Red Hat Bugzilla – Bug 170568
add audit message to sshd
Last modified: 2007-11-30 17:07:21 EST
From Bugzilla Helper:
User-Agent: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.7.12) Gecko/20050922 Fedora/1.0.7-1.1.fc4 Firefox/1.0.7
Description of problem:
We need a message added to sshd to show the fact that a login was attempted and what the results are. Its possible under the current system but very clumsy to figure out logins. This is not conducive to writing automatic reporting tools.
Version-Release number of selected component (if applicable):
Steps to Reproduce:
2. look for it in audit logs
Actual Results: You get a pam session open message. cron also opens pam session and doesn't login, so its hard to spot logins when looking for success/fail with current audit tools.
I will provide a small patch that fixes this.
Created attachment 120505 [details]
rawhide patch that's being tested.
I'm attaching a patch that I've been testing for rawhide. This patch will need
to be adjusted for RHE4's openssh. Also, this patch depends on bug 170495.
audit-1.0.12 is now supposed to be in the RHEL4 build root. Please update any
Requires or BuildRequires to that version. Let me know if you have any problems
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.