From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: User Login Lifecycle events Date: Thu, 20 Aug 2015 14:16:13 -0400 Message-ID: <1574639.dT3VGgdyCS@x2> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: Received: from x2.localnet (vpn-239-173.phx2.redhat.com [10.3.239.173]) by int-mx14.intmail.prod.int.phx2.redhat.com (8.14.4/8.14.4) with ESMTP id t7KIGB06030262 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO) for ; Thu, 20 Aug 2015 14:16:11 -0400 List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com List-Id: linux-audit@redhat.com Hello, I am looking for feedback and comments on a new document that I just finished that outlines the expectations of audit logging around user sessions. http://people.redhat.com/sgrubb/audit/user-login-lifecycle.txt My hope is that we can get a test suite developed that follows this to verify that applications are doing it right and consistently. This will also allow third party's to write analysis software since there is a published standard. Thanks, -Steve