Hi Piotr,

On Tue, Jun 29, 2010 at 04:07:12PM +0200, Piotr Jasiukajtis wrote:
> Hi,
> 
> I have found that auditd in default configuration does not store user
> IDs in the logs if the account is LDAP based.
> 
> praudit says only:
> header,32,2,su,,server,2010-06-29 15:56:24.284 +02:00,return,success,0
> 
> In case of local users it says:
> ,subject,estibi,root,root,root,root,8416,1677303986,6456 71168
> 10.1.1.10,return,success,0

        Please, on which OS build you see the incorrect behaviour? Have
        you filed a bug already? What's the CR?

        Also, please, can you resend the complete audit record for the
        latter case? I can see just the subject, not the header. Was
        that su(1M) as well?

        Thanks,

        /j.

_______________________________________________
security-discuss mailing list
[email protected]

Reply via email to