OpenVista needs to log programmer mode access

Bug #322988 reported by Jon Tai
2
Affects Status Importance Assigned to Milestone
OpenVista/GT.M Integration
Status tracked in Mainline
Mainline
Invalid
Medium
Unassigned

Bug Description

Every time a user drops into programmer mode (or attempts to drop into programmer mode), OpenVista should to log the access to a log file. There are two entry points to "programmer mode" - the first is at PRGMODE^%ZOSV, and the second is when "mumps -dir" is invoked on the Linux command line. Each log entry should contain the date, the real Linux user, the Linux account used for authentication (if the programmer is using a tied account), the remote IP address, and optionally, an error indicating why authentication failed. Also see bug 322986.

The log file should be append-only, i.e., programmers should not be able to edit the log file. A facility such as syslog may be able to provide an append-only log mechanism. Note that this will not guarantee the log file's integrity - users with programmer mode and/or Linux shell access will be able to submit false entries to the logger and/or bypass/disable the logging mechansim.

Jon Tai (jontai)
description: updated
description: updated
Revision history for this message
jeff.apple (jeff-apple) wrote :

Jon - are we still concerned about logging "mumps -dir"? If not, we can close this as a duplicate of bug 322986, correct?

Revision history for this message
Jon Tai (jontai) wrote :

When I mentioned "mumps -dir", I meant the script that would eventually call "mumps -dir", which has since been implemented - it's the openvista script. And that script logs, so yes, I think we can close this as a dupe.

I just realized I filed both bugs. Oops.

Revision history for this message
Jon Tai (jontai) wrote :

Huh, Launchpad doesn't seem to have a duplicate status. Oh well... this is being closed as a duplicate of bug #322986

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.