362666014.811:6503): user pid=7932 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=497 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.351:6504): user pid=7941 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7941 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.351:6505): user pid=7941 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7941 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666016.352:6506): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7941 suid=74 rport=60669 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666016.353:6507): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7941 suid=74 rport=60669 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666016.416:6508): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60669 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666016.416:6509): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60669 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666016.426:6510): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.427:6511): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7941 suid=74 rport=60669 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666016.428:6512): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666016.428:6513): user pid=7940 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666016.428:6514): pid=7940 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=253 >type=USER_ROLE_CHANGE msg=audit(1362666016.565:6515): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666016.571:6516): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666016.577:6517): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666016.577:6518): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.578:6519): user pid=7943 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7943 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.578:6520): user pid=7943 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7943 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666016.579:6521): user pid=7943 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666016.629:6522): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666016.629:6523): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666016.630:6524): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666016.630:6525): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.630:6526): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7940 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.630:6527): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7940 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666016.630:6528): user pid=7940 uid=0 auid=0 ses=253 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7940 suid=0 rport=60669 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.690:6529): user pid=7956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7956 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.690:6530): user pid=7956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7956 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666019.694:6531): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7956 suid=74 rport=60670 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666019.694:6532): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7956 suid=74 rport=60670 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666019.760:6533): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60670 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666019.760:6534): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60670 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666019.769:6535): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.770:6536): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7956 suid=74 rport=60670 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666019.771:6537): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666019.771:6538): user pid=7955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666019.771:6539): pid=7955 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=254 >type=USER_ROLE_CHANGE msg=audit(1362666019.900:6540): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666019.904:6541): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666019.905:6542): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666019.905:6543): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.905:6544): user pid=7958 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7958 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.906:6545): user pid=7958 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7958 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666019.906:6546): user pid=7958 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666019.953:6547): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666019.953:6548): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666019.954:6549): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666019.954:6550): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.955:6551): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.955:6552): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666019.955:6553): user pid=7955 uid=0 auid=0 ses=254 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7955 suid=0 rport=60670 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.017:6554): user pid=7967 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7967 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.017:6555): user pid=7967 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7967 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666023.020:6556): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7967 suid=74 rport=60671 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666023.021:6557): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7967 suid=74 rport=60671 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666023.085:6558): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60671 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666023.085:6559): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60671 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666023.094:6560): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.095:6561): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7967 suid=74 rport=60671 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666023.095:6562): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666023.096:6563): user pid=7966 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666023.096:6564): pid=7966 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=255 >type=USER_ROLE_CHANGE msg=audit(1362666023.240:6565): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666023.244:6566): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666023.249:6567): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666023.249:6568): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.250:6569): user pid=7970 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7970 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.250:6570): user pid=7970 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7970 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666023.251:6571): user pid=7970 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666023.304:6572): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666023.304:6573): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666023.305:6574): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666023.305:6575): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.305:6576): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.305:6577): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666023.305:6578): user pid=7966 uid=0 auid=0 ses=255 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7966 suid=0 rport=60671 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.355:6579): user pid=7978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7978 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.355:6580): user pid=7978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7978 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666026.356:6581): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7978 suid=74 rport=60672 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666026.356:6582): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7978 suid=74 rport=60672 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666026.433:6583): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60672 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666026.433:6584): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60672 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666026.443:6585): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.443:6586): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7978 suid=74 rport=60672 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666026.445:6587): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666026.445:6588): user pid=7977 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666026.445:6589): pid=7977 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=256 >type=USER_ROLE_CHANGE msg=audit(1362666026.589:6590): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666026.593:6591): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666026.599:6592): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666026.600:6593): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.601:6594): user pid=7981 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.601:6595): user pid=7981 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666026.602:6596): user pid=7981 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666026.651:6597): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666026.651:6598): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666026.652:6599): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666026.652:6600): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.652:6601): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7977 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.652:6602): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7977 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666026.652:6603): user pid=7977 uid=0 auid=0 ses=256 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7977 suid=0 rport=60672 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.709:6604): user pid=7991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.710:6605): user pid=7991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666029.710:6606): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=7991 suid=74 rport=60673 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666029.710:6607): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=7991 suid=74 rport=60673 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666029.774:6608): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60673 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666029.774:6609): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60673 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666029.783:6610): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.786:6611): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7991 suid=74 rport=60673 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666029.787:6612): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666029.787:6613): user pid=7990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666029.787:6614): pid=7990 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=257 >type=USER_ROLE_CHANGE msg=audit(1362666029.923:6615): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666029.927:6616): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666029.927:6617): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666029.927:6618): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.929:6619): user pid=7993 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7993 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.929:6620): user pid=7993 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7993 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666029.929:6621): user pid=7993 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666029.979:6622): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666029.980:6623): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666029.980:6624): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666029.980:6625): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.980:6626): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=7990 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.980:6627): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=7990 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666029.980:6628): user pid=7990 uid=0 auid=0 ses=257 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=7990 suid=0 rport=60673 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.045:6629): user pid=8005 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8005 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.045:6630): user pid=8005 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8005 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666033.049:6631): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8005 suid=74 rport=60674 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666033.049:6632): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8005 suid=74 rport=60674 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666033.113:6633): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60674 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666033.113:6634): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60674 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666033.121:6635): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.122:6636): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8005 suid=74 rport=60674 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666033.123:6637): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666033.123:6638): user pid=8004 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666033.123:6639): pid=8004 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=258 >type=USER_ROLE_CHANGE msg=audit(1362666033.255:6640): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666033.258:6641): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666033.263:6642): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666033.264:6643): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.265:6644): user pid=8007 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8007 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.265:6645): user pid=8007 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8007 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666033.266:6646): user pid=8007 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666033.315:6647): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666033.315:6648): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666033.316:6649): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666033.316:6650): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.316:6651): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8004 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.316:6652): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8004 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666033.316:6653): user pid=8004 uid=0 auid=0 ses=258 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8004 suid=0 rport=60674 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.369:6654): user pid=8017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8017 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.369:6655): user pid=8017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8017 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666036.370:6656): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8017 suid=74 rport=60675 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666036.371:6657): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8017 suid=74 rport=60675 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666036.432:6658): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60675 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666036.432:6659): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60675 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666036.439:6660): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.442:6661): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8017 suid=74 rport=60675 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666036.443:6662): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666036.443:6663): user pid=8016 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666036.444:6664): pid=8016 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=259 >type=USER_ROLE_CHANGE msg=audit(1362666036.577:6665): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666036.581:6666): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666036.587:6667): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666036.587:6668): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.588:6669): user pid=8019 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8019 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.588:6670): user pid=8019 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8019 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666036.589:6671): user pid=8019 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666036.634:6672): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666036.634:6673): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666036.635:6674): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666036.635:6675): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.635:6676): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8016 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.635:6677): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8016 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666036.635:6678): user pid=8016 uid=0 auid=0 ses=259 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8016 suid=0 rport=60675 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.689:6679): user pid=8042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8042 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.689:6680): user pid=8042 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8042 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666039.690:6681): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8042 suid=74 rport=60676 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666039.690:6682): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8042 suid=74 rport=60676 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666039.753:6683): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60676 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666039.753:6684): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60676 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666039.761:6685): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.762:6686): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8042 suid=74 rport=60676 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666039.763:6687): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666039.763:6688): user pid=8041 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666039.763:6689): pid=8041 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=260 >type=USER_ROLE_CHANGE msg=audit(1362666039.900:6690): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666039.906:6691): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666039.911:6692): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666039.912:6693): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.913:6694): user pid=8044 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8044 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.913:6695): user pid=8044 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8044 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666039.913:6696): user pid=8044 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666039.957:6697): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666039.957:6698): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666039.958:6699): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666039.958:6700): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.958:6701): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8041 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.958:6702): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8041 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666039.958:6703): user pid=8041 uid=0 auid=0 ses=260 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8041 suid=0 rport=60676 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_CHAUTHTOK msg=audit(1362666042.336:6704): user pid=8051 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="nova" exe="/usr/sbin/usermod" hostname=? addr=? terminal=? res=success' >type=USER_CHAUTHTOK msg=audit(1362666042.341:6705): user pid=8051 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="nova" exe="/usr/sbin/usermod" hostname=? addr=? terminal=? res=success' >type=USER_CHAUTHTOK msg=audit(1362666042.454:6706): user pid=8057 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to group acct="nova" exe="/usr/sbin/usermod" hostname=? addr=? terminal=? res=success' >type=USER_CHAUTHTOK msg=audit(1362666042.454:6707): user pid=8057 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user to shadow group acct="nova" exe="/usr/sbin/usermod" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.011:6708): user pid=8068 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8068 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.011:6709): user pid=8068 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8068 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666043.013:6710): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8068 suid=74 rport=60677 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666043.013:6711): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8068 suid=74 rport=60677 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666043.078:6712): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60677 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666043.078:6713): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60677 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666043.087:6714): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.088:6715): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8068 suid=74 rport=60677 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666043.089:6716): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666043.090:6717): user pid=8067 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666043.090:6718): pid=8067 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=261 >type=USER_ROLE_CHANGE msg=audit(1362666043.226:6719): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666043.230:6720): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666043.236:6721): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666043.236:6722): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.237:6723): user pid=8070 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8070 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.237:6724): user pid=8070 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8070 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666043.238:6725): user pid=8070 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666043.277:6726): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666043.277:6727): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666043.278:6728): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666043.278:6729): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.278:6730): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8067 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.278:6731): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8067 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666043.278:6732): user pid=8067 uid=0 auid=0 ses=261 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8067 suid=0 rport=60677 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.321:6733): user pid=8077 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8077 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.321:6734): user pid=8077 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8077 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666046.322:6735): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8077 suid=74 rport=60678 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666046.322:6736): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8077 suid=74 rport=60678 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666046.390:6737): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60678 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666046.391:6738): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60678 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666046.398:6739): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.401:6740): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8077 suid=74 rport=60678 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666046.401:6741): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666046.402:6742): user pid=8076 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666046.402:6743): pid=8076 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=262 >type=USER_ROLE_CHANGE msg=audit(1362666046.531:6744): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666046.535:6745): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666046.537:6746): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666046.537:6747): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.538:6748): user pid=8079 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8079 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.538:6749): user pid=8079 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8079 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666046.539:6750): user pid=8079 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666046.581:6751): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666046.582:6752): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666046.585:6753): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666046.585:6754): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.586:6755): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8076 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.586:6756): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8076 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666046.586:6757): user pid=8076 uid=0 auid=0 ses=262 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8076 suid=0 rport=60678 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.633:6758): user pid=8089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8089 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.634:6759): user pid=8089 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8089 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666049.634:6760): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8089 suid=74 rport=60680 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666049.635:6761): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8089 suid=74 rport=60680 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666049.699:6762): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60680 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666049.699:6763): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60680 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666049.706:6764): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.707:6765): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8089 suid=74 rport=60680 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666049.708:6766): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666049.708:6767): user pid=8088 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666049.708:6768): pid=8088 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=263 >type=USER_ROLE_CHANGE msg=audit(1362666049.836:6769): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666049.841:6770): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666049.842:6771): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666049.842:6772): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.843:6773): user pid=8091 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8091 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.844:6774): user pid=8091 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8091 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666049.844:6775): user pid=8091 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666049.891:6776): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666049.892:6777): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666049.892:6778): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666049.892:6779): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.892:6780): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8088 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.892:6781): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8088 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666049.893:6782): user pid=8088 uid=0 auid=0 ses=263 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8088 suid=0 rport=60680 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666052.941:6783): user pid=8098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8098 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666052.941:6784): user pid=8098 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8098 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666052.942:6785): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8098 suid=74 rport=60681 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666052.942:6786): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8098 suid=74 rport=60681 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666053.006:6787): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60681 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666053.006:6788): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60681 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666053.014:6789): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666053.015:6790): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8098 suid=74 rport=60681 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666053.016:6791): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666053.016:6792): user pid=8097 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666053.016:6793): pid=8097 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=264 >type=USER_ROLE_CHANGE msg=audit(1362666053.150:6794): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666053.154:6795): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666053.159:6796): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666053.159:6797): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666053.160:6798): user pid=8101 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8101 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666053.160:6799): user pid=8101 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8101 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666053.162:6800): user pid=8101 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666053.207:6801): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666053.207:6802): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666053.207:6803): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666053.208:6804): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666053.208:6805): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8097 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666053.208:6806): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8097 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666053.208:6807): user pid=8097 uid=0 auid=0 ses=264 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8097 suid=0 rport=60681 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666055.998:6808): table=filter family=2 entries=43 >type=SYSCALL msg=audit(1362666055.998:6808): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=9dff90 items=0 ppid=6445 pid=8321 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666056.281:6809): user pid=8327 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8327 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.281:6810): user pid=8327 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8327 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666056.284:6811): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8327 suid=74 rport=60682 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666056.284:6812): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8327 suid=74 rport=60682 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666056.349:6813): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60682 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666056.349:6814): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60682 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666056.356:6815): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.358:6816): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8327 suid=74 rport=60682 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666056.358:6817): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666056.359:6818): user pid=8326 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666056.359:6819): pid=8326 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=265 >type=USER_ROLE_CHANGE msg=audit(1362666056.499:6820): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666056.504:6821): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666056.511:6822): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666056.511:6823): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.512:6824): user pid=8329 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8329 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.512:6825): user pid=8329 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8329 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666056.513:6826): user pid=8329 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666056.543:6827): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666056.543:6828): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666056.544:6829): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666056.544:6830): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.544:6831): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8326 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.544:6832): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8326 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666056.544:6833): user pid=8326 uid=0 auid=0 ses=265 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8326 suid=0 rport=60682 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_START msg=audit(1362666058.144:6834): user pid=8347 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666058.145:6835): user pid=8347 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666058.148:6836): user pid=8347 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666058.149:6837): user pid=8347 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666058.451:6838): user pid=8366 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666058.451:6839): user pid=8366 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666058.455:6840): user pid=8366 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666058.455:6841): user pid=8366 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666058.703:6842): user pid=8389 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666058.703:6843): user pid=8389 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666058.707:6844): user pid=8389 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666058.707:6845): user pid=8389 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666058.940:6846): user pid=8412 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666058.940:6847): user pid=8412 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666058.943:6848): user pid=8412 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666058.943:6849): user pid=8412 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666059.022:6850): user pid=8419 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666059.023:6851): user pid=8419 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666059.024:6852): user pid=8419 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666059.174:6853): user pid=8438 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666059.178:6854): user pid=8438 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666059.182:6855): user pid=8438 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666059.182:6856): user pid=8438 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666059.184:6857): user pid=8419 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666059.184:6858): user pid=8419 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666059.201:6859): user pid=8443 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666059.201:6860): user pid=8443 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666059.201:6861): user pid=8443 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666059.458:6862): table=filter family=2 entries=44 >type=SYSCALL msg=audit(1362666059.458:6862): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=8e5b30 items=0 ppid=8445 pid=8459 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666059.470:6863): user pid=8443 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666059.470:6864): user pid=8443 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666059.480:6865): user pid=8466 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666059.480:6866): user pid=8466 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666059.483:6867): user pid=8466 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666059.483:6868): user pid=8466 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666059.532:6869): user pid=8467 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666059.532:6870): user pid=8467 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666059.533:6871): user pid=8467 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666059.694:6872): user pid=8486 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8486 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666059.694:6873): user pid=8486 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8486 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666059.698:6874): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8486 suid=74 rport=60683 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666059.699:6875): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8486 suid=74 rport=60683 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666059.797:6876): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60683 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666059.797:6877): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60683 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_END msg=audit(1362666059.813:6878): user pid=8467 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666059.813:6879): user pid=8467 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666059.827:6880): user pid=8499 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666059.827:6881): user pid=8499 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666059.828:6882): user pid=8499 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_ACCT msg=audit(1362666059.836:6883): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666059.836:6884): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8486 suid=74 rport=60683 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666059.837:6885): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666059.838:6886): user pid=8482 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666059.838:6887): pid=8482 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=266 >type=USER_ROLE_CHANGE msg=audit(1362666060.041:6888): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666060.046:6889): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666060.052:6890): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666060.053:6891): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666060.054:6892): user pid=8508 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8508 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666060.054:6893): user pid=8508 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8508 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666060.055:6894): user pid=8508 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666060.091:6895): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666060.092:6896): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666060.092:6897): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666060.092:6898): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666060.092:6899): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8482 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666060.092:6900): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8482 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666060.092:6901): user pid=8482 uid=0 auid=0 ses=266 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8482 suid=0 rport=60683 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666060.145:6902): table=mangle family=2 entries=10 >type=SYSCALL msg=audit(1362666060.145:6902): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1db2710 items=0 ppid=8503 pid=8513 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666060.160:6903): user pid=8499 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666060.160:6904): user pid=8499 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666060.222:6905): user pid=8514 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666060.222:6906): user pid=8514 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666060.223:6907): user pid=8514 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666060.367:6908): user pid=8514 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666060.367:6909): user pid=8514 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666060.383:6910): user pid=8517 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666060.383:6911): user pid=8517 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666060.383:6912): user pid=8517 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=ANOM_ABEND msg=audit(1362666060.512:6913): auid=0 uid=0 gid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 pid=8544 comm="pkcheck" sig=6 >type=NETFILTER_CFG msg=audit(1362666060.553:6914): table=nat family=2 entries=25 >type=SYSCALL msg=audit(1362666060.553:6914): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1b81e70 items=0 ppid=8520 pid=8546 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666060.560:6915): user pid=8517 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666060.560:6916): user pid=8517 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666060.579:6917): user pid=8549 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666060.580:6918): user pid=8549 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666060.580:6919): user pid=8549 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666060.735:6920): user pid=8549 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666060.736:6921): user pid=8549 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666060.748:6922): user pid=8553 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666060.748:6923): user pid=8553 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666060.748:6924): user pid=8553 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666060.879:6925): table=filter family=2 entries=56 >type=SYSCALL msg=audit(1362666060.879:6925): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=20692a0 items=0 ppid=8554 pid=8555 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666060.886:6926): user pid=8553 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666060.886:6927): user pid=8553 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666060.896:6928): user pid=8557 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666060.896:6929): user pid=8557 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666060.896:6930): user pid=8557 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666061.029:6931): user pid=8557 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666061.029:6932): user pid=8557 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666061.040:6933): user pid=8560 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666061.040:6934): user pid=8560 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666061.040:6935): user pid=8560 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666061.166:6936): table=mangle family=2 entries=13 >type=SYSCALL msg=audit(1362666061.166:6936): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=95d8e0 items=0 ppid=8561 pid=8564 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666061.172:6937): user pid=8560 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666061.172:6938): user pid=8560 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666061.183:6939): user pid=8565 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666061.183:6940): user pid=8565 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666061.183:6941): user pid=8565 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666061.317:6942): user pid=8565 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666061.317:6943): user pid=8565 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666061.327:6944): user pid=8568 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666061.327:6945): user pid=8568 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666061.327:6946): user pid=8568 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666061.604:6947): table=nat family=2 entries=41 >type=SYSCALL msg=audit(1362666061.604:6947): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=2358030 items=0 ppid=8569 pid=8570 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666061.613:6948): user pid=8568 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666061.613:6949): user pid=8568 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666061.624:6950): user pid=8575 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206164647220616464203136392E3235342E3136392E3235342F33322073636F7065206C696E6B20646576206C6F terminal=? res=success' >type=CRED_ACQ msg=audit(1362666061.625:6951): user pid=8575 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666061.625:6952): user pid=8575 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666061.774:6953): user pid=8575 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666061.775:6954): user pid=8575 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666061.788:6955): user pid=8579 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666061.789:6956): user pid=8579 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666061.789:6957): user pid=8579 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666061.928:6958): user pid=8579 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666061.928:6959): user pid=8579 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666061.939:6960): user pid=8587 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666061.941:6961): user pid=8587 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666061.941:6962): user pid=8587 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666062.086:6963): table=filter family=2 entries=56 >type=SYSCALL msg=audit(1362666062.086:6963): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=204f2a0 items=0 ppid=8588 pid=8589 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666062.094:6964): user pid=8587 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666062.095:6965): user pid=8587 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666062.114:6966): user pid=8591 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666062.124:6967): user pid=8591 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666062.124:6968): user pid=8591 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666062.262:6969): user pid=8591 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666062.262:6970): user pid=8591 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666062.274:6971): user pid=8594 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666062.274:6972): user pid=8594 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666062.275:6973): user pid=8594 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666062.404:6974): table=mangle family=2 entries=13 >type=SYSCALL msg=audit(1362666062.404:6974): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=e7e8e0 items=0 ppid=8595 pid=8596 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666062.413:6975): user pid=8594 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666062.413:6976): user pid=8594 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666062.424:6977): user pid=8597 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666062.424:6978): user pid=8597 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666062.424:6979): user pid=8597 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666062.562:6980): user pid=8597 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666062.562:6981): user pid=8597 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666062.573:6982): user pid=8602 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666062.573:6983): user pid=8602 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666062.573:6984): user pid=8602 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666062.705:6985): table=nat family=2 entries=43 >type=SYSCALL msg=audit(1362666062.705:6985): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1017fe0 items=0 ppid=8603 pid=8604 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666062.713:6986): user pid=8602 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666062.713:6987): user pid=8602 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.156:6988): user pid=8611 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8611 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.156:6989): user pid=8611 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8611 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666063.159:6990): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8611 suid=74 rport=60692 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666063.160:6991): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8611 suid=74 rport=60692 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666063.223:6992): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60692 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666063.223:6993): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60692 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666063.231:6994): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.232:6995): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8611 suid=74 rport=60692 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666063.233:6996): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666063.233:6997): user pid=8609 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666063.233:6998): pid=8609 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=267 >type=USER_ROLE_CHANGE msg=audit(1362666063.383:6999): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666063.388:7000): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666063.394:7001): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666063.394:7002): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.396:7003): user pid=8614 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8614 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.396:7004): user pid=8614 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8614 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666063.397:7005): user pid=8614 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666063.439:7006): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666063.439:7007): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666063.440:7008): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666063.440:7009): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.440:7010): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8609 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.440:7011): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8609 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666063.440:7012): user pid=8609 uid=0 auid=0 ses=267 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8609 suid=0 rport=60692 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.500:7013): user pid=8658 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8658 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.501:7014): user pid=8658 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8658 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666066.501:7015): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8658 suid=74 rport=60697 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666066.501:7016): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8658 suid=74 rport=60697 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666066.571:7017): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60697 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666066.571:7018): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60697 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666066.580:7019): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.582:7020): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8658 suid=74 rport=60697 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666066.583:7021): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666066.583:7022): user pid=8657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666066.583:7023): pid=8657 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=268 >type=USER_ROLE_CHANGE msg=audit(1362666066.718:7024): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666066.721:7025): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666066.722:7026): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666066.723:7027): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.724:7028): user pid=8683 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.724:7029): user pid=8683 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666066.725:7030): user pid=8683 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666066.768:7031): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666066.769:7032): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666066.769:7033): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666066.769:7034): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.769:7035): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8657 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.769:7036): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8657 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.770:7037): user pid=8657 uid=0 auid=0 ses=268 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8657 suid=0 rport=60697 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.797:7038): user pid=8706 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8706 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.797:7039): user pid=8706 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8706 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666066.798:7040): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=8706 suid=74 rport=60698 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666066.798:7041): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=8706 suid=74 rport=60698 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666066.861:7042): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60698 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666066.861:7043): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60698 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666066.871:7044): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666066.872:7045): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8706 suid=74 rport=60698 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666066.873:7046): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666066.873:7047): user pid=8702 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666066.873:7048): pid=8702 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=269 >type=USER_ROLE_CHANGE msg=audit(1362666067.007:7049): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666067.009:7050): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666067.010:7051): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666067.011:7052): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666067.012:7053): user pid=8760 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8760 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666067.012:7054): user pid=8760 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8760 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666067.013:7055): user pid=8760 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666067.042:7056): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666067.042:7057): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666067.042:7058): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666067.042:7059): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666067.042:7060): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=8702 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666067.043:7061): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=8702 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666067.043:7062): user pid=8702 uid=0 auid=0 ses=269 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=8702 suid=0 rport=60698 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.085:7063): user pid=9181 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9181 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.085:7064): user pid=9181 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9181 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666070.086:7065): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9181 suid=74 rport=60699 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666070.086:7066): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9181 suid=74 rport=60699 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666070.151:7067): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60699 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666070.151:7068): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60699 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666070.160:7069): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.160:7070): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9181 suid=74 rport=60699 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666070.161:7071): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666070.161:7072): user pid=9175 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666070.162:7073): pid=9175 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=270 >type=USER_ROLE_CHANGE msg=audit(1362666070.288:7074): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666070.294:7075): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666070.295:7076): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666070.295:7077): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.297:7078): user pid=9233 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9233 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.297:7079): user pid=9233 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9233 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666070.298:7080): user pid=9233 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666070.328:7081): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666070.328:7082): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666070.329:7083): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666070.329:7084): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.329:7085): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9175 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.329:7086): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9175 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.329:7087): user pid=9175 uid=0 auid=0 ses=270 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9175 suid=0 rport=60699 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.358:7088): user pid=9257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9257 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.358:7089): user pid=9257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9257 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666070.358:7090): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9257 suid=74 rport=60700 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666070.359:7091): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9257 suid=74 rport=60700 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666070.422:7092): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60700 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666070.422:7093): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60700 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666070.432:7094): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.433:7095): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9257 suid=74 rport=60700 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666070.433:7096): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666070.434:7097): user pid=9252 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666070.434:7098): pid=9252 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=271 >type=USER_ROLE_CHANGE msg=audit(1362666070.571:7099): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666070.574:7100): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666070.582:7101): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666070.582:7102): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.583:7103): user pid=9262 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9262 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.584:7104): user pid=9262 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9262 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666070.584:7105): user pid=9262 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666070.624:7106): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666070.624:7107): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666070.624:7108): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666070.624:7109): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.624:7110): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9252 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.624:7111): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9252 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666070.625:7112): user pid=9252 uid=0 auid=0 ses=271 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9252 suid=0 rport=60700 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.689:7113): user pid=9278 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9278 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.690:7114): user pid=9278 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9278 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666073.690:7115): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9278 suid=74 rport=60701 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666073.690:7116): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9278 suid=74 rport=60701 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666073.753:7117): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60701 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666073.753:7118): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60701 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666073.763:7119): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.764:7120): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9278 suid=74 rport=60701 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666073.765:7121): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666073.765:7122): user pid=9277 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666073.765:7123): pid=9277 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=272 >type=USER_ROLE_CHANGE msg=audit(1362666073.902:7124): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666073.907:7125): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666073.908:7126): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666073.908:7127): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.910:7128): user pid=9280 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9280 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.910:7129): user pid=9280 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9280 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666073.911:7130): user pid=9280 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666073.961:7131): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666073.961:7132): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666073.962:7133): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666073.962:7134): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.962:7135): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9277 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.962:7136): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9277 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666073.962:7137): user pid=9277 uid=0 auid=0 ses=272 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9277 suid=0 rport=60701 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.021:7138): user pid=9287 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.021:7139): user pid=9287 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666077.024:7140): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9287 suid=74 rport=60702 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666077.025:7141): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9287 suid=74 rport=60702 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666077.089:7142): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60702 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666077.089:7143): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60702 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666077.097:7144): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.097:7145): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9287 suid=74 rport=60702 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666077.098:7146): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666077.099:7147): user pid=9286 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666077.099:7148): pid=9286 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=273 >type=USER_ROLE_CHANGE msg=audit(1362666077.225:7149): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666077.228:7150): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666077.230:7151): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666077.230:7152): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.231:7153): user pid=9289 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9289 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.231:7154): user pid=9289 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9289 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666077.232:7155): user pid=9289 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666077.273:7156): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666077.273:7157): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666077.274:7158): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666077.274:7159): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.274:7160): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9286 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.274:7161): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9286 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666077.274:7162): user pid=9286 uid=0 auid=0 ses=273 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9286 suid=0 rport=60702 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.315:7163): user pid=9296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9296 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.315:7164): user pid=9296 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9296 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666080.317:7165): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9296 suid=74 rport=60703 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666080.317:7166): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9296 suid=74 rport=60703 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666080.380:7167): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60703 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666080.380:7168): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60703 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666080.386:7169): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.387:7170): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9296 suid=74 rport=60703 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666080.388:7171): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666080.389:7172): user pid=9295 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666080.389:7173): pid=9295 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=274 >type=USER_ROLE_CHANGE msg=audit(1362666080.516:7174): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666080.519:7175): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666080.524:7176): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666080.524:7177): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.526:7178): user pid=9298 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9298 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.526:7179): user pid=9298 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9298 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666080.526:7180): user pid=9298 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666080.579:7181): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666080.580:7182): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666080.580:7183): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666080.580:7184): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.580:7185): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9295 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.581:7186): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9295 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666080.581:7187): user pid=9295 uid=0 auid=0 ses=274 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9295 suid=0 rport=60703 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.627:7188): user pid=9305 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9305 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.627:7189): user pid=9305 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9305 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666083.628:7190): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9305 suid=74 rport=60704 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666083.628:7191): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9305 suid=74 rport=60704 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666083.692:7192): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60704 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666083.692:7193): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60704 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666083.701:7194): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.702:7195): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9305 suid=74 rport=60704 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666083.703:7196): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666083.703:7197): user pid=9304 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666083.703:7198): pid=9304 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=275 >type=USER_ROLE_CHANGE msg=audit(1362666083.841:7199): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666083.844:7200): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666083.850:7201): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666083.850:7202): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.851:7203): user pid=9307 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9307 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.851:7204): user pid=9307 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9307 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666083.852:7205): user pid=9307 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666083.903:7206): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666083.903:7207): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666083.903:7208): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666083.903:7209): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.903:7210): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9304 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.904:7211): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9304 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666083.904:7212): user pid=9304 uid=0 auid=0 ses=275 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9304 suid=0 rport=60704 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666086.945:7213): user pid=9314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9314 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666086.945:7214): user pid=9314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9314 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666086.947:7215): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9314 suid=74 rport=60705 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666086.948:7216): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9314 suid=74 rport=60705 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666087.010:7217): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60705 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666087.010:7218): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60705 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666087.018:7219): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666087.019:7220): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9314 suid=74 rport=60705 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666087.020:7221): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666087.020:7222): user pid=9313 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666087.020:7223): pid=9313 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=276 >type=USER_ROLE_CHANGE msg=audit(1362666087.153:7224): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666087.157:7225): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666087.162:7226): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666087.162:7227): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666087.163:7228): user pid=9316 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9316 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666087.163:7229): user pid=9316 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9316 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666087.164:7230): user pid=9316 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666087.213:7231): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666087.213:7232): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666087.213:7233): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666087.213:7234): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666087.213:7235): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9313 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666087.214:7236): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9313 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666087.214:7237): user pid=9313 uid=0 auid=0 ses=276 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9313 suid=0 rport=60705 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.260:7238): user pid=9323 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9323 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.261:7239): user pid=9323 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9323 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666090.261:7240): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9323 suid=74 rport=60706 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666090.261:7241): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9323 suid=74 rport=60706 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666090.324:7242): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60706 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666090.324:7243): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60706 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666090.331:7244): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.334:7245): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9323 suid=74 rport=60706 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666090.335:7246): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666090.335:7247): user pid=9322 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666090.335:7248): pid=9322 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=277 >type=USER_ROLE_CHANGE msg=audit(1362666090.466:7249): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666090.470:7250): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666090.471:7251): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666090.471:7252): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.472:7253): user pid=9325 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9325 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.472:7254): user pid=9325 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9325 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666090.473:7255): user pid=9325 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666090.522:7256): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666090.522:7257): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666090.522:7258): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666090.522:7259): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.522:7260): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9322 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.523:7261): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9322 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666090.523:7262): user pid=9322 uid=0 auid=0 ses=277 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9322 suid=0 rport=60706 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.564:7263): user pid=9332 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9332 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.564:7264): user pid=9332 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9332 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666093.564:7265): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9332 suid=74 rport=60707 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666093.564:7266): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9332 suid=74 rport=60707 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666093.627:7267): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60707 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666093.627:7268): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60707 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666093.635:7269): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.635:7270): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9332 suid=74 rport=60707 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666093.636:7271): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666093.637:7272): user pid=9331 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666093.637:7273): pid=9331 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=278 >type=USER_ROLE_CHANGE msg=audit(1362666093.772:7274): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666093.777:7275): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666093.782:7276): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666093.782:7277): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.783:7278): user pid=9334 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9334 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.783:7279): user pid=9334 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9334 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666093.784:7280): user pid=9334 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666093.834:7281): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666093.834:7282): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666093.835:7283): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666093.835:7284): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.835:7285): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9331 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.835:7286): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9331 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666093.835:7287): user pid=9331 uid=0 auid=0 ses=278 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9331 suid=0 rport=60707 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666096.875:7288): user pid=9341 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9341 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666096.875:7289): user pid=9341 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9341 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666096.879:7290): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9341 suid=74 rport=60708 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666096.879:7291): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9341 suid=74 rport=60708 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666096.943:7292): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60708 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666096.943:7293): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60708 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666096.950:7294): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666096.950:7295): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9341 suid=74 rport=60708 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666096.951:7296): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666096.952:7297): user pid=9340 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666096.952:7298): pid=9340 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=279 >type=USER_ROLE_CHANGE msg=audit(1362666097.088:7299): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666097.092:7300): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666097.093:7301): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666097.093:7302): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666097.094:7303): user pid=9343 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9343 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666097.094:7304): user pid=9343 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9343 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666097.095:7305): user pid=9343 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666097.151:7306): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666097.151:7307): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666097.152:7308): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666097.152:7309): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666097.152:7310): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9340 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666097.152:7311): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9340 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666097.152:7312): user pid=9340 uid=0 auid=0 ses=279 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9340 suid=0 rport=60708 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.197:7313): user pid=9350 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9350 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.197:7314): user pid=9350 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9350 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666100.198:7315): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9350 suid=74 rport=60709 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666100.198:7316): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9350 suid=74 rport=60709 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666100.261:7317): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60709 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666100.261:7318): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60709 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666100.268:7319): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.269:7320): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9350 suid=74 rport=60709 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666100.270:7321): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666100.270:7322): user pid=9349 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666100.270:7323): pid=9349 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=280 >type=USER_ROLE_CHANGE msg=audit(1362666100.397:7324): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666100.400:7325): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666100.405:7326): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666100.405:7327): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.407:7328): user pid=9352 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.407:7329): user pid=9352 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666100.407:7330): user pid=9352 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666100.454:7331): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666100.454:7332): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666100.455:7333): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666100.455:7334): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.455:7335): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9349 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.455:7336): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9349 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666100.455:7337): user pid=9349 uid=0 auid=0 ses=280 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9349 suid=0 rport=60709 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.526:7338): user pid=9359 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9359 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.526:7339): user pid=9359 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9359 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666103.527:7340): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9359 suid=74 rport=60710 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666103.527:7341): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9359 suid=74 rport=60710 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666103.590:7342): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60710 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666103.590:7343): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60710 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666103.599:7344): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.599:7345): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9359 suid=74 rport=60710 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666103.600:7346): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666103.601:7347): user pid=9358 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666103.601:7348): pid=9358 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=281 >type=USER_ROLE_CHANGE msg=audit(1362666103.734:7349): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666103.738:7350): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666103.743:7351): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666103.744:7352): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.745:7353): user pid=9361 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.745:7354): user pid=9361 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9361 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666103.746:7355): user pid=9361 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666103.792:7356): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666103.792:7357): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666103.793:7358): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666103.793:7359): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.793:7360): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9358 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.793:7361): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9358 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666103.793:7362): user pid=9358 uid=0 auid=0 ses=281 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9358 suid=0 rport=60710 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666106.856:7363): user pid=9368 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9368 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666106.856:7364): user pid=9368 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9368 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666106.857:7365): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9368 suid=74 rport=60711 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666106.857:7366): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9368 suid=74 rport=60711 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666106.925:7367): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60711 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666106.925:7368): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60711 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666106.935:7369): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666106.936:7370): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9368 suid=74 rport=60711 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666106.937:7371): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666106.937:7372): user pid=9367 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666106.937:7373): pid=9367 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=282 >type=USER_ROLE_CHANGE msg=audit(1362666107.068:7374): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666107.072:7375): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666107.077:7376): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666107.077:7377): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666107.078:7378): user pid=9370 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9370 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666107.078:7379): user pid=9370 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9370 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666107.079:7380): user pid=9370 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666107.127:7381): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666107.127:7382): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666107.128:7383): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666107.128:7384): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666107.128:7385): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9367 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666107.128:7386): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9367 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666107.128:7387): user pid=9367 uid=0 auid=0 ses=282 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9367 suid=0 rport=60711 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=MAC_CONFIG_CHANGE msg=audit(1362666107.498:7388): bool=httpd_can_network_connect val=1 old_val=0 auid=0 ses=159 >type=SYSCALL msg=audit(1362666107.498:7388): arch=c000003e syscall=1 success=yes exit=2 a0=4 a1=7fffa64bb070 a2=2 a3=0 items=0 ppid=9272 pid=9273 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=159 comm="setsebool" exe="/usr/sbin/setsebool" subj=unconfined_u:unconfined_r:setsebool_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666110.191:7389): user pid=9380 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9380 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.191:7390): user pid=9380 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9380 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666110.195:7391): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9380 suid=74 rport=60713 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666110.195:7392): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9380 suid=74 rport=60713 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666110.257:7393): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60713 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666110.257:7394): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60713 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666110.265:7395): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.266:7396): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9380 suid=74 rport=60713 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666110.266:7397): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666110.267:7398): user pid=9379 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666110.267:7399): pid=9379 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=283 >type=USER_ROLE_CHANGE msg=audit(1362666110.417:7400): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666110.421:7401): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666110.426:7402): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666110.426:7403): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.427:7404): user pid=9382 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9382 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.427:7405): user pid=9382 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9382 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666110.428:7406): user pid=9382 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666110.468:7407): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666110.468:7408): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666110.469:7409): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666110.469:7410): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.469:7411): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9379 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.469:7412): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9379 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666110.469:7413): user pid=9379 uid=0 auid=0 ses=283 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9379 suid=0 rport=60713 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.521:7414): user pid=9389 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9389 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.521:7415): user pid=9389 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9389 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666113.524:7416): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9389 suid=74 rport=60714 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666113.524:7417): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9389 suid=74 rport=60714 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666113.590:7418): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60714 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666113.590:7419): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60714 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666113.599:7420): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.600:7421): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9389 suid=74 rport=60714 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666113.600:7422): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666113.601:7423): user pid=9388 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666113.601:7424): pid=9388 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=284 >type=USER_ROLE_CHANGE msg=audit(1362666113.740:7425): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666113.743:7426): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666113.750:7427): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666113.750:7428): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.751:7429): user pid=9392 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9392 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.751:7430): user pid=9392 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9392 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666113.752:7431): user pid=9392 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666113.784:7432): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666113.784:7433): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666113.784:7434): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666113.785:7435): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.785:7436): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9388 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.785:7437): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9388 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666113.785:7438): user pid=9388 uid=0 auid=0 ses=284 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9388 suid=0 rport=60714 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666114.072:7439): table=filter family=2 entries=56 >type=SYSCALL msg=audit(1362666114.072:7439): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1bf3240 items=0 ppid=8952 pid=9399 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=159 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666116.828:7440): user pid=9407 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9407 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666116.828:7441): user pid=9407 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9407 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666116.831:7442): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9407 suid=74 rport=60716 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666116.831:7443): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9407 suid=74 rport=60716 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666116.894:7444): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60716 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666116.894:7445): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60716 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666116.903:7446): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666116.904:7447): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9407 suid=74 rport=60716 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666116.905:7448): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666116.905:7449): user pid=9406 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666116.905:7450): pid=9406 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=285 >type=USER_ROLE_CHANGE msg=audit(1362666117.045:7451): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666117.048:7452): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666117.054:7453): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666117.054:7454): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666117.055:7455): user pid=9409 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9409 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666117.055:7456): user pid=9409 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9409 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666117.056:7457): user pid=9409 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666117.101:7458): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666117.102:7459): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666117.102:7460): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666117.102:7461): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666117.102:7462): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9406 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666117.102:7463): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9406 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666117.103:7464): user pid=9406 uid=0 auid=0 ses=285 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9406 suid=0 rport=60716 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362666117.349:7465): user pid=9414 uid=0 auid=0 ses=159 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=496 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362666117.392:7466): user pid=9414 uid=0 auid=0 ses=159 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=496 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362666117.393:7467): user pid=9414 uid=0 auid=0 ses=159 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=496 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362666117.458:7468): user pid=9419 uid=0 auid=0 ses=159 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=497 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.158:7469): user pid=9480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9480 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.158:7470): user pid=9480 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9480 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666120.159:7471): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9480 suid=74 rport=60717 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666120.160:7472): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9480 suid=74 rport=60717 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666120.222:7473): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60717 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666120.222:7474): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60717 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666120.230:7475): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.230:7476): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9480 suid=74 rport=60717 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666120.231:7477): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666120.231:7478): user pid=9479 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666120.231:7479): pid=9479 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=286 >type=USER_ROLE_CHANGE msg=audit(1362666120.373:7480): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666120.378:7481): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666120.384:7482): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666120.384:7483): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.385:7484): user pid=9482 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9482 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.386:7485): user pid=9482 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9482 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666120.386:7486): user pid=9482 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666120.431:7487): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666120.432:7488): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666120.432:7489): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666120.432:7490): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.432:7491): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9479 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.433:7492): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9479 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666120.433:7493): user pid=9479 uid=0 auid=0 ses=286 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9479 suid=0 rport=60717 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.483:7494): user pid=9489 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9489 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.484:7495): user pid=9489 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9489 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666123.487:7496): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9489 suid=74 rport=60727 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666123.488:7497): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9489 suid=74 rport=60727 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666123.551:7498): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60727 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666123.551:7499): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60727 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666123.559:7500): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.560:7501): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9489 suid=74 rport=60727 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666123.561:7502): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666123.561:7503): user pid=9488 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666123.561:7504): pid=9488 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=287 >type=USER_ROLE_CHANGE msg=audit(1362666123.694:7505): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666123.697:7506): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666123.702:7507): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666123.703:7508): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.704:7509): user pid=9491 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9491 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.704:7510): user pid=9491 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9491 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666123.704:7511): user pid=9491 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666123.749:7512): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666123.749:7513): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666123.750:7514): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666123.750:7515): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.750:7516): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9488 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.750:7517): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9488 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666123.750:7518): user pid=9488 uid=0 auid=0 ses=287 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9488 suid=0 rport=60727 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666126.802:7519): user pid=9498 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9498 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666126.802:7520): user pid=9498 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9498 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666126.803:7521): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9498 suid=74 rport=60728 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666126.803:7522): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9498 suid=74 rport=60728 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666126.865:7523): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60728 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666126.865:7524): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60728 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666126.873:7525): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666126.873:7526): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9498 suid=74 rport=60728 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666126.874:7527): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666126.874:7528): user pid=9497 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666126.874:7529): pid=9497 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=288 >type=USER_ROLE_CHANGE msg=audit(1362666127.015:7530): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666127.020:7531): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666127.020:7532): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666127.020:7533): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666127.022:7534): user pid=9500 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9500 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666127.022:7535): user pid=9500 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9500 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666127.023:7536): user pid=9500 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666127.055:7537): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666127.055:7538): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666127.055:7539): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666127.055:7540): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666127.056:7541): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9497 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666127.056:7542): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9497 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666127.056:7543): user pid=9497 uid=0 auid=0 ses=288 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9497 suid=0 rport=60728 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.099:7544): user pid=9507 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9507 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.099:7545): user pid=9507 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9507 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666130.099:7546): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9507 suid=74 rport=60729 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666130.099:7547): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9507 suid=74 rport=60729 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666130.162:7548): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60729 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666130.162:7549): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60729 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666130.169:7550): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.170:7551): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9507 suid=74 rport=60729 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666130.171:7552): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666130.171:7553): user pid=9506 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666130.171:7554): pid=9506 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=289 >type=USER_ROLE_CHANGE msg=audit(1362666130.306:7555): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666130.310:7556): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666130.312:7557): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666130.313:7558): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.314:7559): user pid=9509 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9509 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.314:7560): user pid=9509 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9509 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666130.315:7561): user pid=9509 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666130.366:7562): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666130.366:7563): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666130.366:7564): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666130.366:7565): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.367:7566): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9506 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.367:7567): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9506 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666130.367:7568): user pid=9506 uid=0 auid=0 ses=289 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9506 suid=0 rport=60729 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.411:7569): user pid=9516 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9516 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.412:7570): user pid=9516 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9516 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666133.412:7571): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9516 suid=74 rport=60730 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666133.412:7572): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9516 suid=74 rport=60730 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666133.478:7573): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60730 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666133.478:7574): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60730 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666133.487:7575): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.487:7576): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9516 suid=74 rport=60730 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666133.488:7577): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666133.488:7578): user pid=9515 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666133.488:7579): pid=9515 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=290 >type=USER_ROLE_CHANGE msg=audit(1362666133.623:7580): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666133.628:7581): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666133.634:7582): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666133.634:7583): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.635:7584): user pid=9518 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9518 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.635:7585): user pid=9518 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9518 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666133.636:7586): user pid=9518 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666133.685:7587): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666133.686:7588): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666133.686:7589): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666133.686:7590): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.686:7591): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9515 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.686:7592): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9515 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666133.686:7593): user pid=9515 uid=0 auid=0 ses=290 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9515 suid=0 rport=60730 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666136.740:7594): user pid=9525 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9525 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666136.741:7595): user pid=9525 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9525 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666136.743:7596): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9525 suid=74 rport=60731 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666136.743:7597): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9525 suid=74 rport=60731 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666136.807:7598): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60731 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666136.807:7599): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60731 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666136.816:7600): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666136.817:7601): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9525 suid=74 rport=60731 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666136.818:7602): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666136.818:7603): user pid=9524 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666136.818:7604): pid=9524 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=291 >type=USER_ROLE_CHANGE msg=audit(1362666136.943:7605): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666136.946:7606): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666136.951:7607): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666136.952:7608): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666136.952:7609): user pid=9527 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9527 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666136.953:7610): user pid=9527 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9527 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666136.953:7611): user pid=9527 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666137.001:7612): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666137.001:7613): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666137.002:7614): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666137.002:7615): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666137.002:7616): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9524 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666137.002:7617): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9524 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666137.002:7618): user pid=9524 uid=0 auid=0 ses=291 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9524 suid=0 rport=60731 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.052:7619): user pid=9534 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9534 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.053:7620): user pid=9534 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9534 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666140.054:7621): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9534 suid=74 rport=60732 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666140.054:7622): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9534 suid=74 rport=60732 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666140.117:7623): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60732 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666140.117:7624): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60732 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666140.126:7625): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.127:7626): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9534 suid=74 rport=60732 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666140.127:7627): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666140.128:7628): user pid=9533 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666140.128:7629): pid=9533 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=292 >type=USER_ROLE_CHANGE msg=audit(1362666140.267:7630): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666140.270:7631): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666140.275:7632): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666140.276:7633): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.276:7634): user pid=9536 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9536 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.277:7635): user pid=9536 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9536 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666140.277:7636): user pid=9536 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666140.323:7637): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666140.323:7638): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666140.324:7639): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666140.324:7640): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.324:7641): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9533 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.324:7642): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9533 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666140.324:7643): user pid=9533 uid=0 auid=0 ses=292 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9533 suid=0 rport=60732 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.381:7644): user pid=9599 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9599 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.381:7645): user pid=9599 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9599 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666143.382:7646): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9599 suid=74 rport=60733 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666143.382:7647): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9599 suid=74 rport=60733 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666143.444:7648): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60733 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666143.444:7649): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60733 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666143.452:7650): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.454:7651): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9599 suid=74 rport=60733 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666143.455:7652): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666143.455:7653): user pid=9598 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666143.455:7654): pid=9598 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=293 >type=USER_ROLE_CHANGE msg=audit(1362666143.589:7655): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666143.593:7656): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666143.594:7657): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666143.594:7658): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.595:7659): user pid=9601 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9601 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.595:7660): user pid=9601 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9601 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666143.596:7661): user pid=9601 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666143.649:7662): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666143.649:7663): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666143.650:7664): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666143.650:7665): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.650:7666): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9598 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.650:7667): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9598 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.650:7668): user pid=9598 uid=0 auid=0 ses=293 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9598 suid=0 rport=60733 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.674:7669): user pid=9606 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9606 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.674:7670): user pid=9606 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9606 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666143.674:7671): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9606 suid=74 rport=60734 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666143.675:7672): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9606 suid=74 rport=60734 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666143.738:7673): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60734 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666143.738:7674): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60734 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666143.744:7675): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.745:7676): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9606 suid=74 rport=60734 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666143.746:7677): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666143.746:7678): user pid=9605 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666143.746:7679): pid=9605 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=294 >type=USER_ROLE_CHANGE msg=audit(1362666143.870:7680): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666143.872:7681): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666143.874:7682): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666143.874:7683): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.875:7684): user pid=9608 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9608 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.876:7685): user pid=9608 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9608 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666143.876:7686): user pid=9608 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666143.924:7687): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666143.924:7688): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666143.925:7689): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666143.925:7690): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.925:7691): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9605 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.925:7692): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9605 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.925:7693): user pid=9605 uid=0 auid=0 ses=294 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9605 suid=0 rport=60734 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.958:7694): user pid=9620 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9620 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666143.958:7695): user pid=9620 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9620 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666143.958:7696): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9620 suid=74 rport=60735 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666143.958:7697): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9620 suid=74 rport=60735 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666144.022:7698): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60735 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666144.022:7699): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60735 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666144.030:7700): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666144.031:7701): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9620 suid=74 rport=60735 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666144.032:7702): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666144.033:7703): user pid=9619 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666144.033:7704): pid=9619 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=295 >type=USER_ROLE_CHANGE msg=audit(1362666144.157:7705): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666144.159:7706): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666144.161:7707): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666144.161:7708): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666144.163:7709): user pid=9645 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666144.163:7710): user pid=9645 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9645 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666144.163:7711): user pid=9645 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666144.207:7712): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666144.207:7713): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666144.208:7714): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666144.208:7715): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666144.208:7716): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9619 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666144.208:7717): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9619 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666144.208:7718): user pid=9619 uid=0 auid=0 ses=295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9619 suid=0 rport=60735 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.277:7719): user pid=9928 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9928 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.277:7720): user pid=9928 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9928 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666147.280:7721): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9928 suid=74 rport=60736 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666147.280:7722): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9928 suid=74 rport=60736 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666147.348:7723): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60736 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666147.348:7724): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60736 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666147.355:7725): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.356:7726): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9928 suid=74 rport=60736 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666147.357:7727): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666147.357:7728): user pid=9927 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666147.357:7729): pid=9927 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=296 >type=USER_ROLE_CHANGE msg=audit(1362666147.483:7730): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666147.488:7731): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666147.494:7732): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666147.494:7733): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.496:7734): user pid=9930 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9930 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.496:7735): user pid=9930 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9930 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666147.496:7736): user pid=9930 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666147.540:7737): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666147.540:7738): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666147.540:7739): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666147.540:7740): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.541:7741): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9927 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.541:7742): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9927 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666147.541:7743): user pid=9927 uid=0 auid=0 ses=296 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9927 suid=0 rport=60736 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.590:7744): user pid=9946 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9946 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.590:7745): user pid=9946 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9946 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666150.592:7746): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9946 suid=74 rport=60737 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666150.592:7747): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9946 suid=74 rport=60737 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666150.664:7748): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60737 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666150.664:7749): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60737 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666150.673:7750): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.673:7751): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9946 suid=74 rport=60737 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666150.674:7752): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666150.674:7753): user pid=9945 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666150.675:7754): pid=9945 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=297 >type=USER_ROLE_CHANGE msg=audit(1362666150.814:7755): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666150.818:7756): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666150.826:7757): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666150.827:7758): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.828:7759): user pid=9948 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9948 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.828:7760): user pid=9948 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9948 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666150.829:7761): user pid=9948 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666150.874:7762): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666150.875:7763): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666150.875:7764): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666150.875:7765): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.875:7766): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9945 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.875:7767): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9945 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666150.875:7768): user pid=9945 uid=0 auid=0 ses=297 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9945 suid=0 rport=60737 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666153.922:7769): user pid=9955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666153.922:7770): user pid=9955 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9955 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666153.922:7771): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9955 suid=74 rport=60738 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666153.922:7772): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9955 suid=74 rport=60738 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666153.985:7773): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60738 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666153.985:7774): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60738 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666153.992:7775): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666153.993:7776): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9955 suid=74 rport=60738 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666153.994:7777): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666153.994:7778): user pid=9954 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666153.994:7779): pid=9954 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=298 >type=USER_ROLE_CHANGE msg=audit(1362666154.124:7780): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666154.129:7781): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666154.130:7782): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666154.130:7783): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666154.131:7784): user pid=9957 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666154.131:7785): user pid=9957 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666154.133:7786): user pid=9957 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666154.207:7787): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666154.207:7788): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666154.208:7789): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666154.208:7790): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666154.208:7791): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9954 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666154.208:7792): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9954 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666154.208:7793): user pid=9954 uid=0 auid=0 ses=298 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9954 suid=0 rport=60738 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.249:7794): user pid=9964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.249:7795): user pid=9964 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9964 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666157.253:7796): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9964 suid=74 rport=60739 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666157.253:7797): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9964 suid=74 rport=60739 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666157.318:7798): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60739 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666157.318:7799): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60739 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666157.324:7800): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.325:7801): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9964 suid=74 rport=60739 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666157.326:7802): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666157.326:7803): user pid=9963 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666157.327:7804): pid=9963 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=299 >type=USER_ROLE_CHANGE msg=audit(1362666157.453:7805): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666157.455:7806): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666157.457:7807): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666157.457:7808): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.459:7809): user pid=9966 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.459:7810): user pid=9966 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9966 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666157.459:7811): user pid=9966 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666157.512:7812): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666157.512:7813): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666157.513:7814): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666157.513:7815): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.513:7816): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9963 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.513:7817): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9963 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666157.513:7818): user pid=9963 uid=0 auid=0 ses=299 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9963 suid=0 rport=60739 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.557:7819): user pid=9973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9973 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.557:7820): user pid=9973 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9973 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666160.558:7821): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9973 suid=74 rport=60740 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666160.558:7822): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9973 suid=74 rport=60740 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666160.620:7823): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60740 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666160.621:7824): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60740 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666160.628:7825): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.629:7826): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9973 suid=74 rport=60740 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666160.630:7827): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666160.630:7828): user pid=9972 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666160.630:7829): pid=9972 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=300 >type=USER_ROLE_CHANGE msg=audit(1362666160.759:7830): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666160.764:7831): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666160.769:7832): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666160.769:7833): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.770:7834): user pid=9975 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9975 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.770:7835): user pid=9975 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9975 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666160.771:7836): user pid=9975 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666160.826:7837): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666160.826:7838): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666160.826:7839): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666160.826:7840): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.826:7841): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9972 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.826:7842): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9972 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666160.826:7843): user pid=9972 uid=0 auid=0 ses=300 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9972 suid=0 rport=60740 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666163.899:7844): user pid=9982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666163.900:7845): user pid=9982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666163.900:7846): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9982 suid=74 rport=60741 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666163.900:7847): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9982 suid=74 rport=60741 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666163.962:7848): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60741 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666163.962:7849): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60741 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666163.969:7850): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666163.970:7851): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9982 suid=74 rport=60741 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666163.971:7852): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666163.971:7853): user pid=9981 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666163.971:7854): pid=9981 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=301 >type=USER_ROLE_CHANGE msg=audit(1362666164.102:7855): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666164.105:7856): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666164.110:7857): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666164.110:7858): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666164.112:7859): user pid=9984 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9984 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666164.112:7860): user pid=9984 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9984 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666164.113:7861): user pid=9984 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666164.160:7862): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666164.160:7863): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666164.160:7864): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666164.160:7865): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666164.160:7866): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666164.161:7867): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9981 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666164.161:7868): user pid=9981 uid=0 auid=0 ses=301 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9981 suid=0 rport=60741 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.202:7869): user pid=9991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.202:7870): user pid=9991 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9991 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666167.203:7871): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=9991 suid=74 rport=60742 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666167.203:7872): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=9991 suid=74 rport=60742 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666167.268:7873): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60742 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666167.268:7874): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60742 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666167.276:7875): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.276:7876): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9991 suid=74 rport=60742 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666167.277:7877): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666167.277:7878): user pid=9990 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666167.277:7879): pid=9990 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=302 >type=USER_ROLE_CHANGE msg=audit(1362666167.408:7880): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666167.413:7881): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666167.419:7882): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666167.419:7883): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.421:7884): user pid=9993 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9993 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.421:7885): user pid=9993 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9993 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666167.421:7886): user pid=9993 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666167.453:7887): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666167.453:7888): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666167.453:7889): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666167.453:7890): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.454:7891): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9990 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.454:7892): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9990 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666167.454:7893): user pid=9990 uid=0 auid=0 ses=302 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9990 suid=0 rport=60742 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.512:7894): user pid=10000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.512:7895): user pid=10000 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10000 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666170.513:7896): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10000 suid=74 rport=60743 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666170.513:7897): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10000 suid=74 rport=60743 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666170.577:7898): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60743 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666170.577:7899): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60743 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666170.584:7900): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.584:7901): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10000 suid=74 rport=60743 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666170.585:7902): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666170.585:7903): user pid=9999 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666170.585:7904): pid=9999 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=303 >type=USER_ROLE_CHANGE msg=audit(1362666170.717:7905): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666170.721:7906): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666170.727:7907): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666170.727:7908): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.728:7909): user pid=10002 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10002 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.728:7910): user pid=10002 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10002 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666170.729:7911): user pid=10002 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666170.770:7912): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666170.770:7913): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666170.771:7914): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666170.771:7915): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.771:7916): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=9999 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.771:7917): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=9999 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666170.771:7918): user pid=9999 uid=0 auid=0 ses=303 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=9999 suid=0 rport=60743 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666173.813:7919): user pid=10009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666173.813:7920): user pid=10009 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10009 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666173.814:7921): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10009 suid=74 rport=60744 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666173.814:7922): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10009 suid=74 rport=60744 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666173.878:7923): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60744 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666173.878:7924): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60744 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666173.886:7925): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666173.886:7926): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10009 suid=74 rport=60744 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666173.887:7927): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666173.887:7928): user pid=10008 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666173.887:7929): pid=10008 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=304 >type=USER_ROLE_CHANGE msg=audit(1362666174.017:7930): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666174.022:7931): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666174.027:7932): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666174.027:7933): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666174.028:7934): user pid=10011 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10011 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666174.028:7935): user pid=10011 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10011 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666174.029:7936): user pid=10011 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666174.074:7937): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666174.074:7938): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666174.075:7939): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666174.075:7940): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666174.075:7941): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10008 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666174.075:7942): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10008 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666174.075:7943): user pid=10008 uid=0 auid=0 ses=304 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10008 suid=0 rport=60744 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.120:7944): user pid=10018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.120:7945): user pid=10018 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10018 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666177.124:7946): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10018 suid=74 rport=60745 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666177.124:7947): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10018 suid=74 rport=60745 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666177.186:7948): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60745 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666177.186:7949): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60745 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666177.194:7950): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.195:7951): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10018 suid=74 rport=60745 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666177.195:7952): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666177.196:7953): user pid=10017 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666177.196:7954): pid=10017 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=305 >type=USER_ROLE_CHANGE msg=audit(1362666177.323:7955): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666177.326:7956): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666177.327:7957): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666177.328:7958): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.329:7959): user pid=10020 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10020 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.329:7960): user pid=10020 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10020 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666177.330:7961): user pid=10020 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666177.376:7962): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666177.376:7963): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666177.376:7964): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666177.377:7965): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.377:7966): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10017 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.377:7967): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10017 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666177.377:7968): user pid=10017 uid=0 auid=0 ses=305 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10017 suid=0 rport=60745 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.421:7969): user pid=10027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.422:7970): user pid=10027 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10027 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666180.422:7971): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10027 suid=74 rport=60746 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666180.422:7972): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10027 suid=74 rport=60746 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666180.483:7973): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60746 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666180.483:7974): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60746 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666180.490:7975): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.491:7976): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10027 suid=74 rport=60746 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666180.492:7977): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666180.493:7978): user pid=10026 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666180.493:7979): pid=10026 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=306 >type=USER_ROLE_CHANGE msg=audit(1362666180.615:7980): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666180.618:7981): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666180.624:7982): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666180.624:7983): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.626:7984): user pid=10029 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10029 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.626:7985): user pid=10029 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10029 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666180.626:7986): user pid=10029 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666180.672:7987): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666180.672:7988): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666180.673:7989): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666180.673:7990): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.673:7991): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10026 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.673:7992): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10026 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666180.673:7993): user pid=10026 uid=0 auid=0 ses=306 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10026 suid=0 rport=60746 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.723:7994): user pid=10036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.723:7995): user pid=10036 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10036 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666183.724:7996): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10036 suid=74 rport=60747 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666183.724:7997): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10036 suid=74 rport=60747 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666183.788:7998): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60747 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666183.788:7999): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60747 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666183.796:8000): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.796:8001): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10036 suid=74 rport=60747 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666183.797:8002): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666183.798:8003): user pid=10035 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666183.798:8004): pid=10035 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=307 >type=USER_ROLE_CHANGE msg=audit(1362666183.926:8005): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666183.931:8006): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666183.933:8007): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666183.933:8008): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.934:8009): user pid=10038 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10038 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.934:8010): user pid=10038 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10038 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666183.935:8011): user pid=10038 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666183.995:8012): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666183.995:8013): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666183.995:8014): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666183.996:8015): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.996:8016): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10035 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.996:8017): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10035 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666183.996:8018): user pid=10035 uid=0 auid=0 ses=307 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10035 suid=0 rport=60747 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=MAC_CONFIG_CHANGE msg=audit(1362666184.170:8019): bool=rsync_export_all_ro val=1 old_val=0 auid=0 ses=294 >type=SYSCALL msg=audit(1362666184.170:8019): arch=c000003e syscall=1 success=yes exit=2 a0=4 a1=7fffee3d2c60 a2=2 a3=0 items=0 ppid=9940 pid=9941 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=294 comm="setsebool" exe="/usr/sbin/setsebool" subj=unconfined_u:unconfined_r:setsebool_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666187.055:8020): user pid=10048 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10048 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.055:8021): user pid=10048 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10048 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666187.058:8022): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10048 suid=74 rport=60749 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666187.059:8023): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10048 suid=74 rport=60749 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666187.122:8024): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60749 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666187.122:8025): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60749 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666187.130:8026): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.130:8027): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10048 suid=74 rport=60749 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666187.131:8028): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666187.132:8029): user pid=10047 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666187.132:8030): pid=10047 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=308 >type=USER_ROLE_CHANGE msg=audit(1362666187.278:8031): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666187.283:8032): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666187.289:8033): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666187.289:8034): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.290:8035): user pid=10050 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10050 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.290:8036): user pid=10050 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10050 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666187.291:8037): user pid=10050 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666187.336:8038): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666187.336:8039): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666187.336:8040): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666187.337:8041): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.337:8042): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10047 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.337:8043): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10047 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666187.337:8044): user pid=10047 uid=0 auid=0 ses=308 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10047 suid=0 rport=60749 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.389:8045): user pid=10059 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10059 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.389:8046): user pid=10059 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10059 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666190.391:8047): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10059 suid=74 rport=60750 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666190.391:8048): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10059 suid=74 rport=60750 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666190.455:8049): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60750 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666190.455:8050): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60750 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666190.465:8051): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.465:8052): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10059 suid=74 rport=60750 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666190.466:8053): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666190.466:8054): user pid=10058 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666190.467:8055): pid=10058 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=309 >type=USER_ROLE_CHANGE msg=audit(1362666190.616:8056): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666190.622:8057): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666190.628:8058): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666190.629:8059): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.630:8060): user pid=10061 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10061 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.630:8061): user pid=10061 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10061 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666190.632:8062): user pid=10061 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666190.686:8063): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666190.686:8064): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666190.687:8065): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666190.687:8066): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.687:8067): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10058 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.687:8068): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10058 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666190.687:8069): user pid=10058 uid=0 auid=0 ses=309 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10058 suid=0 rport=60750 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.737:8070): user pid=10092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.737:8071): user pid=10092 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10092 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666193.740:8072): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10092 suid=74 rport=60754 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666193.741:8073): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10092 suid=74 rport=60754 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666193.805:8074): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60754 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666193.805:8075): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60754 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666193.812:8076): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.813:8077): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10092 suid=74 rport=60754 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666193.814:8078): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666193.814:8079): user pid=10091 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666193.814:8080): pid=10091 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=310 >type=USER_ROLE_CHANGE msg=audit(1362666193.942:8081): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666193.948:8082): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666193.953:8083): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666193.953:8084): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.955:8085): user pid=10094 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10094 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.955:8086): user pid=10094 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10094 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666193.956:8087): user pid=10094 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666193.998:8088): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666193.999:8089): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666193.999:8090): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666193.999:8091): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.999:8092): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10091 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.999:8093): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10091 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666193.999:8094): user pid=10091 uid=0 auid=0 ses=310 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10091 suid=0 rport=60754 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.069:8095): user pid=10104 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10104 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.069:8096): user pid=10104 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10104 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666197.070:8097): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10104 suid=74 rport=60756 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666197.070:8098): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10104 suid=74 rport=60756 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=ADD_GROUP msg=audit(1362666197.131:8099): user pid=10102 uid=0 auid=0 ses=294 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/group id=160 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=USER_AUTH msg=audit(1362666197.135:8100): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60756 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666197.136:8101): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60756 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666197.142:8102): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.143:8103): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10104 suid=74 rport=60756 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666197.143:8104): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666197.144:8105): user pid=10103 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666197.144:8106): pid=10103 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=311 >type=ADD_GROUP msg=audit(1362666197.180:8107): user pid=10102 uid=0 auid=0 ses=294 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op=adding group to /etc/gshadow id=160 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_GROUP msg=audit(1362666197.184:8108): user pid=10102 uid=0 auid=0 ses=294 subj=unconfined_u:system_r:groupadd_t:s0-s0:c0.c1023 msg='op= id=160 exe="/usr/sbin/groupadd" hostname=? addr=? terminal=? res=success' >type=ADD_USER msg=audit(1362666197.248:8109): user pid=10110 uid=0 auid=0 ses=294 subj=unconfined_u:system_r:useradd_t:s0-s0:c0.c1023 msg='op=adding user id=160 exe="/usr/sbin/useradd" hostname=? addr=? terminal=? res=success' >type=USER_ROLE_CHANGE msg=audit(1362666197.281:8110): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666197.285:8111): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666197.290:8112): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666197.291:8113): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.292:8114): user pid=10111 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10111 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.292:8115): user pid=10111 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10111 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666197.292:8116): user pid=10111 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666197.337:8117): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666197.338:8118): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666197.338:8119): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666197.338:8120): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.338:8121): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10103 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.338:8122): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10103 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666197.339:8123): user pid=10103 uid=0 auid=0 ses=311 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10103 suid=0 rport=60756 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.390:8124): user pid=10123 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10123 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.390:8125): user pid=10123 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10123 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666200.393:8126): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10123 suid=74 rport=60757 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666200.393:8127): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10123 suid=74 rport=60757 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666200.454:8128): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60757 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666200.454:8129): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60757 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666200.465:8130): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.466:8131): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10123 suid=74 rport=60757 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666200.467:8132): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666200.468:8133): user pid=10122 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666200.469:8134): pid=10122 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=312 >type=USER_ROLE_CHANGE msg=audit(1362666200.645:8135): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666200.652:8136): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666200.660:8137): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666200.661:8138): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.662:8139): user pid=10129 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10129 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.662:8140): user pid=10129 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10129 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666200.663:8141): user pid=10129 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666200.703:8142): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666200.703:8143): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666200.704:8144): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666200.704:8145): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.704:8146): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10122 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.704:8147): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10122 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666200.705:8148): user pid=10122 uid=0 auid=0 ses=312 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10122 suid=0 rport=60757 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666203.756:8149): user pid=10141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10141 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666203.756:8150): user pid=10141 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10141 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666203.756:8151): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10141 suid=74 rport=60758 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666203.757:8152): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10141 suid=74 rport=60758 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666203.822:8153): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60758 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666203.822:8154): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60758 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666203.830:8155): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666203.830:8156): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10141 suid=74 rport=60758 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666203.831:8157): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666203.831:8158): user pid=10140 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666203.832:8159): pid=10140 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=313 >type=USER_ROLE_CHANGE msg=audit(1362666203.969:8160): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666203.974:8161): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666203.979:8162): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666203.980:8163): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666203.981:8164): user pid=10143 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10143 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666203.981:8165): user pid=10143 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10143 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666203.982:8166): user pid=10143 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666204.029:8167): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666204.029:8168): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666204.029:8169): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666204.029:8170): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666204.030:8171): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10140 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666204.030:8172): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10140 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666204.030:8173): user pid=10140 uid=0 auid=0 ses=313 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10140 suid=0 rport=60758 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.092:8174): user pid=10150 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10150 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.092:8175): user pid=10150 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10150 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666207.093:8176): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10150 suid=74 rport=60759 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666207.093:8177): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10150 suid=74 rport=60759 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666207.158:8178): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60759 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666207.158:8179): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60759 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666207.165:8180): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.166:8181): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10150 suid=74 rport=60759 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666207.167:8182): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666207.167:8183): user pid=10149 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666207.167:8184): pid=10149 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=314 >type=USER_ROLE_CHANGE msg=audit(1362666207.300:8185): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666207.303:8186): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666207.309:8187): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666207.309:8188): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.310:8189): user pid=10152 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10152 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.310:8190): user pid=10152 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10152 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666207.311:8191): user pid=10152 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666207.352:8192): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666207.352:8193): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666207.352:8194): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666207.352:8195): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.353:8196): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10149 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.353:8197): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10149 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666207.353:8198): user pid=10149 uid=0 auid=0 ses=314 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10149 suid=0 rport=60759 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.412:8199): user pid=10159 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10159 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.412:8200): user pid=10159 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10159 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666210.413:8201): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10159 suid=74 rport=60760 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666210.413:8202): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10159 suid=74 rport=60760 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666210.476:8203): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60760 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666210.476:8204): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60760 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666210.483:8205): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.485:8206): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10159 suid=74 rport=60760 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666210.486:8207): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666210.487:8208): user pid=10158 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666210.487:8209): pid=10158 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=315 >type=USER_ROLE_CHANGE msg=audit(1362666210.615:8210): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666210.618:8211): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666210.624:8212): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666210.624:8213): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.626:8214): user pid=10161 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10161 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.626:8215): user pid=10161 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10161 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666210.626:8216): user pid=10161 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666210.671:8217): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666210.671:8218): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666210.672:8219): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666210.672:8220): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.672:8221): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10158 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.672:8222): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10158 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666210.672:8223): user pid=10158 uid=0 auid=0 ses=315 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10158 suid=0 rport=60760 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.710:8224): user pid=10168 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10168 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.710:8225): user pid=10168 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10168 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666213.711:8226): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10168 suid=74 rport=60761 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666213.711:8227): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10168 suid=74 rport=60761 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666213.775:8228): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60761 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666213.775:8229): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60761 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666213.783:8230): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.784:8231): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10168 suid=74 rport=60761 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666213.785:8232): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666213.785:8233): user pid=10167 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666213.785:8234): pid=10167 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=316 >type=USER_ROLE_CHANGE msg=audit(1362666213.922:8235): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666213.925:8236): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666213.931:8237): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666213.931:8238): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.932:8239): user pid=10170 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.933:8240): user pid=10170 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10170 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666213.934:8241): user pid=10170 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666213.986:8242): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666213.986:8243): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666213.987:8244): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666213.987:8245): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.987:8246): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10167 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.987:8247): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10167 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666213.987:8248): user pid=10167 uid=0 auid=0 ses=316 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10167 suid=0 rport=60761 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.029:8249): user pid=10177 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10177 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.030:8250): user pid=10177 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10177 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666217.033:8251): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10177 suid=74 rport=60762 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666217.033:8252): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10177 suid=74 rport=60762 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666217.096:8253): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60762 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666217.096:8254): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60762 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666217.103:8255): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.104:8256): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10177 suid=74 rport=60762 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666217.105:8257): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666217.105:8258): user pid=10176 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666217.105:8259): pid=10176 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=317 >type=USER_ROLE_CHANGE msg=audit(1362666217.235:8260): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666217.238:8261): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666217.239:8262): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666217.239:8263): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.240:8264): user pid=10179 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10179 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.240:8265): user pid=10179 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10179 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666217.241:8266): user pid=10179 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666217.292:8267): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666217.292:8268): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666217.292:8269): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666217.292:8270): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.292:8271): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10176 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.292:8272): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10176 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666217.292:8273): user pid=10176 uid=0 auid=0 ses=317 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10176 suid=0 rport=60762 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.330:8274): user pid=10195 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10195 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.330:8275): user pid=10195 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10195 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666220.332:8276): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10195 suid=74 rport=60763 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666220.332:8277): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10195 suid=74 rport=60763 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666220.395:8278): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60763 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666220.395:8279): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60763 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666220.403:8280): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.403:8281): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10195 suid=74 rport=60763 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666220.405:8282): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666220.405:8283): user pid=10194 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666220.405:8284): pid=10194 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=318 >type=USER_ROLE_CHANGE msg=audit(1362666220.532:8285): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666220.536:8286): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666220.542:8287): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666220.543:8288): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.544:8289): user pid=10197 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10197 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.544:8290): user pid=10197 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10197 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666220.545:8291): user pid=10197 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666220.591:8292): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666220.591:8293): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666220.592:8294): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666220.592:8295): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.592:8296): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10194 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.592:8297): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10194 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666220.592:8298): user pid=10194 uid=0 auid=0 ses=318 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10194 suid=0 rport=60763 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.641:8299): user pid=10204 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10204 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.641:8300): user pid=10204 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10204 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666223.642:8301): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10204 suid=74 rport=60764 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666223.642:8302): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10204 suid=74 rport=60764 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666223.706:8303): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60764 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666223.706:8304): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60764 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666223.714:8305): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.715:8306): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10204 suid=74 rport=60764 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666223.716:8307): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666223.716:8308): user pid=10203 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666223.716:8309): pid=10203 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=319 >type=USER_ROLE_CHANGE msg=audit(1362666223.850:8310): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666223.853:8311): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666223.859:8312): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666223.859:8313): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.861:8314): user pid=10206 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10206 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.861:8315): user pid=10206 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10206 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666223.861:8316): user pid=10206 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666223.907:8317): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666223.907:8318): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666223.908:8319): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666223.908:8320): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.908:8321): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10203 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.908:8322): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10203 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666223.908:8323): user pid=10203 uid=0 auid=0 ses=319 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10203 suid=0 rport=60764 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666226.946:8324): user pid=10213 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10213 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666226.946:8325): user pid=10213 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10213 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666226.947:8326): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10213 suid=74 rport=60765 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666226.947:8327): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10213 suid=74 rport=60765 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666227.010:8328): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60765 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666227.010:8329): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60765 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666227.018:8330): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666227.018:8331): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10213 suid=74 rport=60765 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666227.019:8332): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666227.020:8333): user pid=10212 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666227.020:8334): pid=10212 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=320 >type=USER_ROLE_CHANGE msg=audit(1362666227.150:8335): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666227.155:8336): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666227.156:8337): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666227.157:8338): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666227.158:8339): user pid=10215 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10215 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666227.158:8340): user pid=10215 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10215 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666227.159:8341): user pid=10215 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666227.204:8342): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666227.204:8343): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666227.204:8344): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666227.205:8345): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666227.205:8346): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10212 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666227.205:8347): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10212 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666227.205:8348): user pid=10212 uid=0 auid=0 ses=320 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10212 suid=0 rport=60765 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.244:8349): user pid=10222 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10222 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.245:8350): user pid=10222 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10222 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666230.245:8351): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10222 suid=74 rport=60766 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666230.245:8352): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10222 suid=74 rport=60766 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666230.310:8353): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60766 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666230.310:8354): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60766 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666230.318:8355): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.319:8356): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10222 suid=74 rport=60766 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666230.320:8357): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666230.320:8358): user pid=10221 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666230.320:8359): pid=10221 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=321 >type=USER_ROLE_CHANGE msg=audit(1362666230.451:8360): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666230.456:8361): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666230.462:8362): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666230.462:8363): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.463:8364): user pid=10224 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10224 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.463:8365): user pid=10224 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10224 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666230.464:8366): user pid=10224 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666230.512:8367): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666230.512:8368): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666230.513:8369): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666230.513:8370): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.513:8371): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10221 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.514:8372): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10221 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666230.514:8373): user pid=10221 uid=0 auid=0 ses=321 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10221 suid=0 rport=60766 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.552:8374): user pid=10231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10231 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.553:8375): user pid=10231 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10231 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666233.553:8376): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10231 suid=74 rport=60767 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666233.554:8377): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10231 suid=74 rport=60767 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666233.617:8378): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60767 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666233.617:8379): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60767 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666233.626:8380): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.626:8381): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10231 suid=74 rport=60767 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666233.628:8382): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666233.628:8383): user pid=10230 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666233.628:8384): pid=10230 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=322 >type=USER_ROLE_CHANGE msg=audit(1362666233.765:8385): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666233.771:8386): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666233.776:8387): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666233.777:8388): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.778:8389): user pid=10233 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10233 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.778:8390): user pid=10233 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10233 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666233.779:8391): user pid=10233 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666233.825:8392): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666233.825:8393): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666233.826:8394): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666233.826:8395): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.826:8396): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10230 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.826:8397): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10230 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666233.826:8398): user pid=10230 uid=0 auid=0 ses=322 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10230 suid=0 rport=60767 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666236.900:8399): user pid=10249 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10249 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666236.900:8400): user pid=10249 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10249 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666236.904:8401): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10249 suid=74 rport=60768 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666236.904:8402): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10249 suid=74 rport=60768 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666236.968:8403): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60768 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666236.968:8404): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60768 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666236.976:8405): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666236.976:8406): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10249 suid=74 rport=60768 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666236.977:8407): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666236.978:8408): user pid=10248 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666236.978:8409): pid=10248 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=323 >type=USER_ROLE_CHANGE msg=audit(1362666237.109:8410): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666237.111:8411): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666237.116:8412): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666237.117:8413): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666237.118:8414): user pid=10251 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666237.118:8415): user pid=10251 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10251 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666237.119:8416): user pid=10251 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666237.164:8417): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666237.164:8418): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666237.164:8419): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666237.164:8420): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666237.164:8421): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10248 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666237.164:8422): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10248 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666237.165:8423): user pid=10248 uid=0 auid=0 ses=323 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10248 suid=0 rport=60768 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.211:8424): user pid=10258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10258 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.211:8425): user pid=10258 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10258 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666240.212:8426): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10258 suid=74 rport=60769 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666240.213:8427): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10258 suid=74 rport=60769 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666240.275:8428): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60769 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666240.275:8429): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60769 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666240.283:8430): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.284:8431): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10258 suid=74 rport=60769 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666240.285:8432): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666240.285:8433): user pid=10257 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666240.285:8434): pid=10257 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=324 >type=USER_ROLE_CHANGE msg=audit(1362666240.419:8435): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666240.424:8436): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666240.429:8437): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666240.430:8438): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.431:8439): user pid=10260 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10260 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.431:8440): user pid=10260 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10260 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666240.431:8441): user pid=10260 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666240.478:8442): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666240.478:8443): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666240.478:8444): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666240.479:8445): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.479:8446): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10257 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.479:8447): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10257 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666240.479:8448): user pid=10257 uid=0 auid=0 ses=324 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10257 suid=0 rport=60769 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.519:8449): user pid=10267 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10267 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.520:8450): user pid=10267 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10267 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666243.521:8451): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10267 suid=74 rport=60770 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666243.521:8452): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10267 suid=74 rport=60770 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666243.583:8453): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60770 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666243.583:8454): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60770 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666243.591:8455): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.591:8456): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10267 suid=74 rport=60770 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666243.592:8457): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666243.593:8458): user pid=10266 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666243.593:8459): pid=10266 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=325 >type=USER_ROLE_CHANGE msg=audit(1362666243.731:8460): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666243.735:8461): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666243.740:8462): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666243.741:8463): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.742:8464): user pid=10269 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10269 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.742:8465): user pid=10269 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10269 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666243.743:8466): user pid=10269 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666243.786:8467): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666243.787:8468): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666243.787:8469): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666243.787:8470): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.787:8471): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10266 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.787:8472): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10266 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666243.787:8473): user pid=10266 uid=0 auid=0 ses=325 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10266 suid=0 rport=60770 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666246.851:8474): user pid=10276 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10276 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666246.851:8475): user pid=10276 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10276 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666246.852:8476): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10276 suid=74 rport=60771 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666246.852:8477): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10276 suid=74 rport=60771 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666246.922:8478): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60771 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666246.922:8479): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60771 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666246.929:8480): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666246.930:8481): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10276 suid=74 rport=60771 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666246.930:8482): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666246.931:8483): user pid=10275 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666246.931:8484): pid=10275 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=326 >type=USER_ROLE_CHANGE msg=audit(1362666247.059:8485): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666247.063:8486): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666247.069:8487): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666247.069:8488): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666247.070:8489): user pid=10278 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10278 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666247.071:8490): user pid=10278 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10278 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666247.072:8491): user pid=10278 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666247.116:8492): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666247.116:8493): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666247.116:8494): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666247.117:8495): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666247.117:8496): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10275 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666247.117:8497): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10275 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666247.117:8498): user pid=10275 uid=0 auid=0 ses=326 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10275 suid=0 rport=60771 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.155:8499): user pid=10285 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10285 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.155:8500): user pid=10285 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10285 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666250.155:8501): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10285 suid=74 rport=60772 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666250.156:8502): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10285 suid=74 rport=60772 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666250.218:8503): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60772 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666250.218:8504): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60772 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666250.226:8505): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.226:8506): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10285 suid=74 rport=60772 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666250.227:8507): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666250.228:8508): user pid=10284 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666250.228:8509): pid=10284 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=327 >type=USER_ROLE_CHANGE msg=audit(1362666250.360:8510): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666250.365:8511): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666250.370:8512): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666250.370:8513): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.371:8514): user pid=10287 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.371:8515): user pid=10287 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10287 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666250.372:8516): user pid=10287 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666250.417:8517): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666250.417:8518): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666250.418:8519): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666250.418:8520): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.418:8521): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10284 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.418:8522): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10284 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666250.418:8523): user pid=10284 uid=0 auid=0 ses=327 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10284 suid=0 rport=60772 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666253.342:8524): table=filter family=2 entries=57 >type=SYSCALL msg=audit(1362666253.342:8524): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=888690 items=0 ppid=9615 pid=10294 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=294 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666253.479:8525): user pid=10307 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10307 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.480:8526): user pid=10307 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10307 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666253.482:8527): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10307 suid=74 rport=60773 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666253.483:8528): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10307 suid=74 rport=60773 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666253.546:8529): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60773 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666253.546:8530): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60773 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666253.556:8531): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.557:8532): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10307 suid=74 rport=60773 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666253.558:8533): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666253.558:8534): user pid=10306 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666253.558:8535): pid=10306 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=328 >type=USER_ROLE_CHANGE msg=audit(1362666253.701:8536): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666253.705:8537): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666253.710:8538): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666253.711:8539): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.712:8540): user pid=10310 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10310 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.712:8541): user pid=10310 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10310 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666253.713:8542): user pid=10310 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666253.761:8543): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666253.762:8544): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666253.762:8545): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666253.762:8546): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.762:8547): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10306 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.762:8548): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10306 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.762:8549): user pid=10306 uid=0 auid=0 ses=328 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10306 suid=0 rport=60773 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.789:8550): user pid=10315 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10315 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.789:8551): user pid=10315 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10315 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666253.790:8552): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10315 suid=74 rport=60774 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666253.790:8553): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10315 suid=74 rport=60774 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666253.852:8554): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60774 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666253.852:8555): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60774 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666253.859:8556): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.860:8557): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10315 suid=74 rport=60774 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666253.860:8558): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666253.861:8559): user pid=10314 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666253.861:8560): pid=10314 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=329 >type=USER_ROLE_CHANGE msg=audit(1362666253.983:8561): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666253.985:8562): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666253.986:8563): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666253.986:8564): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.987:8565): user pid=10317 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10317 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666253.987:8566): user pid=10317 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10317 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666253.988:8567): user pid=10317 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666254.035:8568): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666254.035:8569): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666254.036:8570): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666254.036:8571): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.036:8572): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10314 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.036:8573): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10314 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.036:8574): user pid=10314 uid=0 auid=0 ses=329 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10314 suid=0 rport=60774 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.069:8575): user pid=10329 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10329 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.069:8576): user pid=10329 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10329 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666254.071:8577): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10329 suid=74 rport=60775 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666254.071:8578): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10329 suid=74 rport=60775 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666254.134:8579): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60775 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666254.134:8580): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60775 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666254.141:8581): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.142:8582): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10329 suid=74 rport=60775 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666254.143:8583): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666254.143:8584): user pid=10328 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666254.143:8585): pid=10328 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=330 >type=USER_ROLE_CHANGE msg=audit(1362666254.265:8586): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666254.268:8587): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666254.273:8588): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666254.273:8589): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.275:8590): user pid=10354 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10354 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.275:8591): user pid=10354 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10354 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666254.276:8592): user pid=10354 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666254.311:8593): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666254.312:8594): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666254.312:8595): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666254.312:8596): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.312:8597): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10328 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.312:8598): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10328 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666254.312:8599): user pid=10328 uid=0 auid=0 ses=330 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10328 suid=0 rport=60775 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.369:8600): user pid=10637 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10637 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.369:8601): user pid=10637 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10637 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666257.370:8602): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10637 suid=74 rport=60776 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666257.370:8603): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10637 suid=74 rport=60776 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666257.434:8604): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60776 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666257.434:8605): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60776 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666257.442:8606): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.443:8607): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10637 suid=74 rport=60776 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666257.444:8608): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666257.445:8609): user pid=10636 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666257.445:8610): pid=10636 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=331 >type=USER_ROLE_CHANGE msg=audit(1362666257.581:8611): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666257.586:8612): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666257.593:8613): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666257.593:8614): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.595:8615): user pid=10639 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10639 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.595:8616): user pid=10639 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10639 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666257.596:8617): user pid=10639 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666257.619:8618): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666257.620:8619): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666257.620:8620): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666257.620:8621): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.620:8622): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10636 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.620:8623): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10636 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666257.621:8624): user pid=10636 uid=0 auid=0 ses=331 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10636 suid=0 rport=60776 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.690:8625): user pid=10658 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10658 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.690:8626): user pid=10658 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10658 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666260.691:8627): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10658 suid=74 rport=60777 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666260.691:8628): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10658 suid=74 rport=60777 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666260.755:8629): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60777 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666260.755:8630): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60777 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666260.762:8631): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.765:8632): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10658 suid=74 rport=60777 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666260.766:8633): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666260.766:8634): user pid=10657 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666260.766:8635): pid=10657 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=332 >type=USER_ROLE_CHANGE msg=audit(1362666260.912:8636): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666260.917:8637): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666260.923:8638): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666260.923:8639): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.925:8640): user pid=10660 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10660 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.925:8641): user pid=10660 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10660 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666260.926:8642): user pid=10660 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666260.972:8643): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666260.972:8644): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666260.973:8645): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666260.973:8646): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.973:8647): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10657 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.973:8648): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10657 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666260.973:8649): user pid=10657 uid=0 auid=0 ses=332 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10657 suid=0 rport=60777 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.037:8650): user pid=10674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10674 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.037:8651): user pid=10674 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10674 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666264.040:8652): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10674 suid=74 rport=60779 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666264.040:8653): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10674 suid=74 rport=60779 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666264.105:8654): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60779 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666264.105:8655): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60779 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666264.113:8656): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.114:8657): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10674 suid=74 rport=60779 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666264.115:8658): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666264.116:8659): user pid=10673 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666264.116:8660): pid=10673 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=333 >type=USER_ROLE_CHANGE msg=audit(1362666264.257:8661): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666264.262:8662): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666264.268:8663): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666264.268:8664): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.269:8665): user pid=10676 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10676 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.270:8666): user pid=10676 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10676 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666264.270:8667): user pid=10676 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666264.317:8668): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666264.317:8669): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666264.317:8670): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666264.317:8671): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.318:8672): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10673 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.318:8673): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10673 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666264.318:8674): user pid=10673 uid=0 auid=0 ses=333 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10673 suid=0 rport=60779 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.364:8675): user pid=10683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.365:8676): user pid=10683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666267.365:8677): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10683 suid=74 rport=60780 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666267.365:8678): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10683 suid=74 rport=60780 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666267.429:8679): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60780 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666267.430:8680): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60780 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666267.438:8681): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.439:8682): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10683 suid=74 rport=60780 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666267.440:8683): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666267.440:8684): user pid=10682 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666267.440:8685): pid=10682 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=334 >type=USER_ROLE_CHANGE msg=audit(1362666267.578:8686): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666267.582:8687): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666267.589:8688): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666267.589:8689): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.590:8690): user pid=10685 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10685 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.590:8691): user pid=10685 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10685 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666267.591:8692): user pid=10685 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666267.639:8693): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666267.639:8694): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666267.639:8695): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666267.639:8696): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.640:8697): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10682 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.640:8698): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10682 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666267.640:8699): user pid=10682 uid=0 auid=0 ses=334 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10682 suid=0 rport=60780 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.681:8700): user pid=10692 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10692 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.681:8701): user pid=10692 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10692 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666270.682:8702): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10692 suid=74 rport=60781 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666270.683:8703): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10692 suid=74 rport=60781 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666270.747:8704): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60781 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666270.747:8705): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60781 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666270.754:8706): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.755:8707): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10692 suid=74 rport=60781 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666270.756:8708): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666270.756:8709): user pid=10691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666270.756:8710): pid=10691 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=335 >type=USER_ROLE_CHANGE msg=audit(1362666270.885:8711): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666270.890:8712): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666270.896:8713): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666270.897:8714): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.898:8715): user pid=10694 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10694 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.898:8716): user pid=10694 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10694 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666270.899:8717): user pid=10694 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666270.950:8718): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666270.950:8719): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666270.951:8720): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666270.951:8721): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.951:8722): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10691 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.951:8723): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10691 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666270.951:8724): user pid=10691 uid=0 auid=0 ses=335 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10691 suid=0 rport=60781 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666273.994:8725): user pid=10701 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10701 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666273.994:8726): user pid=10701 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10701 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666273.994:8727): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10701 suid=74 rport=60782 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666273.995:8728): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10701 suid=74 rport=60782 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666274.059:8729): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60782 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666274.059:8730): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60782 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666274.066:8731): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666274.068:8732): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10701 suid=74 rport=60782 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666274.069:8733): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666274.069:8734): user pid=10700 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666274.069:8735): pid=10700 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=336 >type=USER_ROLE_CHANGE msg=audit(1362666274.200:8736): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666274.205:8737): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666274.210:8738): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666274.210:8739): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666274.211:8740): user pid=10703 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10703 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666274.212:8741): user pid=10703 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10703 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666274.212:8742): user pid=10703 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666274.262:8743): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666274.262:8744): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666274.263:8745): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666274.263:8746): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666274.263:8747): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10700 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666274.263:8748): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10700 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666274.263:8749): user pid=10700 uid=0 auid=0 ses=336 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10700 suid=0 rport=60782 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.307:8750): user pid=10710 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10710 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.307:8751): user pid=10710 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10710 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666277.307:8752): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10710 suid=74 rport=60783 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666277.307:8753): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10710 suid=74 rport=60783 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666277.370:8754): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60783 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666277.370:8755): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60783 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666277.377:8756): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.378:8757): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10710 suid=74 rport=60783 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666277.379:8758): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666277.379:8759): user pid=10709 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666277.379:8760): pid=10709 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=337 >type=USER_ROLE_CHANGE msg=audit(1362666277.508:8761): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666277.513:8762): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666277.518:8763): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666277.518:8764): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.520:8765): user pid=10712 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10712 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.520:8766): user pid=10712 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10712 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666277.520:8767): user pid=10712 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666277.569:8768): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666277.569:8769): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666277.569:8770): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666277.570:8771): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.570:8772): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10709 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.570:8773): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10709 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666277.570:8774): user pid=10709 uid=0 auid=0 ses=337 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10709 suid=0 rport=60783 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.614:8775): user pid=10719 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10719 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.614:8776): user pid=10719 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10719 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666280.618:8777): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10719 suid=74 rport=60784 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666280.618:8778): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10719 suid=74 rport=60784 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666280.681:8779): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60784 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666280.681:8780): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60784 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666280.689:8781): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.690:8782): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10719 suid=74 rport=60784 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666280.690:8783): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666280.691:8784): user pid=10718 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666280.691:8785): pid=10718 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=338 >type=USER_ROLE_CHANGE msg=audit(1362666280.827:8786): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666280.831:8787): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666280.831:8788): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666280.831:8789): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.833:8790): user pid=10721 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10721 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.833:8791): user pid=10721 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10721 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666280.834:8792): user pid=10721 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666280.886:8793): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666280.886:8794): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666280.887:8795): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666280.887:8796): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.887:8797): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10718 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.887:8798): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10718 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666280.887:8799): user pid=10718 uid=0 auid=0 ses=338 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10718 suid=0 rport=60784 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666283.932:8800): user pid=10728 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10728 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666283.933:8801): user pid=10728 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10728 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666283.934:8802): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10728 suid=74 rport=60785 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666283.934:8803): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10728 suid=74 rport=60785 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666283.996:8804): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60785 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666283.996:8805): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60785 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666284.005:8806): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666284.005:8807): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10728 suid=74 rport=60785 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666284.006:8808): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666284.006:8809): user pid=10727 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666284.007:8810): pid=10727 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=339 >type=USER_ROLE_CHANGE msg=audit(1362666284.139:8811): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666284.144:8812): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666284.149:8813): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666284.149:8814): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666284.150:8815): user pid=10730 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10730 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666284.150:8816): user pid=10730 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10730 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666284.151:8817): user pid=10730 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666284.198:8818): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666284.198:8819): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666284.199:8820): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666284.199:8821): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666284.199:8822): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10727 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666284.199:8823): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10727 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666284.199:8824): user pid=10727 uid=0 auid=0 ses=339 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10727 suid=0 rport=60785 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.249:8825): user pid=10737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10737 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.249:8826): user pid=10737 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10737 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666287.250:8827): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10737 suid=74 rport=60786 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666287.250:8828): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10737 suid=74 rport=60786 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666287.312:8829): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60786 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666287.312:8830): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60786 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666287.320:8831): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.321:8832): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10737 suid=74 rport=60786 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666287.322:8833): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666287.322:8834): user pid=10736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666287.322:8835): pid=10736 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=340 >type=USER_ROLE_CHANGE msg=audit(1362666287.458:8836): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666287.463:8837): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666287.470:8838): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666287.470:8839): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.471:8840): user pid=10739 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10739 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.471:8841): user pid=10739 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10739 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666287.472:8842): user pid=10739 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666287.520:8843): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666287.521:8844): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666287.521:8845): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666287.521:8846): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.521:8847): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10736 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.521:8848): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10736 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666287.521:8849): user pid=10736 uid=0 auid=0 ses=340 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10736 suid=0 rport=60786 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.560:8850): user pid=10746 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10746 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.560:8851): user pid=10746 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10746 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666290.561:8852): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10746 suid=74 rport=60787 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666290.562:8853): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10746 suid=74 rport=60787 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666290.625:8854): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60787 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666290.625:8855): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60787 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666290.632:8856): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.632:8857): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10746 suid=74 rport=60787 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666290.633:8858): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666290.633:8859): user pid=10745 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666290.633:8860): pid=10745 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=341 >type=USER_ROLE_CHANGE msg=audit(1362666290.769:8861): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666290.773:8862): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666290.775:8863): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666290.775:8864): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.776:8865): user pid=10748 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10748 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.776:8866): user pid=10748 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10748 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666290.777:8867): user pid=10748 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666290.826:8868): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666290.826:8869): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666290.827:8870): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666290.827:8871): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.827:8872): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10745 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.827:8873): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10745 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666290.827:8874): user pid=10745 uid=0 auid=0 ses=341 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10745 suid=0 rport=60787 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666293.868:8875): user pid=10755 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10755 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666293.869:8876): user pid=10755 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10755 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666293.869:8877): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10755 suid=74 rport=60788 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666293.869:8878): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10755 suid=74 rport=60788 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666293.931:8879): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60788 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666293.931:8880): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60788 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666293.940:8881): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666293.940:8882): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10755 suid=74 rport=60788 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666293.941:8883): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666293.941:8884): user pid=10754 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666293.941:8885): pid=10754 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=342 >type=USER_ROLE_CHANGE msg=audit(1362666294.076:8886): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666294.081:8887): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666294.086:8888): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666294.087:8889): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666294.088:8890): user pid=10757 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10757 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666294.088:8891): user pid=10757 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10757 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666294.089:8892): user pid=10757 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666294.137:8893): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666294.137:8894): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666294.138:8895): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666294.138:8896): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666294.138:8897): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10754 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666294.138:8898): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10754 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666294.138:8899): user pid=10754 uid=0 auid=0 ses=342 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10754 suid=0 rport=60788 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.180:8900): user pid=10764 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10764 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.180:8901): user pid=10764 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10764 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666297.180:8902): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10764 suid=74 rport=60789 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666297.181:8903): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10764 suid=74 rport=60789 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666297.245:8904): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60789 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666297.245:8905): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60789 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666297.253:8906): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.253:8907): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10764 suid=74 rport=60789 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666297.254:8908): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666297.254:8909): user pid=10763 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666297.255:8910): pid=10763 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=343 >type=USER_ROLE_CHANGE msg=audit(1362666297.385:8911): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666297.390:8912): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666297.396:8913): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666297.396:8914): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.397:8915): user pid=10766 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10766 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.398:8916): user pid=10766 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10766 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666297.398:8917): user pid=10766 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666297.445:8918): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666297.445:8919): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666297.446:8920): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666297.446:8921): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.446:8922): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10763 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.446:8923): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10763 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666297.446:8924): user pid=10763 uid=0 auid=0 ses=343 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10763 suid=0 rport=60789 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=MAC_CONFIG_CHANGE msg=audit(1362666298.010:8925): bool=rsync_client val=1 old_val=0 auid=0 ses=329 >type=SYSCALL msg=audit(1362666298.010:8925): arch=c000003e syscall=1 success=yes exit=2 a0=4 a1=7fff0bf9a120 a2=2 a3=0 items=0 ppid=10668 pid=10669 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=329 comm="setsebool" exe="/usr/sbin/setsebool" subj=unconfined_u:unconfined_r:setsebool_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666300.517:8926): user pid=10776 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10776 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.517:8927): user pid=10776 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10776 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666300.520:8928): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10776 suid=74 rport=60790 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666300.521:8929): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10776 suid=74 rport=60790 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666300.585:8930): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60790 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666300.585:8931): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60790 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666300.592:8932): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.593:8933): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10776 suid=74 rport=60790 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666300.594:8934): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666300.594:8935): user pid=10775 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666300.594:8936): pid=10775 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=344 >type=USER_ROLE_CHANGE msg=audit(1362666300.744:8937): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666300.747:8938): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666300.753:8939): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666300.754:8940): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.755:8941): user pid=10778 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10778 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.755:8942): user pid=10778 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10778 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666300.756:8943): user pid=10778 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666300.804:8944): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666300.805:8945): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666300.805:8946): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666300.805:8947): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.805:8948): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10775 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.805:8949): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10775 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666300.805:8950): user pid=10775 uid=0 auid=0 ses=344 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10775 suid=0 rport=60790 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666303.871:8951): user pid=10790 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10790 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666303.871:8952): user pid=10790 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10790 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666303.873:8953): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10790 suid=74 rport=60792 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666303.873:8954): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10790 suid=74 rport=60792 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666303.939:8955): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60792 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666303.939:8956): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60792 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666303.948:8957): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666303.948:8958): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10790 suid=74 rport=60792 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666303.949:8959): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666303.949:8960): user pid=10789 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666303.949:8961): pid=10789 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=345 >type=USER_ROLE_CHANGE msg=audit(1362666304.084:8962): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666304.090:8963): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666304.097:8964): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666304.097:8965): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666304.098:8966): user pid=10795 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10795 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666304.099:8967): user pid=10795 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10795 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666304.100:8968): user pid=10795 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666304.140:8969): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666304.140:8970): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666304.140:8971): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666304.141:8972): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666304.141:8973): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10789 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666304.141:8974): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10789 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666304.141:8975): user pid=10789 uid=0 auid=0 ses=345 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10789 suid=0 rport=60792 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.198:8976): user pid=10807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10807 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.198:8977): user pid=10807 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10807 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666307.199:8978): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10807 suid=74 rport=60794 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666307.199:8979): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10807 suid=74 rport=60794 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666307.263:8980): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60794 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666307.263:8981): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60794 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666307.270:8982): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.270:8983): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10807 suid=74 rport=60794 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666307.271:8984): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666307.272:8985): user pid=10806 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666307.272:8986): pid=10806 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=346 >type=USER_ROLE_CHANGE msg=audit(1362666307.409:8987): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666307.413:8988): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666307.418:8989): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666307.418:8990): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.420:8991): user pid=10809 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10809 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.420:8992): user pid=10809 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10809 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666307.421:8993): user pid=10809 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666307.461:8994): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666307.462:8995): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666307.462:8996): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666307.462:8997): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.462:8998): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10806 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.462:8999): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10806 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666307.462:9000): user pid=10806 uid=0 auid=0 ses=346 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10806 suid=0 rport=60794 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.538:9001): user pid=10824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10824 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.538:9002): user pid=10824 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10824 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666310.541:9003): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10824 suid=74 rport=60796 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666310.541:9004): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10824 suid=74 rport=60796 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666310.609:9005): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60796 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666310.609:9006): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60796 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666310.618:9007): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.619:9008): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10824 suid=74 rport=60796 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666310.620:9009): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666310.620:9010): user pid=10823 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666310.620:9011): pid=10823 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=347 >type=USER_ROLE_CHANGE msg=audit(1362666310.760:9012): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666310.765:9013): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666310.771:9014): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666310.771:9015): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.773:9016): user pid=10826 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10826 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.773:9017): user pid=10826 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10826 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666310.774:9018): user pid=10826 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666310.825:9019): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666310.825:9020): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666310.825:9021): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666310.825:9022): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.826:9023): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10823 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.826:9024): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10823 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666310.826:9025): user pid=10823 uid=0 auid=0 ses=347 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10823 suid=0 rport=60796 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666312.190:9026): table=filter family=2 entries=58 >type=SYSCALL msg=audit(1362666312.190:9026): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=b2faf0 items=0 ppid=10324 pid=10834 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=329 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=NETFILTER_CFG msg=audit(1362666313.175:9027): table=filter family=2 entries=59 >type=SYSCALL msg=audit(1362666313.175:9027): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=17dff40 items=0 ppid=10324 pid=10870 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=329 comm="iptables" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 key=(null) >type=CRYPTO_KEY_USER msg=audit(1362666313.867:9028): user pid=10906 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10906 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666313.867:9029): user pid=10906 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10906 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666313.868:9030): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10906 suid=74 rport=60797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666313.869:9031): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10906 suid=74 rport=60797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666313.932:9032): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60797 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666313.932:9033): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60797 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666313.941:9034): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666313.941:9035): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10906 suid=74 rport=60797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666313.942:9036): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666313.943:9037): user pid=10905 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666313.943:9038): pid=10905 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=348 >type=USER_ROLE_CHANGE msg=audit(1362666314.105:9039): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666314.110:9040): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666314.116:9041): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666314.117:9042): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666314.118:9043): user pid=10916 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10916 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666314.119:9044): user pid=10916 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10916 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666314.120:9045): user pid=10916 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666314.159:9046): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666314.159:9047): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666314.159:9048): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666314.160:9049): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666314.160:9050): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10905 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666314.160:9051): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10905 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666314.160:9052): user pid=10905 uid=0 auid=0 ses=348 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10905 suid=0 rport=60797 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.203:9053): user pid=10982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.203:9054): user pid=10982 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10982 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666317.207:9055): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=10982 suid=74 rport=60801 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666317.207:9056): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=10982 suid=74 rport=60801 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666317.271:9057): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60801 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666317.271:9058): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60801 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666317.279:9059): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.280:9060): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10982 suid=74 rport=60801 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666317.281:9061): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666317.281:9062): user pid=10978 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666317.281:9063): pid=10978 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=349 >type=USER_ROLE_CHANGE msg=audit(1362666317.431:9064): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666317.435:9065): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666317.437:9066): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666317.437:9067): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.439:9068): user pid=11011 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11011 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.439:9069): user pid=11011 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11011 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666317.440:9070): user pid=11011 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666317.466:9071): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666317.467:9072): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666317.467:9073): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666317.467:9074): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.467:9075): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=10978 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.467:9076): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=10978 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666317.468:9077): user pid=10978 uid=0 auid=0 ses=349 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=10978 suid=0 rport=60801 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.515:9078): user pid=11154 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11154 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.515:9079): user pid=11154 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11154 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666320.516:9080): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11154 suid=74 rport=60802 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666320.516:9081): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11154 suid=74 rport=60802 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666320.580:9082): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60802 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666320.581:9083): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60802 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666320.590:9084): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.591:9085): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11154 suid=74 rport=60802 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666320.592:9086): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666320.592:9087): user pid=11153 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666320.592:9088): pid=11153 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=350 >type=USER_ROLE_CHANGE msg=audit(1362666320.730:9089): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666320.734:9090): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666320.740:9091): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666320.740:9092): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.742:9093): user pid=11169 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11169 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.742:9094): user pid=11169 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11169 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666320.742:9095): user pid=11169 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666320.779:9096): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666320.780:9097): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666320.780:9098): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666320.780:9099): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.780:9100): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11153 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.781:9101): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11153 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666320.781:9102): user pid=11153 uid=0 auid=0 ses=350 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11153 suid=0 rport=60802 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666323.858:9103): user pid=11255 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11255 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666323.858:9104): user pid=11255 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11255 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666323.861:9105): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11255 suid=74 rport=60803 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666323.861:9106): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11255 suid=74 rport=60803 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666323.927:9107): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60803 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666323.927:9108): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60803 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666323.934:9109): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666323.934:9110): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11255 suid=74 rport=60803 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666323.935:9111): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666323.936:9112): user pid=11254 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666323.936:9113): pid=11254 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=351 >type=USER_ROLE_CHANGE msg=audit(1362666324.075:9114): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666324.079:9115): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666324.086:9116): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666324.086:9117): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666324.088:9118): user pid=11270 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11270 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666324.088:9119): user pid=11270 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11270 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666324.089:9120): user pid=11270 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666324.125:9121): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666324.125:9122): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666324.126:9123): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666324.126:9124): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666324.126:9125): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11254 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666324.126:9126): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11254 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666324.126:9127): user pid=11254 uid=0 auid=0 ses=351 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11254 suid=0 rport=60803 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.171:9128): user pid=11345 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11345 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.171:9129): user pid=11345 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11345 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666327.172:9130): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11345 suid=74 rport=60804 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666327.172:9131): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11345 suid=74 rport=60804 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.234:9132): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60804 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.234:9133): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60804 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666327.242:9134): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.242:9135): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11345 suid=74 rport=60804 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.243:9136): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666327.244:9137): user pid=11344 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666327.244:9138): pid=11344 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=352 >type=USER_ROLE_CHANGE msg=audit(1362666327.385:9139): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666327.390:9140): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666327.396:9141): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666327.397:9142): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.398:9143): user pid=11347 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11347 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.398:9144): user pid=11347 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11347 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666327.399:9145): user pid=11347 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666327.444:9146): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666327.445:9147): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666327.445:9148): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666327.446:9149): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.446:9150): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11344 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.446:9151): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11344 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.446:9152): user pid=11344 uid=0 auid=0 ses=352 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11344 suid=0 rport=60804 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.473:9153): user pid=11352 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.473:9154): user pid=11352 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11352 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666327.474:9155): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11352 suid=74 rport=60805 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666327.474:9156): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11352 suid=74 rport=60805 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.537:9157): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60805 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.537:9158): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60805 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666327.543:9159): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.543:9160): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11352 suid=74 rport=60805 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.544:9161): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666327.544:9162): user pid=11351 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666327.544:9163): pid=11351 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=353 >type=USER_ROLE_CHANGE msg=audit(1362666327.671:9164): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666327.675:9165): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666327.680:9166): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666327.680:9167): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.682:9168): user pid=11354 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11354 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.682:9169): user pid=11354 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11354 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666327.682:9170): user pid=11354 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666327.732:9171): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666327.732:9172): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666327.732:9173): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666327.733:9174): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.733:9175): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11351 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.733:9176): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11351 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.733:9177): user pid=11351 uid=0 auid=0 ses=353 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11351 suid=0 rport=60805 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.766:9178): user pid=11366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11366 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.767:9179): user pid=11366 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11366 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666327.767:9180): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11366 suid=74 rport=60806 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666327.767:9181): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11366 suid=74 rport=60806 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.830:9182): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60806 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.830:9183): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60806 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666327.837:9184): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.839:9185): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11366 suid=74 rport=60806 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666327.840:9186): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666327.840:9187): user pid=11365 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666327.840:9188): pid=11365 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=354 >type=USER_ROLE_CHANGE msg=audit(1362666327.958:9189): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666327.961:9190): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666327.961:9191): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666327.961:9192): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.962:9193): user pid=11391 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11391 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666327.962:9194): user pid=11391 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11391 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666327.964:9195): user pid=11391 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666328.002:9196): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666328.002:9197): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666328.002:9198): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666328.002:9199): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666328.002:9200): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11365 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666328.002:9201): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11365 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666328.003:9202): user pid=11365 uid=0 auid=0 ses=354 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11365 suid=0 rport=60806 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.044:9203): user pid=11677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11677 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.044:9204): user pid=11677 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11677 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666331.048:9205): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11677 suid=74 rport=60807 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666331.048:9206): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11677 suid=74 rport=60807 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.119:9207): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60807 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.119:9208): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60807 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666331.127:9209): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.128:9210): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11677 suid=74 rport=60807 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.129:9211): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666331.129:9212): user pid=11676 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666331.129:9213): pid=11676 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=355 >type=USER_ROLE_CHANGE msg=audit(1362666331.257:9214): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666331.261:9215): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666331.267:9216): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666331.267:9217): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.269:9218): user pid=11679 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11679 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.269:9219): user pid=11679 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11679 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666331.270:9220): user pid=11679 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666331.311:9221): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666331.311:9222): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666331.312:9223): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666331.312:9224): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.312:9225): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11676 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.312:9226): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11676 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.312:9227): user pid=11676 uid=0 auid=0 ses=355 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11676 suid=0 rport=60807 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.338:9228): user pid=11684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11684 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.338:9229): user pid=11684 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11684 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666331.339:9230): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11684 suid=74 rport=60808 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666331.339:9231): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11684 suid=74 rport=60808 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.401:9232): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=60808 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.401:9233): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=66:00:c8:7f:10:2a:68:37:02:0d:d7:87:fc:94:34:35 rport=60808 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_ACCT msg=audit(1362666331.407:9234): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.408:9235): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11684 suid=74 rport=60808 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.409:9236): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666331.409:9237): user pid=11683 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=LOGIN msg=audit(1362666331.409:9238): pid=11683 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=356 >type=USER_ROLE_CHANGE msg=audit(1362666331.534:9239): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666331.537:9240): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666331.542:9241): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_START msg=audit(1362666331.542:9242): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.543:9243): user pid=11686 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11686 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.543:9244): user pid=11686 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11686 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRED_REFR msg=audit(1362666331.544:9245): user pid=11686 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666331.620:9246): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666331.620:9247): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_END msg=audit(1362666331.621:9248): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666331.621:9249): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=rhel6 addr=192.168.129.3 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.621:9250): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.621:9251): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11683 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.621:9252): user pid=11683 uid=0 auid=0 ses=356 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11683 suid=0 rport=60808 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.3 terminal=? res=success' >type=USER_END msg=audit(1362666331.645:9253): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666331.645:9254): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666331.646:9255): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666331.646:9256): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.646:9257): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=1565 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.646:9258): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=1565 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.646:9259): user pid=1565 uid=0 auid=0 ses=5 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=1565 suid=0 rport=56206 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.696:9260): user pid=11691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11691 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.697:9261): user pid=11691 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11691 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666331.697:9262): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11691 suid=74 rport=56208 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666331.697:9263): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11691 suid=74 rport=56208 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.763:9264): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56208 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.763:9265): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56208 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362666331.770:9266): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.770:9267): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11691 suid=74 rport=56208 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666331.771:9268): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666331.772:9269): user pid=11690 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362666331.772:9270): pid=11690 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=357 >type=USER_ROLE_CHANGE msg=audit(1362666331.897:9271): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666331.902:9272): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666331.904:9273): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666331.904:9274): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.905:9275): user pid=11693 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11693 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666331.905:9276): user pid=11693 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11693 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362666331.906:9277): user pid=11693 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666332.225:9278): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666332.225:9279): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666332.225:9280): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666332.225:9281): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.225:9282): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11690 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.225:9283): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11690 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.226:9284): user pid=11690 uid=0 auid=0 ses=357 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11690 suid=0 rport=56208 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.520:9285): user pid=11697 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11697 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.520:9286): user pid=11697 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11697 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666332.521:9287): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11697 suid=74 rport=56209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666332.521:9288): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11697 suid=74 rport=56209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666332.590:9289): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56209 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666332.591:9290): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56209 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362666332.598:9291): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.598:9292): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11697 suid=74 rport=56209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666332.599:9293): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666332.599:9294): user pid=11696 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362666332.599:9295): pid=11696 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=358 >type=USER_ROLE_CHANGE msg=audit(1362666332.732:9296): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666332.737:9297): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666332.739:9298): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666332.739:9299): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.740:9300): user pid=11699 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11699 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666332.740:9301): user pid=11699 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11699 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362666332.741:9302): user pid=11699 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666334.739:9303): user pid=11731 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_open acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_ACQ msg=audit(1362666334.739:9304): user pid=11731 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666334.744:9305): user pid=11731 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:setcred acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666334.744:9306): user pid=11731 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:initrc_t:s0 msg='op=PAM:session_close acct="nova" exe="/sbin/runuser" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666334.751:9307): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666334.751:9308): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666334.752:9309): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666334.752:9310): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666334.752:9311): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11696 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666334.752:9312): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11696 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666334.752:9313): user pid=11696 uid=0 auid=0 ses=358 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11696 suid=0 rport=56209 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666335.040:9314): user pid=11736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11736 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666335.040:9315): user pid=11736 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11736 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666335.041:9316): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=11736 suid=74 rport=56210 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666335.041:9317): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=11736 suid=74 rport=56210 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666335.125:9318): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56210 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666335.126:9319): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56210 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362666335.133:9320): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666335.134:9321): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11736 suid=74 rport=56210 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666335.135:9322): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666335.135:9323): user pid=11735 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362666335.135:9324): pid=11735 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=359 >type=USER_ROLE_CHANGE msg=audit(1362666335.279:9325): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666335.284:9326): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666335.287:9327): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666335.287:9328): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666335.288:9329): user pid=11742 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11742 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666335.288:9330): user pid=11742 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11742 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362666335.289:9331): user pid=11742 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_CMD msg=audit(1362666419.276:9332): user pid=12074 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B2073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666419.278:9333): user pid=12074 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666419.278:9334): user pid=12074 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666419.461:9335): user pid=12074 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666419.461:9336): user pid=12074 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666419.486:9337): user pid=12079 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C206164646272206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666419.486:9338): user pid=12079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666419.487:9339): user pid=12079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666419.648:9340): user pid=12079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666419.648:9341): user pid=12079 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666419.672:9342): user pid=12083 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2073657466642062723130302030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666419.673:9343): user pid=12083 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666419.673:9344): user pid=12083 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666419.830:9345): user pid=12083 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666419.830:9346): user pid=12083 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666419.862:9347): user pid=12108 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C20737470206272313030206F6666 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666419.863:9348): user pid=12108 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666419.863:9349): user pid=12108 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666420.017:9350): user pid=12108 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666420.017:9351): user pid=12108 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666420.038:9352): user pid=12111 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B20736574206272313030207570 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666420.038:9353): user pid=12111 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666420.038:9354): user pid=12111 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666420.189:9355): user pid=12111 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666420.189:9356): user pid=12111 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666420.213:9357): user pid=12117 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2061646469662062723130302065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666420.213:9358): user pid=12117 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666420.214:9359): user pid=12117 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=ANOM_PROMISCUOUS msg=audit(1362666420.355:9360): dev=eth0 prom=256 old_prom=0 auid=0 uid=0 gid=0 ses=157 >type=SYSCALL msg=audit(1362666420.355:9360): arch=c000003e syscall=16 success=yes exit=0 a0=3 a1=89a2 a2=7fff22ff8410 a3=7fff22ff8160 items=0 ppid=12120 pid=12121 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="brctl" exe="/usr/sbin/brctl" subj=unconfined_u:system_r:brctl_t:s0 key=(null) >type=USER_END msg=audit(1362666420.361:9361): user pid=12117 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666420.361:9362): user pid=12117 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666420.401:9363): user pid=12123 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020726F7574652064656C2064656661756C7420766961203139322E3136382E3132392E31 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666420.401:9364): user pid=12123 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666420.402:9365): user pid=12123 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666420.547:9366): user pid=12123 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666420.547:9367): user pid=12123 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666420.568:9368): user pid=12126 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F772064657620657468302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666420.568:9369): user pid=12126 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666420.569:9370): user pid=12126 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666420.722:9371): user pid=12126 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666420.722:9372): user pid=12126 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666420.744:9373): user pid=12129 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722064656C203139322E3136382E3132392E332F323420627264203139322E3136382E3132392E3235352073636F706520676C6F62616C206465762065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666420.744:9374): user pid=12129 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666420.745:9375): user pid=12129 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666420.901:9376): user pid=12129 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666420.901:9377): user pid=12129 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666420.923:9378): user pid=12132 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206164647220616464203139322E3136382E3132392E332F323420627264203139322E3136382E3132392E3235352073636F706520676C6F62616C20646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666420.923:9379): user pid=12132 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666420.924:9380): user pid=12132 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666421.076:9381): user pid=12132 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666421.076:9382): user pid=12132 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666421.097:9383): user pid=12135 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020726F757465206164642064656661756C7420766961203139322E3136382E3132392E31 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666421.097:9384): user pid=12135 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666421.097:9385): user pid=12135 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666421.241:9386): user pid=12135 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666421.241:9387): user pid=12135 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666421.263:9388): user pid=12138 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666421.263:9389): user pid=12138 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666421.264:9390): user pid=12138 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666421.436:9391): user pid=12138 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666421.436:9392): user pid=12138 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666421.457:9393): user pid=12143 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666421.457:9394): user pid=12143 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666421.458:9395): user pid=12143 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666421.597:9396): table=filter family=2 entries=60 >type=SYSCALL msg=audit(1362666421.597:9396): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=2325630 items=0 ppid=12144 pid=12146 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666421.604:9397): user pid=12143 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666421.604:9398): user pid=12143 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666421.624:9399): user pid=12148 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666421.625:9400): user pid=12148 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666421.625:9401): user pid=12148 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666421.771:9402): user pid=12148 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666421.771:9403): user pid=12148 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666421.794:9404): user pid=12151 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666421.794:9405): user pid=12151 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666421.794:9406): user pid=12151 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666421.937:9407): table=mangle family=2 entries=13 >type=SYSCALL msg=audit(1362666421.937:9407): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=e0d8e0 items=0 ppid=12152 pid=12153 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666421.943:9408): user pid=12151 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666421.943:9409): user pid=12151 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666421.964:9410): user pid=12154 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666421.965:9411): user pid=12154 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666421.965:9412): user pid=12154 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666422.115:9413): user pid=12154 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666422.115:9414): user pid=12154 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666422.137:9415): user pid=12158 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666422.137:9416): user pid=12158 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666422.138:9417): user pid=12158 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666422.280:9418): table=nat family=2 entries=44 >type=SYSCALL msg=audit(1362666422.280:9418): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1da7fc0 items=0 ppid=12160 pid=12162 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666422.286:9419): user pid=12158 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666422.286:9420): user pid=12158 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666422.308:9421): user pid=12167 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662073797363746C202D77206E65742E697076342E69705F666F72776172643D31 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666422.308:9422): user pid=12167 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666422.309:9423): user pid=12167 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666422.451:9424): user pid=12167 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666422.451:9425): user pid=12167 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666422.472:9426): user pid=12170 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F77206465762062723130302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666422.472:9427): user pid=12170 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666422.472:9428): user pid=12170 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666422.615:9429): user pid=12170 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666422.615:9430): user pid=12170 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666422.636:9431): user pid=12173 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020726F7574652073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666422.636:9432): user pid=12173 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666422.637:9433): user pid=12173 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666422.783:9434): user pid=12173 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666422.784:9435): user pid=12173 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666422.805:9436): user pid=12176 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020726F7574652064656C2064656661756C7420646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666422.806:9437): user pid=12176 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666422.806:9438): user pid=12176 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666422.955:9439): user pid=12176 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666422.955:9440): user pid=12176 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666422.977:9441): user pid=12179 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722064656C203139322E3136382E3132392E332F323420627264203139322E3136382E3132392E3235352073636F706520676C6F62616C20646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666422.978:9442): user pid=12179 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666422.978:9443): user pid=12179 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666423.128:9444): user pid=12179 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666423.128:9445): user pid=12179 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666423.149:9446): user pid=12182 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206164647220616464203139322E3136382E302E312F323420627264203139322E3136382E302E32353520646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666423.149:9447): user pid=12182 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666423.149:9448): user pid=12182 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666423.296:9449): user pid=12182 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666423.296:9450): user pid=12182 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666423.319:9451): user pid=12185 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206164647220616464203139322E3136382E3132392E332F323420627264203139322E3136382E3132392E3235352073636F706520676C6F62616C20646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666423.319:9452): user pid=12185 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666423.319:9453): user pid=12185 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666423.467:9454): user pid=12185 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666423.467:9455): user pid=12185 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666423.488:9456): user pid=12188 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020726F757465206164642064656661756C7420766961203139322E3136382E3132392E31 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666423.489:9457): user pid=12188 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666423.489:9458): user pid=12188 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666423.638:9459): user pid=12188 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666423.638:9460): user pid=12188 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666423.671:9461): user pid=12192 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620464C414746494C453D5B222F7573722F73686172652F6E6F76612F6E6F76612D646973742E636F6E66222C20222F6574632F6E6F76612F6E6F76612E636F6E66225D204E4554574F524B5F49443D3120646E736D617371202D2D7374726963742D6F72646572202D2D62696E642D696E7465726661636573202D2D636F6E662D66696C653D202D2D646F6D61696E3D6E6F76616C6F63616C202D2D7069642D66696C653D2F7661722F6C69622F6E6F76612F6E6574776F726B732F6E6F76612D62723130302E706964202D2D6C697374656E2D616464726573733D3139322E3136382E302E31202D2D6578636570742D696E746572666163653D6C6F202D2D646863702D72616E67653D7365743A276E6F76616E6574776F726B272C3139322E3136382E302E322C7374617469632C31323073202D2D646863702D6C656173652D6D61783D323536202D2D646863702D686F73747366696C653D2F7661722F6C69622F6E6F76612F6E6574776F726B732F6E6F76612D62723130302E636F6E66202D2D646863702D7363726970743D2F7573722F62696E2F6E6F76612D64686370627269646765202D2D6C6561736566696C652D726F terminal=? res=success' >type=CRED_ACQ msg=audit(1362666423.671:9462): user pid=12192 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666423.671:9463): user pid=12192 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666425.006:9464): user pid=12192 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666425.006:9465): user pid=12192 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666425.033:9466): user pid=12218 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666425.033:9467): user pid=12218 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666425.033:9468): user pid=12218 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666425.189:9469): user pid=12218 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666425.189:9470): user pid=12218 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666425.210:9471): user pid=12224 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666425.210:9472): user pid=12224 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666425.210:9473): user pid=12224 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666425.353:9474): table=filter family=2 entries=62 >type=SYSCALL msg=audit(1362666425.353:9474): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1d67e20 items=0 ppid=12225 pid=12232 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666425.359:9475): user pid=12224 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666425.359:9476): user pid=12224 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666425.379:9477): user pid=12234 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666425.380:9478): user pid=12234 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666425.380:9479): user pid=12234 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666425.526:9480): user pid=12234 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666425.526:9481): user pid=12234 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666425.546:9482): user pid=12239 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666425.546:9483): user pid=12239 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666425.547:9484): user pid=12239 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666425.684:9485): table=mangle family=2 entries=13 >type=SYSCALL msg=audit(1362666425.684:9485): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=25dd8e0 items=0 ppid=12240 pid=12243 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666425.692:9486): user pid=12239 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666425.692:9487): user pid=12239 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666425.712:9488): user pid=12244 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666425.712:9489): user pid=12244 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666425.713:9490): user pid=12244 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666425.861:9491): user pid=12244 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666425.861:9492): user pid=12244 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666425.883:9493): user pid=12249 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666425.883:9494): user pid=12249 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666425.883:9495): user pid=12249 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666426.026:9496): table=nat family=2 entries=44 >type=SYSCALL msg=audit(1362666426.026:9496): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=bfafc0 items=0 ppid=12250 pid=12252 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666426.032:9497): user pid=12249 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666426.033:9498): user pid=12249 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666427.020:9499): user pid=12259 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B2073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666427.023:9500): user pid=12259 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666427.023:9501): user pid=12259 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666427.185:9502): user pid=12259 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666427.185:9503): user pid=12259 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666427.205:9504): user pid=12266 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2061646469662062723130302065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666427.205:9505): user pid=12266 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666427.206:9506): user pid=12266 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666427.360:9507): user pid=12266 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666427.361:9508): user pid=12266 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666427.400:9509): user pid=12270 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F772064657620657468302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666427.400:9510): user pid=12270 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666427.400:9511): user pid=12270 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666427.547:9512): user pid=12270 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666427.547:9513): user pid=12270 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666428.282:9514): user pid=12282 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B2073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666428.283:9515): user pid=12282 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666428.283:9516): user pid=12282 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666428.428:9517): user pid=12282 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666428.428:9518): user pid=12282 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666428.447:9519): user pid=12289 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2061646469662062723130302065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666428.447:9520): user pid=12289 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666428.448:9521): user pid=12289 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666428.592:9522): user pid=12289 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666428.592:9523): user pid=12289 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666428.619:9524): user pid=12293 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F772064657620657468302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666428.619:9525): user pid=12293 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666428.619:9526): user pid=12293 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666428.769:9527): user pid=12293 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666428.769:9528): user pid=12293 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666428.982:9529): user pid=12297 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666428.982:9530): user pid=12297 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666428.983:9531): user pid=12297 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666429.160:9532): user pid=12297 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666429.161:9533): user pid=12297 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666429.181:9534): user pid=12303 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666429.182:9535): user pid=12303 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666429.182:9536): user pid=12303 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666429.327:9537): table=filter family=2 entries=66 >type=SYSCALL msg=audit(1362666429.327:9537): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=19fbc90 items=0 ppid=12304 pid=12307 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666429.334:9538): user pid=12303 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666429.334:9539): user pid=12303 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666429.351:9540): user pid=12309 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666429.351:9541): user pid=12309 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666429.352:9542): user pid=12309 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666429.499:9543): user pid=12309 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666429.499:9544): user pid=12309 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666429.519:9545): user pid=12317 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666429.520:9546): user pid=12317 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666429.520:9547): user pid=12317 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666429.663:9548): table=mangle family=2 entries=13 >type=SYSCALL msg=audit(1362666429.663:9548): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1438a60 items=0 ppid=12319 pid=12321 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666429.672:9549): user pid=12317 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666429.672:9550): user pid=12317 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666429.690:9551): user pid=12322 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666429.690:9552): user pid=12322 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666429.691:9553): user pid=12322 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666429.840:9554): user pid=12322 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666429.840:9555): user pid=12322 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666429.858:9556): user pid=12333 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666429.858:9557): user pid=12333 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666429.859:9558): user pid=12333 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666429.998:9559): table=nat family=2 entries=44 >type=SYSCALL msg=audit(1362666429.998:9559): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=b6f890 items=0 ppid=12334 pid=12336 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666430.004:9560): user pid=12333 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666430.005:9561): user pid=12333 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666431.618:9562): user pid=12361 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666431.618:9563): user pid=12361 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666431.618:9564): user pid=12361 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666431.767:9565): user pid=12361 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666431.767:9566): user pid=12361 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666431.788:9567): user pid=12366 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666431.789:9568): user pid=12366 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666431.789:9569): user pid=12366 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666431.933:9570): table=filter family=2 entries=85 >type=SYSCALL msg=audit(1362666431.933:9570): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1770c40 items=0 ppid=12367 pid=12379 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666431.939:9571): user pid=12366 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666431.939:9572): user pid=12366 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666431.957:9573): user pid=12381 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666431.958:9574): user pid=12381 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666431.958:9575): user pid=12381 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666432.103:9576): user pid=12381 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666432.103:9577): user pid=12381 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666432.123:9578): user pid=12391 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666432.123:9579): user pid=12391 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666432.123:9580): user pid=12391 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666432.262:9581): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666432.262:9581): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=f36c30 items=0 ppid=12392 pid=12393 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666432.269:9582): user pid=12391 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666432.269:9583): user pid=12391 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666432.286:9584): user pid=12394 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666432.286:9585): user pid=12394 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666432.286:9586): user pid=12394 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666432.439:9587): user pid=12394 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666432.439:9588): user pid=12394 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666432.458:9589): user pid=12398 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666432.458:9590): user pid=12398 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666432.458:9591): user pid=12398 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666432.599:9592): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666432.599:9592): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1a841d0 items=0 ppid=12399 pid=12400 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666432.607:9593): user pid=12398 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666432.607:9594): user pid=12398 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666432.629:9595): user pid=12402 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666432.629:9596): user pid=12402 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666432.630:9597): user pid=12402 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666432.778:9598): user pid=12402 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666432.778:9599): user pid=12402 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666432.798:9600): user pid=12414 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666432.799:9601): user pid=12414 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666432.799:9602): user pid=12414 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666432.941:9603): table=filter family=2 entries=94 >type=SYSCALL msg=audit(1362666432.941:9603): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=23c7570 items=0 ppid=12415 pid=12418 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666432.948:9604): user pid=12414 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666432.948:9605): user pid=12414 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666432.966:9606): user pid=12420 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666432.966:9607): user pid=12420 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666432.967:9608): user pid=12420 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666433.111:9609): user pid=12420 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666433.111:9610): user pid=12420 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666433.129:9611): user pid=12426 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666433.130:9612): user pid=12426 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666433.130:9613): user pid=12426 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666433.271:9614): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666433.271:9614): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1e2cc30 items=0 ppid=12427 pid=12441 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666433.278:9615): user pid=12426 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666433.278:9616): user pid=12426 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666433.295:9617): user pid=12443 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666433.295:9618): user pid=12443 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666433.296:9619): user pid=12443 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666433.443:9620): user pid=12443 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666433.444:9621): user pid=12443 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666433.463:9622): user pid=12448 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666433.463:9623): user pid=12448 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666433.463:9624): user pid=12448 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666433.602:9625): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666433.602:9625): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=25de1d0 items=0 ppid=12449 pid=12453 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666433.608:9626): user pid=12448 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666433.608:9627): user pid=12448 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=VIRT_MACHINE_ID msg=audit(1362666433.657:9628): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c vm-ctx=? img-ctx=? model=stack exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_MACHINE_ID msg=audit(1362666433.657:9629): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c vm-ctx=unconfined_u:system_r:svirt_t:s0:c436,c850 img-ctx=unconfined_u:object_r:svirt_image_t:s0:c436,c850 model=selinux exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_MACHINE_ID msg=audit(1362666433.658:9630): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c vm-ctx=107:107 img-ctx=107:107 model=dac exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=ANOM_PROMISCUOUS msg=audit(1362666433.677:9631): dev=vnet0 prom=256 old_prom=0 auid=0 uid=0 gid=0 ses=157 >type=SYSCALL msg=audit(1362666433.677:9631): arch=c000003e syscall=16 success=yes exit=0 a0=1a a1=89a2 a2=7f2997bfdbb0 a3=203a2032373a6573 items=0 ppid=1 pid=7381 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="libvirtd" exe="/usr/sbin/libvirtd" subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 key=(null) >type=VIRT_RESOURCE msg=audit(1362666433.679:9632): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=net reason=open vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c net=FA:16:3E:6A:B9:31 path="/dev/net/tun" rdev=0A:C8 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=AVC msg=audit(1362666434.127:9633): avc: denied { read } for pid=12666 comm="qemu-kvm" name="1b2f18e21edadbfb7972bbbbe8d232c5392eb5b9" dev=dm-0 ino=1702204 scontext=unconfined_u:system_r:svirt_t:s0:c436,c850 tcontext=unconfined_u:object_r:nova_var_lib_t:s0 tclass=file >type=SYSCALL msg=audit(1362666434.127:9633): arch=c000003e syscall=2 success=no exit=-13 a0=7fff7b8a57b0 a1=800 a2=0 a3=0 items=0 ppid=1 pid=12666 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=157 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c436,c850 key=(null) >type=AVC msg=audit(1362666434.127:9634): avc: denied { getattr } for pid=12666 comm="qemu-kvm" path="/var/lib/nova/instances/_base/1b2f18e21edadbfb7972bbbbe8d232c5392eb5b9" dev=dm-0 ino=1702204 scontext=unconfined_u:system_r:svirt_t:s0:c436,c850 tcontext=unconfined_u:object_r:nova_var_lib_t:s0 tclass=file >type=SYSCALL msg=audit(1362666434.127:9634): arch=c000003e syscall=4 success=no exit=-13 a0=7fff7b8a57b0 a1=7fff7b8a3560 a2=7fff7b8a3560 a3=0 items=0 ppid=1 pid=12666 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=157 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c436,c850 key=(null) >type=AVC msg=audit(1362666434.127:9635): avc: denied { read } for pid=12666 comm="qemu-kvm" name="1b2f18e21edadbfb7972bbbbe8d232c5392eb5b9" dev=dm-0 ino=1702204 scontext=unconfined_u:system_r:svirt_t:s0:c436,c850 tcontext=unconfined_u:object_r:nova_var_lib_t:s0 tclass=file >type=SYSCALL msg=audit(1362666434.127:9635): arch=c000003e syscall=2 success=no exit=-13 a0=7fff7b8a57b0 a1=81000 a2=0 a3=40 items=0 ppid=1 pid=12666 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=157 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c436,c850 key=(null) >type=ANOM_PROMISCUOUS msg=audit(1362666434.172:9636): dev=vnet0 prom=0 old_prom=256 auid=0 uid=107 gid=107 ses=157 >type=VIRT_RESOURCE msg=audit(1362666434.801:9637): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=disk reason=start vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c old-disk="?" new-disk="/var/lib/nova/instances/instance-00000001/disk" exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_RESOURCE msg=audit(1362666434.801:9638): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=net reason=start vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c old-net=? new-net=FA:16:3E:6A:B9:31 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_RESOURCE msg=audit(1362666434.801:9639): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=mem reason=start vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c old-mem=0 new-mem=524288 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_RESOURCE msg=audit(1362666434.801:9640): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=vcpu reason=start vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c old-vcpu=0 new-vcpu=1 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_CONTROL msg=audit(1362666434.801:9641): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu op=start reason=booted vm="instance-00000001" uuid=3a0f08f1-75b7-4c82-a16c-5fb609fb040c vm-pid=-1 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=failed' >type=USER_CMD msg=audit(1362666435.491:9642): user pid=12767 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206B696C6C202D485550203132323135 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666435.491:9643): user pid=12767 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666435.492:9644): user pid=12767 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666435.638:9645): user pid=12767 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666435.638:9646): user pid=12767 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666435.662:9647): user pid=12772 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666435.662:9648): user pid=12772 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666435.662:9649): user pid=12772 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666435.836:9650): user pid=12772 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666435.836:9651): user pid=12772 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666435.874:9652): user pid=12776 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666435.874:9653): user pid=12776 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666435.874:9654): user pid=12776 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666436.017:9655): table=filter family=2 entries=96 >type=SYSCALL msg=audit(1362666436.017:9655): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1e0c4e0 items=0 ppid=12778 pid=12784 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666436.023:9656): user pid=12776 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666436.023:9657): user pid=12776 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666436.043:9658): user pid=12786 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666436.043:9659): user pid=12786 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666436.043:9660): user pid=12786 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666436.188:9661): user pid=12786 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666436.189:9662): user pid=12786 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666436.209:9663): user pid=12790 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666436.210:9664): user pid=12790 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666436.210:9665): user pid=12790 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666436.348:9666): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666436.348:9666): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=24f2c30 items=0 ppid=12791 pid=12797 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666436.354:9667): user pid=12790 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666436.354:9668): user pid=12790 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666436.373:9669): user pid=12798 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666436.373:9670): user pid=12798 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666436.373:9671): user pid=12798 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666436.521:9672): user pid=12798 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666436.521:9673): user pid=12798 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666436.543:9674): user pid=12802 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666436.543:9675): user pid=12802 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666436.543:9676): user pid=12802 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666436.687:9677): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666436.687:9677): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=ab1100 items=0 ppid=12803 pid=12805 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666436.694:9678): user pid=12802 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666436.694:9679): user pid=12802 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666436.726:9680): user pid=12807 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620646863705F72656C65617365206272313030203139322E3136382E302E322066613A31363A33653A36613A62393A3331 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666436.726:9681): user pid=12807 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666436.726:9682): user pid=12807 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666436.868:9683): user pid=12807 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666436.868:9684): user pid=12807 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666439.480:9685): user pid=12836 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B2073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666439.480:9686): user pid=12836 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666439.481:9687): user pid=12836 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666439.636:9688): user pid=12836 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666439.636:9689): user pid=12836 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666439.663:9690): user pid=12839 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2061646469662062723130302065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666439.663:9691): user pid=12839 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666439.664:9692): user pid=12839 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666439.844:9693): user pid=12839 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666439.844:9694): user pid=12839 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666439.884:9695): user pid=12843 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F772064657620657468302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666439.884:9696): user pid=12843 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666439.884:9697): user pid=12843 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666440.036:9698): user pid=12843 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666440.036:9699): user pid=12843 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666440.060:9700): user pid=12846 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666440.060:9701): user pid=12846 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666440.061:9702): user pid=12846 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666440.217:9703): user pid=12846 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666440.217:9704): user pid=12846 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666440.241:9705): user pid=12850 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666440.241:9706): user pid=12850 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666440.241:9707): user pid=12850 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666440.384:9708): table=filter family=2 entries=96 >type=SYSCALL msg=audit(1362666440.384:9708): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=c124e0 items=0 ppid=12851 pid=12852 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666440.392:9709): user pid=12850 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666440.392:9710): user pid=12850 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666440.412:9711): user pid=12854 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666440.412:9712): user pid=12854 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666440.412:9713): user pid=12854 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666440.560:9714): user pid=12854 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666440.560:9715): user pid=12854 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666440.580:9716): user pid=12857 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666440.580:9717): user pid=12857 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666440.580:9718): user pid=12857 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666440.715:9719): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666440.715:9719): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=abcc30 items=0 ppid=12858 pid=12859 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666440.723:9720): user pid=12857 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666440.723:9721): user pid=12857 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666440.744:9722): user pid=12860 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666440.744:9723): user pid=12860 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666440.745:9724): user pid=12860 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666440.893:9725): user pid=12860 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666440.893:9726): user pid=12860 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666440.914:9727): user pid=12864 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666440.914:9728): user pid=12864 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666440.915:9729): user pid=12864 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666441.055:9730): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666441.055:9730): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1e76100 items=0 ppid=12865 pid=12866 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666441.061:9731): user pid=12864 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666441.062:9732): user pid=12864 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666441.083:9733): user pid=12868 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662073797363746C202D77206E65742E697076342E69705F666F72776172643D31 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666441.083:9734): user pid=12868 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666441.084:9735): user pid=12868 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666441.230:9736): user pid=12868 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666441.230:9737): user pid=12868 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666441.251:9738): user pid=12871 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F77206465762062723130302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666441.251:9739): user pid=12871 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666441.252:9740): user pid=12871 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666441.402:9741): user pid=12871 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666441.402:9742): user pid=12871 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666441.446:9743): user pid=12875 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206B696C6C202D485550203132323135 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666441.447:9744): user pid=12875 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666441.447:9745): user pid=12875 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666441.597:9746): user pid=12875 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666441.598:9747): user pid=12875 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666441.622:9748): user pid=12878 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666441.622:9749): user pid=12878 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666441.623:9750): user pid=12878 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666441.772:9751): user pid=12878 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666441.772:9752): user pid=12878 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666441.794:9753): user pid=12882 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666441.794:9754): user pid=12882 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666441.795:9755): user pid=12882 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666441.933:9756): table=filter family=2 entries=96 >type=SYSCALL msg=audit(1362666441.933:9756): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=10cc4e0 items=0 ppid=12883 pid=12884 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666441.940:9757): user pid=12882 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666441.940:9758): user pid=12882 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666441.961:9759): user pid=12886 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666441.961:9760): user pid=12886 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666441.961:9761): user pid=12886 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666442.106:9762): user pid=12886 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666442.106:9763): user pid=12886 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666442.128:9764): user pid=12889 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666442.128:9765): user pid=12889 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666442.129:9766): user pid=12889 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666442.266:9767): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666442.266:9767): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=790c30 items=0 ppid=12890 pid=12891 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666442.274:9768): user pid=12889 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666442.274:9769): user pid=12889 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666442.293:9770): user pid=12892 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666442.294:9771): user pid=12892 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666442.294:9772): user pid=12892 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666442.440:9773): user pid=12892 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666442.440:9774): user pid=12892 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666442.461:9775): user pid=12896 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666442.461:9776): user pid=12896 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666442.461:9777): user pid=12896 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666442.602:9778): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666442.602:9778): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=13c0100 items=0 ppid=12897 pid=12898 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666442.610:9779): user pid=12896 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666442.610:9780): user pid=12896 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666443.267:9781): user pid=12900 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B2073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666443.270:9782): user pid=12900 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666443.271:9783): user pid=12900 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666443.422:9784): user pid=12900 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666443.422:9785): user pid=12900 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666443.451:9786): user pid=12903 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2061646469662062723130302065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666443.451:9787): user pid=12903 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666443.451:9788): user pid=12903 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666443.603:9789): user pid=12903 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666443.603:9790): user pid=12903 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666443.645:9791): user pid=12907 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F772064657620657468302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666443.645:9792): user pid=12907 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666443.646:9793): user pid=12907 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666443.788:9794): user pid=12907 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666443.788:9795): user pid=12907 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666443.861:9796): user pid=12913 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662067756573746D6F756E74202D2D7277202D61202F7661722F6C69622F6E6F76612F696E7374616E6365732F696E7374616E63652D30303030303030322F6469736B202D69202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E3379 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666443.861:9797): user pid=12913 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666443.862:9798): user pid=12913 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666469.802:9799): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >type=USER_LOGOUT msg=audit(1362666469.802:9800): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >type=USER_END msg=audit(1362666469.811:9801): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666469.811:9802): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666469.811:9803): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=5118 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666469.812:9804): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=5118 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666469.812:9805): user pid=5118 uid=0 auid=0 ses=116 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=5118 suid=0 rport=56207 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666479.652:9806): user pid=12949 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12949 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666479.652:9807): user pid=12949 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12949 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666479.652:9808): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=12949 suid=74 rport=56211 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666479.653:9809): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=12949 suid=74 rport=56211 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_LOGIN msg=audit(1362666479.707:9810): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login acct=28756E6B6E6F776E207573657229 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=failed' >type=CRYPTO_KEY_USER msg=audit(1362666488.055:9811): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=12949 suid=74 rport=56211 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ERR msg=audit(1362666488.056:9812): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:bad_ident acct="?" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=failed' >type=CRYPTO_KEY_USER msg=audit(1362666488.056:9813): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12948 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666488.056:9814): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12948 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_LOGIN msg=audit(1362666488.056:9815): user pid=12948 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login acct=28696E76616C6964207573657229 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=failed' >type=CRYPTO_KEY_USER msg=audit(1362666497.410:9816): user pid=12951 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12951 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.411:9817): user pid=12951 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12951 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666497.411:9818): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=12951 suid=74 rport=56212 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666497.411:9819): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=12951 suid=74 rport=56212 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666497.478:9820): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56212 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666497.479:9821): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56212 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362666497.489:9822): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.490:9823): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=12951 suid=74 rport=56212 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666497.491:9824): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666497.491:9825): user pid=12950 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362666497.491:9826): pid=12950 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=360 >type=USER_ROLE_CHANGE msg=audit(1362666497.643:9827): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666497.648:9828): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666497.653:9829): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666497.653:9830): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.655:9831): user pid=12953 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12953 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.655:9832): user pid=12953 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12953 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362666497.656:9833): user pid=12953 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666497.726:9834): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666497.727:9835): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666497.727:9836): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666497.727:9837): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.727:9838): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12950 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.727:9839): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12950 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666497.727:9840): user pid=12950 uid=0 auid=0 ses=360 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=12950 suid=0 rport=56212 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666502.247:9841): user pid=12957 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666502.247:9842): user pid=12957 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12957 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666502.247:9843): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=12957 suid=74 rport=56213 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362666502.248:9844): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=12957 suid=74 rport=56213 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666502.314:9845): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56213 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666502.314:9846): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56213 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362666502.324:9847): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666502.324:9848): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=12957 suid=74 rport=56213 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362666502.325:9849): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362666502.325:9850): user pid=12956 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362666502.325:9851): pid=12956 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=361 >type=USER_ROLE_CHANGE msg=audit(1362666502.462:9852): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362666502.469:9853): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362666502.476:9854): user pid=12959 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=/dev/pts/0 res=success' >type=USER_START msg=audit(1362666502.476:9855): user pid=12959 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=/dev/pts/0 res=success' >type=CRYPTO_KEY_USER msg=audit(1362666502.477:9856): user pid=12959 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12959 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=pts/0 res=success' >type=CRYPTO_KEY_USER msg=audit(1362666502.477:9857): user pid=12959 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12959 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=pts/0 res=success' >type=CRED_REFR msg=audit(1362666502.478:9858): user pid=12959 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666507.497:9859): user pid=12913 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666507.497:9860): user pid=12913 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666507.541:9861): user pid=12979 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620726561646C696E6B202D6E6D202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E737368 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666507.541:9862): user pid=12979 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666507.541:9863): user pid=12979 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666507.723:9864): user pid=12979 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666507.723:9865): user pid=12979 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666507.752:9866): user pid=12982 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206D6B646972202D70202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E737368 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666507.752:9867): user pid=12982 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666507.752:9868): user pid=12982 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666507.953:9869): user pid=12982 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666507.953:9870): user pid=12982 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666507.979:9871): user pid=12985 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662063686F776E20726F6F74202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E737368 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666507.979:9872): user pid=12985 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666507.980:9873): user pid=12985 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666508.166:9874): user pid=12985 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666508.166:9875): user pid=12985 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666508.201:9876): user pid=12988 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662063686D6F6420373030202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E737368 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666508.201:9877): user pid=12988 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666508.202:9878): user pid=12988 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666508.355:9879): user pid=12988 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666508.355:9880): user pid=12988 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666508.375:9881): user pid=12991 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620726561646C696E6B202D6E6D202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E7373682F617574686F72697A65645F6B657973 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666508.375:9882): user pid=12991 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666508.375:9883): user pid=12991 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666508.529:9884): user pid=12991 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666508.529:9885): user pid=12991 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666508.547:9886): user pid=12994 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206D6B646972202D70202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E737368 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666508.548:9887): user pid=12994 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666508.548:9888): user pid=12994 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666508.733:9889): user pid=12994 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666508.733:9890): user pid=12994 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666508.752:9891): user pid=12997 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620746565202D61202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E7373682F617574686F72697A65645F6B657973 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666508.752:9892): user pid=12997 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666508.752:9893): user pid=12997 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666508.923:9894): user pid=12997 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666508.923:9895): user pid=12997 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666508.942:9896): user pid=13000 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620726561646C696E6B202D6E6D202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F6574632F73656C696E7578 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666508.942:9897): user pid=13000 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666508.943:9898): user pid=13000 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666509.112:9899): user pid=13000 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666509.112:9900): user pid=13000 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666509.129:9901): user pid=13003 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620726561646C696E6B202D65202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F6574632F73656C696E7578 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666509.129:9902): user pid=13003 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666509.129:9903): user pid=13003 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666509.286:9904): user pid=13003 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666509.286:9905): user pid=13003 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666509.306:9906): user pid=13007 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620726561646C696E6B202D6E6D202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F6D6574612E6A73 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666509.307:9907): user pid=13007 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666509.307:9908): user pid=13007 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666509.455:9909): user pid=13007 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666509.455:9910): user pid=13007 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666509.474:9911): user pid=13010 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206D6B646972202D70202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E3379 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666509.475:9912): user pid=13010 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666509.475:9913): user pid=13010 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666509.618:9914): user pid=13010 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666509.618:9915): user pid=13010 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666509.635:9916): user pid=13013 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620746565202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F6D6574612E6A73 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666509.636:9917): user pid=13013 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666509.636:9918): user pid=13013 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666509.816:9919): user pid=13013 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666509.817:9920): user pid=13013 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666509.836:9921): user pid=13016 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620726561646C696E6B202D6E6D202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E7373682F617574686F72697A65645F6B657973 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666509.837:9922): user pid=13016 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666509.837:9923): user pid=13016 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666509.993:9924): user pid=13016 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666509.994:9925): user pid=13016 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666510.012:9926): user pid=13019 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206D6B646972202D70202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E737368 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666510.013:9927): user pid=13019 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666510.013:9928): user pid=13019 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666510.167:9929): user pid=13019 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666510.167:9930): user pid=13019 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666510.184:9931): user pid=13022 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620746565202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E33792F726F6F742F2E7373682F617574686F72697A65645F6B657973 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666510.184:9932): user pid=13022 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666510.184:9933): user pid=13022 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666510.362:9934): user pid=13022 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666510.362:9935): user pid=13022 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666510.381:9936): user pid=13025 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662066757365726D6F756E74202D75202F746D702F6F70656E737461636B2D6469736B2D6D6F756E742D746D7059736A6E3379 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666510.381:9937): user pid=13025 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666510.382:9938): user pid=13025 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666510.544:9939): user pid=13025 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666510.544:9940): user pid=13025 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666511.399:9941): user pid=13047 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206970206C696E6B2073686F7720646576206272313030 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666511.399:9942): user pid=13047 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666511.399:9943): user pid=13047 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666511.553:9944): user pid=13047 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666511.553:9945): user pid=13047 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666511.574:9946): user pid=13050 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620627263746C2061646469662062723130302065746830 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666511.574:9947): user pid=13050 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666511.574:9948): user pid=13050 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666511.723:9949): user pid=13050 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666511.724:9950): user pid=13050 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666511.754:9951): user pid=13054 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620697020616464722073686F772064657620657468302073636F706520676C6F62616C terminal=? res=success' >type=CRED_ACQ msg=audit(1362666511.755:9952): user pid=13054 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666511.756:9953): user pid=13054 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666511.897:9954): user pid=13054 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666511.897:9955): user pid=13054 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666512.040:9956): user pid=13057 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666512.041:9957): user pid=13057 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666512.041:9958): user pid=13057 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666512.214:9959): user pid=13057 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666512.214:9960): user pid=13057 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666512.235:9961): user pid=13061 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666512.236:9962): user pid=13061 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666512.236:9963): user pid=13061 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666512.379:9964): table=filter family=2 entries=96 >type=SYSCALL msg=audit(1362666512.379:9964): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=cf5de0 items=0 ppid=13062 pid=13063 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666512.386:9965): user pid=13061 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666512.386:9966): user pid=13061 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666512.403:9967): user pid=13065 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666512.403:9968): user pid=13065 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666512.403:9969): user pid=13065 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666512.551:9970): user pid=13065 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666512.552:9971): user pid=13065 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666512.570:9972): user pid=13068 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666512.570:9973): user pid=13068 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666512.571:9974): user pid=13068 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666512.709:9975): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666512.709:9975): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=dffc30 items=0 ppid=13069 pid=13070 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666512.716:9976): user pid=13068 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666512.716:9977): user pid=13068 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666512.735:9978): user pid=13071 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666512.736:9979): user pid=13071 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666512.736:9980): user pid=13071 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666512.883:9981): user pid=13071 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666512.883:9982): user pid=13071 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666512.901:9983): user pid=13075 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666512.902:9984): user pid=13075 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666512.902:9985): user pid=13075 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666513.041:9986): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666513.041:9986): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=155f1d0 items=0 ppid=13076 pid=13077 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666513.048:9987): user pid=13075 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666513.048:9988): user pid=13075 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666513.069:9989): user pid=13079 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666513.069:9990): user pid=13079 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666513.069:9991): user pid=13079 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666513.215:9992): user pid=13079 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666513.215:9993): user pid=13079 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666513.235:9994): user pid=13083 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666513.235:9995): user pid=13083 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666513.235:9996): user pid=13083 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666513.373:9997): table=filter family=2 entries=105 >type=SYSCALL msg=audit(1362666513.373:9997): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1e72350 items=0 ppid=13084 pid=13085 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666513.381:9998): user pid=13083 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666513.381:9999): user pid=13083 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666513.397:10000): user pid=13087 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666513.398:10001): user pid=13087 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666513.398:10002): user pid=13087 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666513.541:10003): user pid=13087 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666513.541:10004): user pid=13087 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666513.557:10005): user pid=13090 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666513.558:10006): user pid=13090 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666513.558:10007): user pid=13090 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666513.693:10008): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666513.693:10008): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=de8c30 items=0 ppid=13091 pid=13092 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666513.701:10009): user pid=13090 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666513.702:10010): user pid=13090 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666513.719:10011): user pid=13093 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666513.719:10012): user pid=13093 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666513.719:10013): user pid=13093 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666513.866:10014): user pid=13093 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666513.866:10015): user pid=13093 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666513.885:10016): user pid=13097 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666513.885:10017): user pid=13097 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666513.885:10018): user pid=13097 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666514.027:10019): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666514.027:10019): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=9ed1d0 items=0 ppid=13098 pid=13099 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666514.037:10020): user pid=13097 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666514.037:10021): user pid=13097 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=VIRT_MACHINE_ID msg=audit(1362666514.073:10022): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b vm-ctx=? img-ctx=? model=stack exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_MACHINE_ID msg=audit(1362666514.073:10023): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b vm-ctx=unconfined_u:system_r:svirt_t:s0:c125,c604 img-ctx=unconfined_u:object_r:svirt_image_t:s0:c125,c604 model=selinux exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_MACHINE_ID msg=audit(1362666514.073:10024): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b vm-ctx=107:107 img-ctx=107:107 model=dac exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=ANOM_PROMISCUOUS msg=audit(1362666514.093:10025): dev=vnet0 prom=256 old_prom=0 auid=0 uid=0 gid=0 ses=157 >type=SYSCALL msg=audit(1362666514.093:10025): arch=c000003e syscall=16 success=yes exit=0 a0=1a a1=89a2 a2=7f29985febb0 a3=203a2032373a6573 items=0 ppid=1 pid=7380 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="libvirtd" exe="/usr/sbin/libvirtd" subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 key=(null) >type=VIRT_RESOURCE msg=audit(1362666514.096:10026): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=net reason=open vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b net=FA:16:3E:1B:B4:4B path="/dev/net/tun" rdev=0A:C8 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=AVC msg=audit(1362666514.490:10027): avc: denied { read } for pid=13304 comm="qemu-kvm" name="1b2f18e21edadbfb7972bbbbe8d232c5392eb5b9" dev=dm-0 ino=1702204 scontext=unconfined_u:system_r:svirt_t:s0:c125,c604 tcontext=unconfined_u:object_r:nova_var_lib_t:s0 tclass=file >type=SYSCALL msg=audit(1362666514.490:10027): arch=c000003e syscall=2 success=no exit=-13 a0=7fff6ce1aec0 a1=800 a2=0 a3=0 items=0 ppid=1 pid=13304 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=157 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c125,c604 key=(null) >type=AVC msg=audit(1362666514.490:10028): avc: denied { getattr } for pid=13304 comm="qemu-kvm" path="/var/lib/nova/instances/_base/1b2f18e21edadbfb7972bbbbe8d232c5392eb5b9" dev=dm-0 ino=1702204 scontext=unconfined_u:system_r:svirt_t:s0:c125,c604 tcontext=unconfined_u:object_r:nova_var_lib_t:s0 tclass=file >type=SYSCALL msg=audit(1362666514.490:10028): arch=c000003e syscall=4 success=no exit=-13 a0=7fff6ce1aec0 a1=7fff6ce18c70 a2=7fff6ce18c70 a3=0 items=0 ppid=1 pid=13304 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=157 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c125,c604 key=(null) >type=AVC msg=audit(1362666514.490:10029): avc: denied { read } for pid=13304 comm="qemu-kvm" name="1b2f18e21edadbfb7972bbbbe8d232c5392eb5b9" dev=dm-0 ino=1702204 scontext=unconfined_u:system_r:svirt_t:s0:c125,c604 tcontext=unconfined_u:object_r:nova_var_lib_t:s0 tclass=file >type=SYSCALL msg=audit(1362666514.490:10029): arch=c000003e syscall=2 success=no exit=-13 a0=7fff6ce1aec0 a1=81000 a2=0 a3=40 items=0 ppid=1 pid=13304 auid=0 uid=107 gid=107 euid=107 suid=107 fsuid=107 egid=107 sgid=107 fsgid=107 tty=(none) ses=157 comm="qemu-kvm" exe="/usr/libexec/qemu-kvm" subj=unconfined_u:system_r:svirt_t:s0:c125,c604 key=(null) >type=ANOM_PROMISCUOUS msg=audit(1362666514.514:10030): dev=vnet0 prom=0 old_prom=256 auid=0 uid=107 gid=107 ses=157 >type=VIRT_RESOURCE msg=audit(1362666515.083:10031): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=disk reason=start vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b old-disk="?" new-disk="/var/lib/nova/instances/instance-00000002/disk" exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_RESOURCE msg=audit(1362666515.083:10032): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=net reason=start vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b old-net=? new-net=FA:16:3E:1B:B4:4B exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_RESOURCE msg=audit(1362666515.083:10033): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=mem reason=start vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b old-mem=0 new-mem=524288 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_RESOURCE msg=audit(1362666515.083:10034): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu resrc=vcpu reason=start vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b old-vcpu=0 new-vcpu=1 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=success' >type=VIRT_CONTROL msg=audit(1362666515.083:10035): user pid=7379 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='virt=qemu op=start reason=booted vm="instance-00000002" uuid=7367056e-119c-4774-b662-f6bbf78ac72b vm-pid=-1 exe="/usr/sbin/libvirtd" hostname=? addr=? terminal=? res=failed' >type=USER_CMD msg=audit(1362666515.598:10036): user pid=13388 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206B696C6C202D485550203132323135 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666515.600:10037): user pid=13388 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666515.601:10038): user pid=13388 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666515.746:10039): user pid=13388 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666515.746:10040): user pid=13388 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666515.771:10041): user pid=13391 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666515.771:10042): user pid=13391 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666515.771:10043): user pid=13391 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666515.940:10044): user pid=13391 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666515.940:10045): user pid=13391 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666515.964:10046): user pid=13395 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666515.964:10047): user pid=13395 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666515.964:10048): user pid=13395 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666516.111:10049): table=filter family=2 entries=105 >type=SYSCALL msg=audit(1362666516.111:10049): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1cc2190 items=0 ppid=13396 pid=13397 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666516.119:10050): user pid=13395 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666516.119:10051): user pid=13395 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666516.140:10052): user pid=13399 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666516.140:10053): user pid=13399 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666516.141:10054): user pid=13399 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666516.285:10055): user pid=13399 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666516.285:10056): user pid=13399 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666516.307:10057): user pid=13402 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666516.307:10058): user pid=13402 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666516.308:10059): user pid=13402 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666516.445:10060): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666516.445:10060): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=b7fc30 items=0 ppid=13403 pid=13404 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666516.452:10061): user pid=13402 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666516.452:10062): user pid=13402 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666516.473:10063): user pid=13405 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666516.473:10064): user pid=13405 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666516.473:10065): user pid=13405 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666516.619:10066): user pid=13405 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666516.619:10067): user pid=13405 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666516.640:10068): user pid=13409 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666516.640:10069): user pid=13409 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666516.640:10070): user pid=13409 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666516.779:10071): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666516.779:10071): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1d2c100 items=0 ppid=13410 pid=13411 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666516.787:10072): user pid=13409 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666516.787:10073): user pid=13409 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666516.814:10074): user pid=13413 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E6620646863705F72656C65617365206272313030203139322E3136382E302E322066613A31363A33653A31623A62343A3462 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666516.814:10075): user pid=13413 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666516.814:10076): user pid=13413 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666516.963:10077): user pid=13413 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666516.963:10078): user pid=13413 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666531.710:10079): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362666531.710:10080): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362666531.711:10081): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGOUT msg=audit(1362666531.711:10082): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362666531.711:10083): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=11735 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666531.711:10084): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=11735 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362666531.711:10085): user pid=11735 uid=0 auid=0 ses=359 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=11735 suid=0 rport=56210 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_CMD msg=audit(1362666532.338:10086): user pid=13474 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E66206B696C6C202D485550203132323135 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666532.340:10087): user pid=13474 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666532.341:10088): user pid=13474 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666532.487:10089): user pid=13474 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666532.487:10090): user pid=13474 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666532.616:10091): user pid=13477 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666532.617:10092): user pid=13477 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666532.617:10093): user pid=13477 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666532.773:10094): user pid=13477 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666532.774:10095): user pid=13477 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666532.798:10096): user pid=13481 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666532.798:10097): user pid=13481 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666532.799:10098): user pid=13481 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666532.940:10099): table=filter family=2 entries=105 >type=SYSCALL msg=audit(1362666532.940:10099): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=b29190 items=0 ppid=13482 pid=13483 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666532.948:10100): user pid=13481 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666532.948:10101): user pid=13481 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666532.968:10102): user pid=13485 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666532.968:10103): user pid=13485 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666532.969:10104): user pid=13485 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666533.111:10105): user pid=13485 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666533.111:10106): user pid=13485 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666533.132:10107): user pid=13488 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666533.133:10108): user pid=13488 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666533.133:10109): user pid=13488 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666533.271:10110): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666533.271:10110): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1973c30 items=0 ppid=13489 pid=13490 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666533.279:10111): user pid=13488 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666533.279:10112): user pid=13488 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666533.300:10113): user pid=13491 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666533.300:10114): user pid=13491 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666533.300:10115): user pid=13491 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666533.447:10116): user pid=13491 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666533.447:10117): user pid=13491 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666533.467:10118): user pid=13495 uid=162 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666533.468:10119): user pid=13495 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666533.468:10120): user pid=13495 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666533.608:10121): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666533.608:10121): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=1c09100 items=0 ppid=13496 pid=13497 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=157 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0 key=(null) >type=USER_END msg=audit(1362666533.616:10122): user pid=13495 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666533.616:10123): user pid=13495 uid=0 auid=0 ses=157 subj=unconfined_u:system_r:nova_network_t:s0 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666533.854:10124): user pid=13499 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D742066696C746572 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666533.855:10125): user pid=13499 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666533.855:10126): user pid=13499 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666534.016:10127): user pid=13499 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666534.017:10128): user pid=13499 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666534.048:10129): user pid=13503 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666534.048:10130): user pid=13503 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666534.049:10131): user pid=13503 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666534.191:10132): table=filter family=2 entries=105 >type=SYSCALL msg=audit(1362666534.191:10132): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=81abd0 items=0 ppid=13504 pid=13505 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666534.198:10133): user pid=13503 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666534.198:10134): user pid=13503 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666534.216:10135): user pid=13507 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206D616E676C65 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666534.217:10136): user pid=13507 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666534.217:10137): user pid=13507 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666534.362:10138): user pid=13507 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666534.362:10139): user pid=13507 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666534.380:10140): user pid=13510 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666534.381:10141): user pid=13510 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666534.381:10142): user pid=13510 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666534.518:10143): table=mangle family=2 entries=16 >type=SYSCALL msg=audit(1362666534.518:10143): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=b89c30 items=0 ppid=13511 pid=13512 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666534.526:10144): user pid=13510 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666534.526:10145): user pid=13510 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666534.544:10146): user pid=13513 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D73617665202D63202D74206E6174 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666534.545:10147): user pid=13513 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666534.546:10148): user pid=13513 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362666534.692:10149): user pid=13513 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666534.692:10150): user pid=13513 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_CMD msg=audit(1362666534.711:10151): user pid=13517 uid=162 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='cwd="/" cmd=6E6F76612D726F6F7477726170202F6574632F6E6F76612F726F6F74777261702E636F6E662069707461626C65732D726573746F7265202D63 terminal=? res=success' >type=CRED_ACQ msg=audit(1362666534.712:10152): user pid=13517 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_START msg=audit(1362666534.712:10153): user pid=13517 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=NETFILTER_CFG msg=audit(1362666534.852:10154): table=nat family=2 entries=59 >type=SYSCALL msg=audit(1362666534.852:10154): arch=c000003e syscall=54 success=yes exit=0 a0=3 a1=0 a2=40 a3=249a1d0 items=0 ppid=13518 pid=13519 auid=0 uid=0 gid=0 euid=0 suid=0 fsuid=0 egid=0 sgid=0 fsgid=0 tty=(none) ses=358 comm="iptables-restor" exe="/sbin/iptables-multi-1.4.7" subj=unconfined_u:system_r:iptables_t:s0-s0:c0.c1023 key=(null) >type=USER_END msg=audit(1362666534.859:10155): user pid=13517 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=CRED_DISP msg=audit(1362666534.859:10156): user pid=13517 uid=0 auid=0 ses=358 subj=unconfined_u:system_r:virtd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/bin/sudo" hostname=? addr=? terminal=? res=success' >type=USER_END msg=audit(1362667086.570:10157): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >type=USER_LOGOUT msg=audit(1362667086.570:10158): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >type=USER_END msg=audit(1362667086.582:10159): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362667086.582:10160): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362667086.582:10161): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=12956 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362667086.582:10162): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=12956 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362667086.582:10163): user pid=12956 uid=0 auid=0 ses=361 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=12956 suid=0 rport=56213 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668236.120:10164): user pid=13551 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=13551 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668236.120:10165): user pid=13551 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=13551 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362668236.122:10166): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=13551 suid=74 rport=56214 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362668236.122:10167): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=13551 suid=74 rport=56214 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362668236.191:10168): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56214 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362668236.192:10169): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56214 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362668236.200:10170): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362668236.201:10171): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=13551 suid=74 rport=56214 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362668236.202:10172): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362668236.202:10173): user pid=13550 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362668236.202:10174): pid=13550 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=362 >type=USER_ROLE_CHANGE msg=audit(1362668236.351:10175): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362668236.356:10176): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362668236.364:10177): user pid=13553 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=/dev/pts/0 res=success' >type=USER_START msg=audit(1362668236.365:10178): user pid=13553 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=/dev/pts/0 res=success' >type=CRYPTO_KEY_USER msg=audit(1362668236.365:10179): user pid=13553 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=13553 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=pts/0 res=success' >type=CRYPTO_KEY_USER msg=audit(1362668236.365:10180): user pid=13553 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=13553 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=pts/0 res=success' >type=CRED_REFR msg=audit(1362668236.366:10181): user pid=13553 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_END msg=audit(1362668237.569:10182): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >type=USER_LOGOUT msg=audit(1362668237.569:10183): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=? addr=? terminal=/dev/pts/0 res=success' >type=USER_END msg=audit(1362668237.571:10184): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_close acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRED_DISP msg=audit(1362668237.571:10185): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362668237.571:10186): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=13550 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668237.571:10187): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=13550 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668237.571:10188): user pid=13550 uid=0 auid=0 ses=362 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=13550 suid=0 rport=56214 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668248.923:10189): user pid=13567 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=13567 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668248.923:10190): user pid=13567 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=13567 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362668248.924:10191): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-client cipher=aes128-ctr ksize=128 spid=13567 suid=74 rport=56215 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_SESSION msg=audit(1362668248.924:10192): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=start direction=from-server cipher=aes128-ctr ksize=128 spid=13567 suid=74 rport=56215 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362668248.991:10193): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=pubkey_auth rport=56215 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362668248.991:10194): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=key algo=ssh-rsa size=2048 fp=f3:2c:03:53:0f:8c:4b:c8:9f:18:ab:d7:16:93:c6:b8 rport=56215 acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_ACCT msg=audit(1362668249.000:10195): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:accounting acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362668249.000:10196): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=session fp=? direction=both spid=13567 suid=74 rport=56215 laddr=192.168.129.3 lport=22 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=USER_AUTH msg=audit(1362668249.001:10197): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=success acct="root" exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=ssh res=success' >type=CRED_ACQ msg=audit(1362668249.001:10198): user pid=13566 uid=0 auid=4294967295 ses=4294967295 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=LOGIN msg=audit(1362668249.001:10199): pid=13566 uid=0 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 old auid=4294967295 new auid=0 old ses=4294967295 new ses=363 >type=USER_ROLE_CHANGE msg=audit(1362668249.131:10200): user pid=13566 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='pam: default-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 selected-context=unconfined_u:unconfined_r:unconfined_t:s0-s0:c0.c1023 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362668249.138:10201): user pid=13566 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:session_open acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_LOGIN msg=audit(1362668249.140:10202): user pid=13566 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=USER_START msg=audit(1362668249.140:10203): user pid=13566 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=login id=0 exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success' >type=CRYPTO_KEY_USER msg=audit(1362668249.141:10204): user pid=13569 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=67:22:f4:71:53:ac:b7:18:90:fd:32:b7:1d:54:21:ed direction=? spid=13569 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRYPTO_KEY_USER msg=audit(1362668249.141:10205): user pid=13569 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=74:0a:1f:ce:e2:ec:aa:21:bd:33:22:6b:f4:f9:b5:31 direction=? spid=13569 suid=0 exe="/usr/sbin/sshd" hostname=? addr=192.168.129.1 terminal=? res=success' >type=CRED_REFR msg=audit(1362668249.142:10206): user pid=13569 uid=0 auid=0 ses=363 subj=system_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=PAM:setcred acct="root" exe="/usr/sbin/sshd" hostname=192.168.129.1 addr=192.168.129.1 terminal=ssh res=success'
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 919074
: 706656