Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #192664

Re: SSH session audit

From Eero Volotinen <eero.volotinen@iki.fi>
Newsgroups linux.debian.user
Subject Re: SSH session audit
Date 2018-02-19 14:50 +0100
Message-ID <vkTZn-3DR-3@gated-at.bofh.it> (permalink)
References <vkTmG-3qb-15@gated-at.bofh.it> <vkTwm-3uw-13@gated-at.bofh.it> <vkTPH-3AI-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing

pam audit might work, test it :)

--
Eero

On Mon, Feb 19, 2018 at 3:29 PM, <me@risca.eu> wrote:

> On 2018-02-19 14:11, Eero Volotinen wrote:
>
>> Commercial solution: https://www.ssh.com/products/cryptoauditor/
>>
>
> Thanks for the option and sorry if I hadn't specified in my previous:
> commercial solution are against the TOS of the project. We have the
> requirement, commitment and wish to be 100% free-software.
>
> On 2018-02-19 14:22, Steve Kemp wrote:
>
>> Do you know about that solution? Or could you suggest something similar?
>>>
>>   You could install "snoopy", which will log all command-executed to
>>  syslog.  Then configure your syslog to forward logs to a remote host.
>>   It is not fool-proof, but requires no setup for a user..
>>
>
> Nice to know. It could be improved by moving the logs outside but would
> required additional work (and who will be the one in charge of managing
> it?). I had a quick view of it but probably it has problem with interactive
> programs like editors (I think you'd get only a "vim file.txt").
>
> Anyway, I also remember about the post that I read, that was such a clever
> and easy solution to feel like the obvious way of doing it. It was easy to
> run and very reliable thanks to asymmetric encryption via gpg.
>

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

SSH session audit me@risca.eu - 2018-02-19 14:10 +0100
  Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 14:20 +0100
    Re: SSH session audit me@risca.eu - 2018-02-19 14:40 +0100
      Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 14:50 +0100
  Re: SSH session audit Steve Kemp <steve@steve.org.uk> - 2018-02-19 14:50 +0100
  Re: SSH session audit john doe <johndoe65534@mail.com> - 2018-02-19 17:00 +0100
    Re: SSH session audit me@risca.eu - 2018-02-19 17:30 +0100
      Re: SSH session audit Eero Volotinen <eero.volotinen@iki.fi> - 2018-02-19 17:40 +0100
      Re: SSH session audit Roberto C. Sánchez <roberto@debian.org> - 2018-02-19 17:40 +0100
  Re: SSH session audit David Christensen <dpchrist@holgerdanske.com> - 2018-02-19 22:40 +0100

csiph-web