From mboxrd@z Thu Jan 1 00:00:00 1970 From: Maupertuis Philippe Subject: Strange behavior with pam_tty_audit Date: Tue, 14 Nov 2017 14:29:34 +0100 Message-ID: <3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDD@FRVDX103.fr01.awl.atosorigin.net> Mime-Version: 1.0 Content-Type: multipart/mixed; boundary="===============2169335669238892465==" Return-path: Received: from mx1.redhat.com (ext-mx04.extmail.prod.ext.phx2.redhat.com [10.5.110.28]) by smtp.corp.redhat.com (Postfix) with ESMTPS id C7D9889D15 for ; Tue, 14 Nov 2017 13:29:40 +0000 (UTC) Received: from smtppost.atos.net (smtppost.atos.net [193.56.114.166]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by mx1.redhat.com (Postfix) with ESMTPS id 1578B7EA91 for ; Tue, 14 Nov 2017 13:29:38 +0000 (UTC) Content-Language: fr-FR List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: "linux-audit@redhat.com" List-Id: linux-audit@redhat.com --===============2169335669238892465== Content-Language: fr-FR Content-Type: multipart/alternative; boundary="_000_3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDDFRVDX103fr0_" --_000_3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDDFRVDX103fr0_ Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: quoted-printable Hi The auditd rules for PCI reads : ## 10.2.2 Log administrative action. To meet this, you need to enable tty ## logging. The pam config below should be placed into su and sudo pam stac= ks. ## session required pam_tty_audit.so disable=3D* enable=3Droot I have noticed that nothing happened unless I add in /etc/pam.d/sshd session required pam_tty_audit.so enable=3D* At which point I get Should it be done that way ? Did I miss something ? Philippe !!!************************************************************************= ************* "Ce message et les pi?ces jointes sont confidentiels et r?serv?s ? l'usage = exclusif de ses destinataires. Il peut ?galement ?tre prot?g? par le secret= professionnel. Si vous recevez ce message par erreur, merci d'en avertir i= mm?diatement l'exp?diteur et de le d?truire. L'int?grit? du message ne pouv= ant ?tre assur?e sur Internet, la responsabilit? de Worldline ne pourra ?tr= e recherch?e quant au contenu de ce message. Bien que les meilleurs efforts= soient faits pour maintenir cette transmission exempte de tout virus, l'ex= p?diteur ne donne aucune garantie ? cet ?gard et sa responsabilit? ne saura= it ?tre recherch?e pour tout dommage r?sultant d'un virus transmis. This e-mail and the documents attached are confidential and intended solely= for the addressee; it may also be privileged. If you receive this e-mail i= n error, please notify the sender immediately and destroy it. As its integr= ity cannot be secured on the Internet, the Worldline liability cannot be tr= iggered for the message content. Although the sender endeavours to maintain= a computer virus-free network, the sender does not warrant that this trans= mission is virus-free and will not be liable for any damages resulting from= any virus transmitted.!!!" --_000_3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDDFRVDX103fr0_ Content-Type: text/html; charset="us-ascii" Content-Transfer-Encoding: quoted-printable

Hi

The auditd rules for PCI reads = :

## 10.2.2 Log administrative ac= tion. To meet this, you need to enable tty

## logging. The pam config belo= w should be placed into su and sudo pam stacks.

## session   required= pam_tty_audit.so disable=3D* enable=3Droot

 

I have noticed  that nothi= ng happened unless I add in /etc/pam.d/sshd

session    requi= red pam_tty_audit.so enable=3D*

 

At which point I get

 

Should it be done that way ?

Did I miss something ?

 

Philippe


!!!**********************= ***************************************************************
"Ce message et les pièces jointes sont confidentiels et r&eacut= e;servés à l'usage exclusif de ses destinataires. Il peut &ea= cute;galement être protégé par le secret professionnel.= Si vous recevez ce message par erreur, merci d'en avertir immédiate= ment l'expéditeur et de le détruire. L'intégrité du message ne pouvant ê= ;tre assurée sur Internet, la responsabilité de Worldline ne = pourra être recherchée quant au contenu de ce message. Bien qu= e les meilleurs efforts soient faits pour maintenir cette transmission exem= pte de tout virus, l'expéditeur ne donne aucune garantie à cet ég= ard et sa responsabilité ne saurait être recherchée pou= r tout dommage résultant d'un virus transmis.

This e-mail and the documents attached are confidential and intended solely= for the addressee; it may also be privileged. If you receive this e-mail i= n error, please notify the sender immediately and destroy it. As its integr= ity cannot be secured on the Internet, the Worldline liability cannot be triggered for the message content. Altho= ugh the sender endeavours to maintain a computer virus-free network, the se= nder does not warrant that this transmission is virus-free and will not be = liable for any damages resulting from any virus transmitted.!!!"
--_000_3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDDFRVDX103fr0_-- --===============2169335669238892465== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline --===============2169335669238892465==-- From mboxrd@z Thu Jan 1 00:00:00 1970 From: Steve Grubb Subject: Re: Strange behavior with pam_tty_audit Date: Tue, 14 Nov 2017 08:53:02 -0500 Message-ID: <2393137.nNdHcdsWyM@x2> References: <3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDD@FRVDX103.fr01.awl.atosorigin.net> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDD@FRVDX103.fr01.awl.atosorigin.net> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: linux-audit@redhat.com Cc: Maupertuis Philippe List-Id: linux-audit@redhat.com Hello, On Tuesday, November 14, 2017 8:29:34 AM EST Maupertuis Philippe wrote: > The auditd rules for PCI reads : > ## 10.2.2 Log administrative action. To meet this, you need to enable tty > ## logging. The pam config below should be placed into su and sudo pam > stacks. ## session required pam_tty_audit.so disable=* enable=root > > I have noticed that nothing happened unless I add in /etc/pam.d/sshd > session required pam_tty_audit.so enable=* If I understand, you deleted the 'disable=*' and replaced 'root' with '*'. That would be unusual. The command line is processed from left to right. So, what should happen in the original rule is disable auditing of all users, then enable auditing of only root. PCI wants administrative actions which would only be the root user. > At which point I get > > Should it be done that way ? > Did I miss something ? It works for me as specified in the PCI rules. (Tested using su.) Note that the kernel caches the keystrokes and you do not get a 1x1 mapping of events to commands entered. You will likely get multiple commands all strung together. It only creates the event when either it fills the buffer or the user ends the privileged session. -Steve From mboxrd@z Thu Jan 1 00:00:00 1970 From: Maupertuis Philippe Subject: RE: Strange behavior with pam_tty_audit Date: Tue, 14 Nov 2017 16:47:39 +0100 Message-ID: <3D2AB1326AB2974190FCE3F69401F7900102F4CE0E31@FRVDX103.fr01.awl.atosorigin.net> References: <3D2AB1326AB2974190FCE3F69401F7900102F4CE0DDD@FRVDX103.fr01.awl.atosorigin.net> <2393137.nNdHcdsWyM@x2> Mime-Version: 1.0 Content-Type: text/plain; charset="iso-8859-1" Content-Transfer-Encoding: quoted-printable Return-path: In-Reply-To: <2393137.nNdHcdsWyM@x2> Content-Language: fr-FR List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: linux-audit-bounces@redhat.com Errors-To: linux-audit-bounces@redhat.com To: Steve Grubb , "linux-audit@redhat.com" List-Id: linux-audit@redhat.com > -----Message d'origine----- > De : Steve Grubb [mailto:sgrubb@redhat.com] > Envoy=E9 : mardi 14 novembre 2017 14:53 > =C0 : linux-audit@redhat.com > Cc : Maupertuis Philippe > Objet : Re: Strange behavior with pam_tty_audit > > Hello, > > On Tuesday, November 14, 2017 8:29:34 AM EST Maupertuis Philippe wrote: > > The auditd rules for PCI reads : > > ## 10.2.2 Log administrative action. To meet this, you need to enable > > tty ## logging. The pam config below should be placed into su and sudo > pam > > stacks. ## session required pam_tty_audit.so disable=3D* enable=3Droot > > > > I have noticed that nothing happened unless I add in /etc/pam.d/sshd > > session required pam_tty_audit.so enable=3D* > > If I understand, you deleted the 'disable=3D*' and replaced 'root' with '= *'. > That would be unusual. The command line is processed from left to right. = So, > what should happen in the original rule is disable auditing of all users,= then > enable auditing of only root. PCI wants administrative actions which would > only be the root user. > > > > At which point I get > > > > Should it be done that way ? > > Did I miss something ? > > It works for me as specified in the PCI rules. (Tested using su.) Note th= at the > kernel caches the keystrokes and you do not get a 1x1 mapping of events to > commands entered. You will likely get multiple commands all strung > together. > It only creates the event when either it fills the buffer or the user end= s the > privileged session. > I tried with su instead of sudo and it works as indicated in the doc. The same line in sudo doesn't work, it seems there is a bug with sudo I am on redhat 7.4 if that matters > -Steve !!!************************************************************************= ************* "Ce message et les pi=E8ces jointes sont confidentiels et r=E9serv=E9s =E0 = l'usage exclusif de ses destinataires. Il peut =E9galement =EAtre prot=E9g= =E9 par le secret professionnel. Si vous recevez ce message par erreur, mer= ci d'en avertir imm=E9diatement l'exp=E9diteur et de le d=E9truire. L'int= =E9grit=E9 du message ne pouvant =EAtre assur=E9e sur Internet, la responsa= bilit=E9 de Worldline ne pourra =EAtre recherch=E9e quant au contenu de ce = message. Bien que les meilleurs efforts soient faits pour maintenir cette t= ransmission exempte de tout virus, l'exp=E9diteur ne donne aucune garantie = =E0 cet =E9gard et sa responsabilit=E9 ne saurait =EAtre recherch=E9e pour = tout dommage r=E9sultant d'un virus transmis. This e-mail and the documents attached are confidential and intended solely= for the addressee; it may also be privileged. If you receive this e-mail i= n error, please notify the sender immediately and destroy it. As its integr= ity cannot be secured on the Internet, the Worldline liability cannot be tr= iggered for the message content. Although the sender endeavours to maintain= a computer virus-free network, the sender does not warrant that this trans= mission is virus-free and will not be liable for any damages resulting from= any virus transmitted.!!!"