All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steve Grubb <sgrubb@redhat.com>
To: linux-audit@redhat.com
Subject: Re: audisp-prelude login question
Date: Thu, 30 Oct 2008 14:07:07 -0400	[thread overview]
Message-ID: <200810301407.08084.sgrubb@redhat.com> (raw)
In-Reply-To: <1225376952.9388.341.camel@homeserver>

On Thursday 30 October 2008 10:29:12 LC Bruzenak wrote:
> So I went back to the gdm session which audits. I thought if I could see
> the strace from that I'd know what to look for on the failing one. Here
> is the USER_LOGIN event:
> node=hugo type=USER_LOGIN msg=audit(10/30/2008 08:55:53.356:278784) : user
> pid=7417 uid=root auid=lenny subj=system_u:system_r:xdm_t:s0-s15:c0.c1023
> msg='uid=lenny exe=/usr/libexec/gdm-session-worker (hostname=, addr=?,
> terminal=/dev/tty7 res=success)'

OK, so i just remembered that I patched gdm, login, and sshd specifically to 
send the USER_LOGIN event. I did not patch xdm or kdm or shadow-utils login. 
So, I think it will need to be patched to send this one event.

-Steve

      reply	other threads:[~2008-10-30 18:07 UTC|newest]

Thread overview: 6+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2008-10-30  2:28 audisp-prelude login question LC Bruzenak
2008-10-30  3:27 ` LC Bruzenak
2008-10-30 10:34 ` Steve Grubb
2008-10-30 12:46   ` LC Bruzenak
2008-10-30 14:29     ` LC Bruzenak
2008-10-30 18:07       ` Steve Grubb [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=200810301407.08084.sgrubb@redhat.com \
    --to=sgrubb@redhat.com \
    --cc=linux-audit@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.