Enable logging of all commands run by the libravatar-master user
Bug #1281072 reported by
François Marier
This bug affects 1 person
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Libravatar (obsolete) |
Confirmed
|
Medium
|
Unassigned |
Bug Description
The libravatar-master user should only ever run the rsync command on the master. It's enforced by the shell (rssh) that is set, but it should also be logged in case rssh fails.
All that's needed is to add the following to /etc/pam.d/sshd:
session required pam_tty_audit.so enable=
Unfortunately pam_tty_audit is not shipped with wheezy.
Source: http://