https://bugzilla.novell.com/show_bug.cgi?id=298909 Summary: auditd not working. Product: openSUSE 10.2 Version: Final Platform: x86-64 OS/Version: openSUSE 10.2 Status: NEW Severity: Major Priority: P5 - None Component: Security AssignedTo: security-team@suse.de ReportedBy: ep1admin@physik.uni-wuerzburg.de QAContact: qa@suse.de Found By: --- I'm having some trouble with pam_mount. so to figure out why some error messages show up in /var/log/messages (pmvarrun not being able to chown some dir) I tried to use auditing with auditd to determine the uid of pmvarrun at that time. I've tried to set some auditing rules according to this: http://www.cyberciti.biz/tips/howto-log-user-activity-using-process-accounti... example: - modify /etc/sysconfig/auditd to do syscall auditing, run SuSEconfig, restart auditd - "auditctl -w /etc/passwd -p war -k passwd-file" - use some ordinary user to mess with /etc/passwd which fails of course - "ausearch -k passwd-file" with opensuse10.2 no audit messages get created at all ! (all updates as of 2007-08-89) the very same example works as intended on SLES10-SP1. -- Configure bugmail: https://bugzilla.novell.com/userprefs.cgi?tab=email ------- You are receiving this mail because: ------- You are on the CC list for the bug.