pam_tty_audit and non privileged users
Posted
by
Jeff
on Server Fault
See other posts from Server Fault
or by Jeff
Published on 2012-08-31T20:13:59Z
Indexed on
2012/08/31
21:39 UTC
Read the original article
Hit count: 224
I'm working on a cents 6.3 box and am trying to log all commands executed from a bash shell and came across pam_tty_audit. I've added the appropriate line to my /etc/pam.d/system-auth file: "session required pam_tty_audit.so enable=*"
The problem is that it does not appear to capture commands unless a user is root. For example, if i ssh in as root it logs everything to the audit log, but if I ssh as a regular user it does not start logging anything until after I have su to root.
Any ideas?
© Server Fault or respective owner