linux-audit.redhat.com archive mirror
 help / color / mirror / Atom feed
* Auditd misses accept syscalls from sshd
@ 2016-12-02 20:43 Nathan Cooprider
  2016-12-02 21:09 ` Steve Grubb
  2016-12-02 21:26 ` Paul Moore
  0 siblings, 2 replies; 14+ messages in thread
From: Nathan Cooprider @ 2016-12-02 20:43 UTC (permalink / raw)
  To: linux-audit


[-- Attachment #1.1: Type: text/plain, Size: 741 bytes --]

Auditd seems to miss accept syscalls from ssh on Ubuntu 14. I tried
versions 2.3.2 and 2.4.5 of the daemon with kernel versions 3.13.0-96 and
4.4.0-47. In all cases the accept syscall (43) failed to show up until
after I restarted the ssh daemon. It's especially weird because I don't see
this problem on Ubuntu 16 (4.4.0-38). Any thoughts about why I am seeing
this or where to look?

I found a similar question in the archives, but it seems to do with the
architecture size and not OS versions:
https://www.redhat.com/archives/linux-audit/2015-January/msg00060.html

I also posted this question on Stack Overflow:
http://stackoverflow.com/questions/40940225/why-does-sshd-accept-syscall-have-inconsistent-behavior-in-linux-audit-framework

[-- Attachment #1.2: Type: text/html, Size: 1073 bytes --]

[-- Attachment #2: Type: text/plain, Size: 0 bytes --]



^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2016-12-05 22:44 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2016-12-02 20:43 Auditd misses accept syscalls from sshd Nathan Cooprider
2016-12-02 21:09 ` Steve Grubb
2016-12-02 21:55   ` Nathan Cooprider
2016-12-02 22:13     ` Steve Grubb
2016-12-03  2:11       ` Nathan Cooprider
2016-12-03 17:47         ` Steve Grubb
2016-12-05 16:42           ` Nathan Cooprider
2016-12-05 22:44             ` Steve Grubb
2016-12-02 21:26 ` Paul Moore
2016-12-02 21:42   ` Nathan Cooprider
2016-12-02 21:56     ` Paul Moore
2016-12-02 23:44     ` Hassan Sultan
2016-12-03  2:15       ` Nathan Cooprider
2016-12-03 17:39       ` Steve Grubb

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).