How does Solaris BSM aduit work?

How does Solaris BSM aduit work?

Post by Fu Min » Sun, 22 Mar 1998 04:00:00



I am using Solaris 2.5 on a Sparc-5, and I have the BSM audit turned on.

The audit function works as the document says until I find the
following:

Telnet sessions that went in through kerberos telnetd were not audited,
but telnet through Solaris telnetd is audited. Run su from a kerberos
telnet shell, the commands issued in the subsequent shell forked out
from su get auditing.

I assume that kerberos did not set the audit user id, "setauid()" that
results this problem. I changed the login.krb5 login program of kerberos

and patched it to call setauid() to set the audit user id to login user
id before set the real user id. Yet login session through kerberos
telnet still not audited.

Anyone can enlight me on this?

Thanks

Fu Ming

 
 
 

1. How does Solaris BSM audit work?

I am using Solaris 2.5 on a Sparc-5, and I have the BSM audit turned on.
The audit function works as the document says until I find the
following:

Telnet sessions that went in through kerberos telnetd were not audited,
but telnet through Solaris telnetd is audited. Run su from a kerberos
telnet shell, the commands issued in the subsequent shell forked out
from su get auditing.

I assume that kerberos did not set the audit user id, "setauid()" that
results this problem. I changed the login.krb5 login program of kerberos
and patched it to call setauid() to set the audit user id to login user
id before set the real user id. Yet login session through kerberos
telnet still not audited.

Anyone can enlight me on this?

Thanks

Fu Ming

2. **** Mosaic on SOLARIS 2.1 ? ****

3. BSM on 2.5.1 not working

4. question: Unix commands for splitting a file

5. BSM, Solaris 8 and auditing changes to /etc/shadow

6. Hitting modem from script

7. BSM on Solaris 8 Generic_108528-05

8. Need help with SCSI

9. Thoughts on Solaris BSM Auditing

10. Auditing printing using Solaris BSM.

11. q: solaris bsm and triteal gui

12. BSM Solaris - question of return value

13. q: solaris bsm and triteal desktop