Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
AlexeyD
Explorer

TTY auditing

Hello, everyone!

Does anybody successfully configured audit-daemon at CP with module `pam_tty_audit.so`? The module`pam_tty_audit.so` doesn't exist in a standard package of CP but it exists in standard CentOS and RHEL editions.
I want to log and audit all characters passed into the console\tty from expert and clish shells. Existed audit methods in clish are not satisfied with me. Maybe someone knows the best decision for this task?

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

If you want support for pam_tty_audit.so, an RFE will likely be required.
Specific commands entered via clish and expert shell can be logged, but not “all characters passed.”

0 Kudos
AlexeyD
Explorer

Existing audit methods (clish and expert-mode) don't log all passed commands. There are many flows that can give you unlogged command execution. The same fault may be caused if you try to log commands with profile's *.rc files. I think that the only proper solution is audit with the pam-module, isn't it? 

0 Kudos
PhoneBoy
Admin
Admin

Don’t know enough about how pam_tty_audit.so works to comment.
That said, an RFE would be needed.
You may also want to engage your local Check Point office with your precise requirements.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events