Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Explorer

TTY auditing

Hello, everyone!

Does anybody successfully configured audit-daemon at CP with module `pam_tty_audit.so`? The module`pam_tty_audit.so` doesn't exist in a standard package of CP but it exists in standard CentOS and RHEL editions.
I want to log and audit all characters passed into the console\tty from expert and clish shells. Existed audit methods in clish are not satisfied with me. Maybe someone knows the best decision for this task?

Tags (4)
0 Kudos
Reply
3 Replies
Highlighted
Admin
Admin

If you want support for pam_tty_audit.so, an RFE will likely be required.
Specific commands entered via clish and expert shell can be logged, but not “all characters passed.”

0 Kudos
Reply
Highlighted
Explorer

Existing audit methods (clish and expert-mode) don't log all passed commands. There are many flows that can give you unlogged command execution. The same fault may be caused if you try to log commands with profile's *.rc files. I think that the only proper solution is audit with the pam-module, isn't it? 

0 Kudos
Reply
Highlighted
Admin
Admin

Don’t know enough about how pam_tty_audit.so works to comment.
That said, an RFE would be needed.
You may also want to engage your local Check Point office with your precise requirements.

0 Kudos
Reply