Hi Piotr,
On Tue, Jun 29, 2010 at 04:07:12PM +0200, Piotr Jasiukajtis wrote:
> Hi,
>
> I have found that auditd in default configuration does not store user
> IDs in the logs if the account is LDAP based.
>
> praudit says only:
> header,32,2,su,,server,2010-06-29 15:56:24.284 +02:00,return,success,0
>
> In case of local users it says:
> ,subject,estibi,root,root,root,root,8416,1677303986,6456 71168
> 10.1.1.10,return,success,0
Please, on which OS build you see the incorrect behaviour? Have
you filed a bug already? What's the CR?
Also, please, can you resend the complete audit record for the
latter case? I can see just the subject, not the header. Was
that su(1M) as well?
Thanks,
/j.
_______________________________________________
security-discuss mailing list
[email protected]