Enable logging of all commands run by the libravatar-master user

Bug #1281072 reported by François Marier
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Libravatar (obsolete)
Confirmed
Medium
Unassigned

Bug Description

The libravatar-master user should only ever run the rsync command on the master. It's enforced by the shell (rssh) that is set, but it should also be logged in case rssh fails.

All that's needed is to add the following to /etc/pam.d/sshd:

  session required pam_tty_audit.so enable=libravatar-master

Unfortunately pam_tty_audit is not shipped with wheezy.

Source: http://beardyjay.co.uk/logging-all-ssh-commands/logging-ssh

description: updated
tags: added: security
tags: added: rsync
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.