Question about Solaris BSM and Auditd

Question about Solaris BSM and Auditd

Post by Fu Min » Tue, 17 Feb 1998 04:00:00



I am running Solaris 2.5 on a sparc-5.

I find the following problem when I run MIT kerberos telnetd and Solaris
BSM audit, the basic security module.

The auditd does not log info of any event of remote sessions connected
through the kerberos telnetd. At the same time, auditd works fine in
logging events of local login sessions and remote connection through
rlogind. If inside a remote login session through the kerberos telnetd,
I run su to root, then all events initiated from the root shell were
logged.

Change the telnetd back to the default Solarsi version correct the
problem.

I was wondering where does the auditd get execution event information, I
guess it shuold come from the Solaris kernel, this should not be related
to a user level application like telnetd, am I right?

Any help is appreciated.

Fu Ming

 
 
 

Question about Solaris BSM and Auditd

Post by Casper H.S. Dik - Network Security Engine » Tue, 17 Feb 1998 04:00:00


[[ PLEASE DON'T SEND ME EMAIL COPIES OF POSTINGS ]]


>I was wondering where does the auditd get execution event information, I
>guess it shuold come from the Solaris kernel, this should not be related
>to a user level application like telnetd, am I right?

Not quite; the telnetd application has hooks to enable the kernel audit
data.

Casper
--
Expressed in this posting are my opinions.  They are in no way related
to opinions held by my employer, Sun Microsystems.
Statements on Sun products included here are not gospel and may
be fiction rather than truth.

 
 
 

1. Log file for BSM (auditd)

Hi all,

- I enabled BSM by runing the script /etc/security/bsmconv
- The file /etc/system is updated. I reboot the server.
- The process auditd is started at boot.

Now, i have binary file in directory :
/var/audit/20050309114754.not_terminated.MyServer

Can you tell me how can i read this file ?
Where process auditd log data (/var/adm/messages... ?)

Does BSM consume lot of Memory/CPU ?

ThankYou very much for your help
NS

2. PROBLEM 2

3. BSM Solaris - question of return value

4. Samba and CCC

5. Solaris 2.5.1 and auditd

6. KDE Error

7. auditd question?

8. Newbie boot question - GNOME

9. QUESTION: auditd setup

10. Matrox Mystique ands X.

11. How does Solaris BSM aduit work?

12. BSM, Solaris 8 and auditing changes to /etc/shadow

13. BSM on Solaris 8 Generic_108528-05