Bug 1270927
| Summary: | ksu doesn't properly log auth failures | |||
|---|---|---|---|---|
| Product: | Red Hat Enterprise Linux 7 | Reporter: | Pat Riehecky <riehecky> | |
| Component: | krb5 | Assignee: | Robbie Harwood <rharwood> | |
| Status: | CLOSED ERRATA | QA Contact: | Filip Dvorak <fdvorak> | |
| Severity: | unspecified | Docs Contact: | ||
| Priority: | low | |||
| Version: | 7.1 | CC: | csieh, dpal, misterbonnie, pasik, riehecky | |
| Target Milestone: | rc | |||
| Target Release: | --- | |||
| Hardware: | All | |||
| OS: | Linux | |||
| URL: | https://github.com/krb5/krb5/pull/776 | |||
| Whiteboard: | ||||
| Fixed In Version: | krb5-1.15.1-45.el7 | Doc Type: | No Doc Update | |
| Doc Text: | Story Points: | --- | ||
| Clone Of: | ||||
| : | 1575771 (view as bug list) | Environment: | ||
| Last Closed: | 2020-03-31 19:41:21 UTC | Type: | Bug | |
| Regression: | --- | Mount Type: | --- | |
| Documentation: | --- | CRM: | ||
| Verified Versions: | Category: | --- | ||
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | ||
| Cloudforms Team: | --- | Target Upstream Version: | ||
| Embargoed: | ||||
| Bug Depends On: | 1575771 | |||
| Bug Blocks: | ||||
|
Description
Pat Riehecky
2015-10-12 17:12:42 UTC
My read of the current state is:
- If the source user is root, no message will be logged.
- If the source user is not root and there's no cmd, a successful or failed auth message is logged.
- If the source user is not root, there's a command, and auth succeds, a message is logged (syslog at NOTICE) which says something like
"Account TARGET: authorization for CLIENT for execution of CMD successful".
- If the source user is not root, there's a command, and auth fails, a message is logged (syslog at WARNING) which says something like
"Account TARGET: authorization for CLIENT for execution of CMD failed".
Does that match what you're seeing? And if so, what part of that (if any) are you requesting improvement in?
I'm not seeing the second two (Account TARGET:...) appear in syslog.
$ ksu testuser -e /bin/ls
account testuser: authorization failed
However, I don't show anything logged to secure or messages for execution for non-root target accounts.
I do show a success message for running as root:
$ ksu -e /bin/ls
Authenticated riehecky
Account root: authorization for riehecky for execution of
/bin/ls successful
==> messages <==
Apr 12 08:18:30 test ksu[396]: Account root: authorization for riehecky for execution of /bin/ls successful
I definitely see the non-root success: may 07 14:50:16 freeipa.rharwood.biz ksu[1769]: 'ksu left' authenticated right for right on /dev/pts/0 may 07 14:50:16 freeipa.rharwood.biz ksu[1769]: Account left: authorization for right for execution of /bin/ls successful Failures for non-root users (regardless of whether they're running a command, or their target user) don't seem to show up. Let me see what I can do. Just to double-check - the non-root success and failure logging as described in comment#4 would meet your requirements, right? And currently the only missing part of that is the failure logging? That is all correct. Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. https://access.redhat.com/errata/RHBA-2020:1029 |