Bug 170568 - add audit message to sshd
Summary: add audit message to sshd
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: openssh
Version: 4.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
: ---
Assignee: Tomas Mraz
QA Contact: Brian Brock
URL:
Whiteboard:
Depends On: 170495
Blocks: 168429
TreeView+ depends on / blocked
 
Reported: 2005-10-12 22:06 UTC by Steve Grubb
Modified: 2007-11-30 22:07 UTC (History)
1 user (show)

Fixed In Version: RHSA-2006-0044
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-03-07 16:51:34 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)
rawhide patch that's being tested. (6.11 KB, patch)
2005-10-28 13:25 UTC, Steve Grubb
no flags Details | Diff


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2006:0044 0 qe-ready SHIPPED_LIVE Low: openssh security update 2006-03-07 05:00:00 UTC

Description Steve Grubb 2005-10-12 22:06:18 UTC
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050922 Fedora/1.0.7-1.1.fc4 Firefox/1.0.7

Description of problem:
We need a message added to sshd to show the fact that a login was attempted and what the results are. Its possible under the current system but very clumsy to figure out logins. This is not conducive to writing automatic reporting tools.

Version-Release number of selected component (if applicable):


How reproducible:
Always

Steps to Reproduce:
1. login
2. look for it in audit logs
3.
  

Actual Results:  You get a pam session open message. cron also opens pam session and doesn't login, so its hard to spot logins when looking for success/fail with current audit tools.

Additional info:

I will provide a small patch that fixes this.

Comment 5 Steve Grubb 2005-10-28 13:25:08 UTC
Created attachment 120505 [details]
rawhide patch that's being tested.

I'm attaching a patch that I've been testing for rawhide. This patch will need
to be adjusted for RHE4's openssh. Also, this patch depends on bug 170495.

Comment 9 Steve Grubb 2005-11-21 18:25:26 UTC
audit-1.0.12 is now supposed to be in the RHEL4 build root. Please update any
Requires or BuildRequires to that version. Let me know if you have any problems

Comment 13 Red Hat Bugzilla 2006-03-07 16:51:35 UTC
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.

http://rhn.redhat.com/errata/RHSA-2006-0044.html



Note You need to log in before you can comment on or make changes to this bug.