All of lore.kernel.org
 help / color / mirror / Atom feed
* How to capture a login event?
@ 2007-11-07 20:35 Zachary Shay
  2007-11-07 20:53 ` Steve Grubb
  0 siblings, 1 reply; 2+ messages in thread
From: Zachary Shay @ 2007-11-07 20:35 UTC (permalink / raw)
  To: linux-audit

I am fairly new to the linux audit subsystem, and have a question that 
can probably be answered in a one line response.  I'm trying to detect 
when logins (successful) and login attempts (unsuccessful) occur using 
the auditing subsystem.  Is there an auditing rule that can do this?  My 
brief research has shown a syscall, setauid(), available in BSD and 
SysV; however, it isn't implemented in linux.  Also, a rule watching the 
file "/proc/self/loginuid" will show every time the pam_loginuid.so is 
called by a point of entry...unfortunately that isn't useful because the 
uid/euid/auid is always bound to root.  Any ideas?

Thanks in advance,
Zach

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2007-11-07 20:53 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-11-07 20:35 How to capture a login event? Zachary Shay
2007-11-07 20:53 ` Steve Grubb

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.