pam_tty_audit and non privileged users

Posted by Jeff on Server Fault See other posts from Server Fault or by Jeff
Published on 2012-08-31T20:13:59Z Indexed on 2012/08/31 21:39 UTC
Read the original article Hit count: 224

Filed under:
|
|
|

I'm working on a cents 6.3 box and am trying to log all commands executed from a bash shell and came across pam_tty_audit. I've added the appropriate line to my /etc/pam.d/system-auth file: "session required pam_tty_audit.so enable=*"

The problem is that it does not appear to capture commands unless a user is root. For example, if i ssh in as root it logs everything to the audit log, but if I ssh as a regular user it does not start logging anything until after I have su to root.

Any ideas?

© Server Fault or respective owner

Related posts about centos

Related posts about pam