OpenSSH
[Top] [All Lists]

Re: ssh 4.x using aix 5.3 auditing

To: openssh-unix-dev@mindrot.org
Subject: Re: ssh 4.x using aix 5.3 auditing
From: Ryan Robertson <r3r2@yahoo.com>
Date: Thu, 7 Dec 2006 19:11:52 -0800 (PST)
Delivered-to: sp-com-lists@consult.net
Delivered-to: openssh-unix-dev-list1@securepoint.com
Delivered-to: openssh-unix-dev-tmda@mindrot.org
Delivered-to: openssh-unix-dev@mindrot.org
List-archive: <http://lists.mindrot.org/pipermail/openssh-unix-dev>
List-help: <mailto:openssh-unix-dev-request@mindrot.org?subject=help>
List-id: Development of portable OpenSSH <openssh-unix-dev.mindrot.org>
List-post: <mailto:openssh-unix-dev@mindrot.org>
List-subscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=subscribe>
List-unsubscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=unsubscribe>
Sender: openssh-unix-dev-bounces+openssh-unix-dev-list1=securepoint.com@mindrot.org
The only way I was able to get any sort of record of a logout was when adding 
"USER_Exit" to /etc/security/audit/config.  I'm still not convinced that that 
is proper field.  Even if it is, then what does USER_Logout do?  It may be the 
"logout" command, which if called from any remote connection, fails since its 
not "on the login terminal."   Of course I get no response from IBM.
I did notice an entry for rlogind/telnetd in /etc/security/audit/events.  
Perhaps there is some API that be used for ssh?  Is this something that could 
be added?

-Ryan






 
____________________________________________________________________________________
Do you Yahoo!?
Everyone is raving about the all-new Yahoo! Mail beta.
http://new.mail.yahoo.com
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

<Prev in Thread] Current Thread [Next in Thread>