[Ubuntu 15.04] Ubuntu should audit account modification events

Bug #1414817 reported by bugproxy on 2015-01-26
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
shadow (Ubuntu)
High
Mathieu Trudel-Lapierre

Bug Description

Ubuntu should log user modification events to the system audit trail (/var/log/audit/audit.log) but does not.

Steps to Verify:

- Install Ubuntu 14.04 on an x86_64 VM
- apt install auditd
- useradd testuser
- ausearch -i

Expected Results:

An audit record should be appended to the audit trail that indicates testuser was added.

Actual Results:

An appropriate audit event was not appended to the audit trail. A record is logged in /var/log/auth.log.

Discussion:

Auditable system events should be logged in the standard audit trail via the Linux audit subsystem. Doing so provides a central location where sysadmins can monitor security events. The Linux audit subsystem can be used to meet Common Criteria and compliance hardening standards requirements. OSPP v2.0 [https://www.commoncriteriaportal.org/files/ppfiles/pp0067b_pdf.pdf] should provide a good reference for commonly logged audit events and other audit requirements.

Related branches

bugproxy (bugproxy) on 2015-01-26
tags: added: architecture-all bugnameltc-120769 severity-high targetmilestone-inin1504
Luciano Chavez (lnx1138) on 2015-01-26
affects: ubuntu → audit (Ubuntu)
Changed in audit (Ubuntu):
assignee: nobody → Taco Screen team (taco-screen-team)
bugproxy (bugproxy) on 2015-03-24
tags: added: targetmilestone-inin1510
removed: targetmilestone-inin1504
Steve Langasek (vorlon) on 2015-05-28
Changed in audit (Ubuntu):
importance: Undecided → High
assignee: Taco Screen team (taco-screen-team) → Mathieu Trudel-Lapierre (mathieu-tl)

Looks like this is in fact an issue with shadow, which has its audit support disabled.

affects: audit (Ubuntu) → shadow (Ubuntu)
Changed in shadow (Ubuntu):
status: New → In Progress
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package shadow - 1:4.1.5.1-1.1ubuntu5

---------------
shadow (1:4.1.5.1-1.1ubuntu5) wily; urgency=medium

  * debian/rules: Re-enable audit support. (LP: #1414817)
  * debian/control: add libaudit-dev to Build-Depends.

 -- Mathieu Trudel-Lapierre <email address hidden> Tue, 02 Jun 2015 10:46:18 -0400

Changed in shadow (Ubuntu):
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Other bug subscribers