[Pkg-shadow-devel] Bug#190215: Bug probably no more relevant

Reinhard Müller Reinhard Müller <reinhard.mueller@bytewise.at>, 190215@bugs.debian.org
Tue, 24 May 2005 22:18:18 +0200

Content-Type: text/plain
Content-Transfer-Encoding: quoted-printable

Am Dienstag, den 24.05.2005, 18:59 +0200 schrieb Christian Perrier:
> In Debian bug #190215, you mention:
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
> login logs a message to syslog (with severity LOG_NOTICE) when a
> successful root login occures.
> This is a very good feature, and I think su should do the same.
> =3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=
> As su and login now use PAM, su to root triggers the following entry
> in logs (auth.log actually):
> May 24 18:54:41 mykerinos su[21364]: (pam_unix) authentication failure; l=
ogname=3D uid=3D7426 euid=3D0 tty=3Dpts/10 ruser=3Dbubulle rhost=3D  user=
> May 24 18:54:43 mykerinos su[21364]: pam_authenticate: Authenticationfail=
> May 24 18:54:43 mykerinos su[21364]: - pts/10 bubulle:root
> May 24 18:54:47 mykerinos su[21365]: + pts/10 bubulle:root
> May 24 18:54:47 mykerinos su[21365]: (pam_unix) session opened for user r=
oot by (uid=3D7426)
> The first is an unsuccessful attempt, the latter a successful attempt.
> I think this is enough information and hence I propose closing this
> bug report.

It's not exactly what I was after.

The pam log messages are of priority LOG_INFO and are generated
regardless of the user that logs in. The login program issues an
additional log message with (higher) priority LOG_NOTICE for root
logins. I think this makes sense, because somebody logging in as root is
always a more "interesting" event than somebody logging in with a
"normal" user name, and this justifies (IMHO) a log message with higher

It seems that not many people divide their logs by priority, but I, for
example, do :-)


Content-Type: application/pgp-signature; name=signature.asc
Content-Description: Dies ist ein digital signierter Nachrichtenteil

Version: GnuPG v1.4.1 (GNU/Linux)

