Enable logging of all commands run by the libravatar-master user

Bug #1281072 reported by François Marier on 2014-02-17
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Libravatar
Medium
Unassigned

Bug Description

The libravatar-master user should only ever run the rsync command on the master. It's enforced by the shell (rssh) that is set, but it should also be logged in case rssh fails.

All that's needed is to add the following to /etc/pam.d/sshd:

  session required pam_tty_audit.so enable=libravatar-master

Unfortunately pam_tty_audit is not shipped with wheezy.

Source: http://beardyjay.co.uk/logging-all-ssh-commands/logging-ssh

description: updated
tags: added: security
tags: added: rsync
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers