public inbox for linux-audit@redhat.com
 help / color / mirror / Atom feed
* command logging
@ 2011-11-08 20:40 Frank Kruchio
  2011-11-08 20:59 ` Steve Grubb
  0 siblings, 1 reply; 3+ messages in thread
From: Frank Kruchio @ 2011-11-08 20:40 UTC (permalink / raw)
  To: Linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 564 bytes --]

We are running RHEL5 x86_64 and RHEL4 (32 and 64 bit) servers mostly at 
work and management like to trac every single command a user types.
So far we used rootsh but once a user types

sudo rootsh
sudo su - oracle

the oracle user commands are not logged any more.

Is there a way to trac/record a user to see what was typed using the audit 
subsystem ?


We are considering the idea now to 
> /etc/securetty
to lock root logins out 

The goal is to not have any shared IDs at all and all users should be 
identified on what they did on the servers if necessary.

[-- Attachment #1.2: Type: text/html, Size: 1008 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2011-11-08 21:31 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-11-08 20:40 command logging Frank Kruchio
2011-11-08 20:59 ` Steve Grubb
     [not found]   ` <OFA15CC340.C126AE80-ONCC257942.0073F9E8-CC257942.007440EF@nz1.ibm.com>
2011-11-08 21:31     ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox