[Q] BSM audit_user file

From:
Date: 10/31/02


Date: 30 Oct 2002 18:08:54 -0800

During setting up BSM in Solaris8 on Ultra10 workstation, I met a problem.
I willing to audit all users including root and not to audit at all
about user "foo". I set up audit_control and audit_user like
following.

1. audit_control
flags:lo,ad,-all,^-fc

2. audit_user
foo::all

When user logins as "foo", no audit is generated. But, When he switchs to
root using "su", the problem happen. After he become root, BSM audit is
generated. I hope no audit is generated even after "su".

So, I have some question.
1. What does "username" in audit_user file mean? audit ID or effective
user ID?
2. How can I solve this problem?

Hope advice.
Thanks in advance,
Chun-Mok Chung



Relevant Pages

  • Re: login as root vs su root
    ... There's something to be said for permitting local logins by root, ... and vastly outweighed by the audit ... It's theoretically possible that under some bizarre circumstances a login as ... without resorting to a direct login as root. ...
    (AIX-L)
  • Re: [PATCH] Audit: Add TTY input auditing
    ... Implement automated audit trails for all system components to reconstruct the ... All actions taken by any individual with root or administrative privileges ... an administration user interface facility as the admin shell. ... Which can be done by auditing for execution of specific apps or watching ...
    (Linux-Kernel)
  • Re: Auditing the windows registry
    ... > I can audit any of the Root Keys execpt for HKEY CLASSES ...
    (microsoft.public.win2000.security)
  • Re: Auditing Windows XP Registry
    ... > I can audit any of the Root Keys execpt for HKEY CLASSES ...
    (microsoft.public.windowsxp.security_admin)
  • Auditing Windows XP Registry
    ... I can audit any of the Root Keys execpt for HKEY CLASSES ... ker is greyed out? ...
    (microsoft.public.windowsxp.security_admin)