Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #192687
| From | Eero Volotinen <eero.volotinen@iki.fi> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: SSH session audit |
| Date | 2018-02-19 17:40 +0100 |
| Message-ID | <vkWDU-5pu-15@gated-at.bofh.it> (permalink) |
| References | <vkTmG-3qb-15@gated-at.bofh.it> <vkW1b-4U1-3@gated-at.bofh.it> <vkWue-5kM-13@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Well. It's normal way to stream logs to centralized log server via rsyslog or ossec.. Eero 19.2.2018 18.25 <me@risca.eu> kirjoitti: > On 2018-02-19 16:52, john doe wrote: > >> Isn't pam enough?: >> https://linux.die.net/man/8/pam >> >> No need to install anything and it's quite versatile. >> > > Yes, this is in line with the other suggested options such as snoopy or > pam_tty_audit. It could work as audit system, but it seems to me as a > solution for more structured and corporate environment. > In the described case I would like a solution that store record the > session in a safe way, immutable and trustable, therefore encrypting all > (only the owners have to be able to read it) and hosted on a read only > resource (the user who logins should not be able to delete it) and provable > (signed). > I think that with pam there is the risk that a user with full access right > could easily delete all the logs. Or that the log could be altered after. > >
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
SSH session audit me@risca.eu - 2018-02-19 14:10 +0100
Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 14:20 +0100
Re: SSH session audit me@risca.eu - 2018-02-19 14:40 +0100
Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 14:50 +0100
Re: SSH session audit Steve Kemp <steve@steve.org.uk> - 2018-02-19 14:50 +0100
Re: SSH session audit john doe <johndoe65534@mail.com> - 2018-02-19 17:00 +0100
Re: SSH session audit me@risca.eu - 2018-02-19 17:30 +0100
Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 17:40 +0100
Re: SSH session audit Roberto C. Sánchez <roberto@debian.org> - 2018-02-19 17:40 +0100
Re: SSH session audit David Christensen <dpchrist@holgerdanske.com> - 2018-02-19 22:40 +0100
csiph-web