From mboxrd@z Thu Jan 1 00:00:00 1970 From: Miloslav Trmac Subject: Re: pam_tty_audit Date: Wed, 12 Dec 2012 06:46:16 -0500 (EST) Message-ID: <1835115808.46519974.1355312776198.JavaMail.root@redhat.com> References: Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============5235365964985913665==" Return-path: Received: from mx3-phx2.redhat.com (mx01.colomx.prod.int.phx2.redhat.com [10.5.7.1]) by int-mx02.intmail.prod.int.phx2.redhat.com (8.13.8/8.13.8) with ESMTP id qBCBkGpK029243 for ; Wed, 12 Dec 2012 06:46:16 -0500 In-Reply-To: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Pieter Baele Cc: linux-audit@redhat.com List-Id: linux-audit@redhat.com --===============5235365964985913665== Content-Type: multipart/alternative; boundary="----=_Part_46519973_1720830451.1355312776197" ------=_Part_46519973_1720830451.1355312776197 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 7bit Hello, ----- Original Message ----- > But if user1 does log on, no commands are logged.... Are you talking about TTY or USER_TTY records, and are you checking immediately after entering the command, or after exiting the session? Unprivileged users are not allowed to send USER_TTY records as each command is entered, so the input read by unprivileged users is audited only when the (4 KB) buffer is flushed or the process (i.e. the shell) exits. Mirek ------=_Part_46519973_1720830451.1355312776197 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: 7bit
Hello,

But if user1 does log on, no commands are logged....

Are you talking about TTY or USER_TTY records, and are you checking immediately after entering the command, or after exiting the session?

Unprivileged users are not allowed to send USER_TTY records as each command is entered, so the input read by unprivileged users is audited only when the (4 KB) buffer is flushed or the process (i.e. the shell) exits.
    Mirek
------=_Part_46519973_1720830451.1355312776197-- --===============5235365964985913665== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============5235365964985913665==--