Hide Forgot
Description of problem: After discussion with openssh developer libaudit seems to be printing an extra colon (i.e. suid=0 : ) in audit records printed by openssh with function audit_log_acct_message (according to the devel): time->Mon Mar 28 05:32:23 2011 type=CRYPTO_KEY_USER msg=audit(1301304743.056:77380): user pid=14237 uid=0 auid=0 ses=2712 subj=unconfined_u:system_r:sshd_t:s0-s0:c0.c1023 msg='op=destroy kind=server fp=72:74:bf:4e:ad:55:82:9c:ec:62:79:ae:4b:07:94:d3 direction=? spid=14237 suid=0 : exe="/usr/sbin/sshd" hostname=? addr=10.34.35.69 terminal=pts/5 res=success' Version-Release number of selected component (if applicable): audit-2.0.6-1.el6 How reproducible: 100% Steps to Reproduce: 1. try to login via ssh 2. check audit records CRYPTO_KEY_USER or CRYPTO_SESSION Actual results: Colon after suid=0 Expected results: No colon Additional info:
Sorry the correct function name should be audit_log_user_message
This function prints a colon to separate a possible text message from credentials it gathers.
So is the CRYPTO_KEY_USER record in the description ok and the colon makes "no harm" there? Then we can close this as not a bug I assume. I just wanted to be sure ...
Closing as not a bug according to previous comments.