BSM on 2.5.1 not working

Post by Bob Tann » Sat, 18 Jul 1998 04:00:00

I recently activated BSM on a Sparc5 running Solaris 2.5.1. Running
the audit files through praudit I am getting very weird results.

header,102,2,execve(2),,Thu Jul 16 23:24:32 1998, + 355502906 msec
subject,-2,root,other,root,other,357,0,0 0

I am not sure that -2 is coming from, or why it is there. I would
like to use BSM to track illegal root transitions. I am following the
article in Sys Admin, August Issue. pg 29.

1. How does Solaris BSM aduit work?

I am using Solaris 2.5 on a Sparc-5, and I have the BSM audit turned on.

The audit function works as the document says until I find the

Telnet sessions that went in through kerberos telnetd were not audited,
but telnet through Solaris telnetd is audited. Run su from a kerberos
telnet shell, the commands issued in the subsequent shell forked out
from su get auditing.

I assume that kerberos did not set the audit user id, "setauid()" that
results this problem. I changed the login.krb5 login program of kerberos

and patched it to call setauid() to set the audit user id to login user
id before set the real user id. Yet login session through kerberos
telnet still not audited.

Anyone can enlight me on this?


Fu Ming

