Bug 170568

Summary: add audit message to sshd
Product: Red Hat Enterprise Linux 4 Reporter: Steve Grubb <sgrubb>
Component: opensshAssignee: Tomas Mraz <tmraz>
Status: CLOSED ERRATA QA Contact: Brian Brock <bbrock>
Severity: medium Docs Contact:
Priority: medium    
Version: 4.0CC: poelstra
Target Milestone: ---Keywords: FutureFeature
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: RHSA-2006-0044 Doc Type: Enhancement
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2006-03-07 16:51:34 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 170495    
Bug Blocks: 168429    
Attachments:
Description Flags
rawhide patch that's being tested. none

Description Steve Grubb 2005-10-12 22:06:18 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050922 Fedora/1.0.7-1.1.fc4 Firefox/1.0.7

Description of problem:
We need a message added to sshd to show the fact that a login was attempted and what the results are. Its possible under the current system but very clumsy to figure out logins. This is not conducive to writing automatic reporting tools.

Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1. login
2. look for it in audit logs
3.
  

Actual Results:  You get a pam session open message. cron also opens pam session and doesn't login, so its hard to spot logins when looking for success/fail with current audit tools.

Additional info:

I will provide a small patch that fixes this.

Comment 5 Steve Grubb 2005-10-28 13:25:08 UTC
Created attachment 120505 [details]
rawhide patch that's being tested.

I'm attaching a patch that I've been testing for rawhide. This patch will need
to be adjusted for RHE4's openssh. Also, this patch depends on bug 170495.

Comment 9 Steve Grubb 2005-11-21 18:25:26 UTC
audit-1.0.12 is now supposed to be in the RHEL4 build root. Please update any
Requires or BuildRequires to that version. Let me know if you have any problems

Comment 13 Red Hat Bugzilla 2006-03-07 16:51:35 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2006-0044.html