Bug 121507
Summary: | FC1 syslog.conf logs auth msgs to /var/log/messages | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Need Real Name <vader> |
Component: | sysklogd | Assignee: | Jason Vas Dias <jvdias> |
Status: | CLOSED CURRENTRELEASE | QA Contact: | Brian Brock <bbrock> |
Severity: | medium | Docs Contact: | |
Priority: | medium | ||
Version: | 1 | Keywords: | Security |
Target Milestone: | --- | ||
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Bug Fix | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2004-08-04 14:33:34 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: |
Description
Need Real Name
2004-04-22 07:49:54 UTC
What changed from authpriv to auth? What specific messages do you see? From su and login, for example: Apr 22 16:54:50 host su(pam_unix)[2716]: session opened for user root by vader(uid=0) Apr 22 16:54:50 host su(pam_unix)[2716]: session closed for user root Apr 22 16:54:58 host login(pam_unix)[1047]: session opened for user root by LOGIN(uid=0) Apr 22 16:54:58 host -- root[1047]: ROOT LOGIN ON tty1 Apr 22 16:55:02 host login(pam_unix)[1047]: session closed for user root In fc2+, syslog.conf is now: " # Don't log private authentication messages! *.info;mail.none;news.none;authpriv.none;cron.none /var/log/messages # The authpriv file has restricted access. authpriv.* /var/log/secure " These messages: Apr 22 16:54:50 host su(pam_unix)[2716]: session closed for user root Apr 22 16:54:50 host su(pam_unix)[2716]: session closed for user root are auth.info messages; users can direct them elsewhere using syslog.conf, but by default they are caught by *.info;... /var/log/messages |