LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 08-20-2018, 01:19 PM   #1
chrisr710
LQ Newbie
 
Registered: Aug 2018
Posts: 5

Rep: Reputation: Disabled
Aureport shows changes to accounts, groups, or roles, when there are none


Hello:
I am working on setting up auditing on a Debian 8 64 bit system. I have left the computer running for several days.

When I run aureport against the local audit logs, the computer consistently reports "changes to accounts, groups or roles", when there shouldn't be any.

if I search for the events (aureport -m) and look at what is triggering these reported "changes in accounts" I see events like this that happen in the middle of the night:

type=USER_CHAUTHTOK msg=audit(1534662002.939:44423): pid=30145 uid=0 auid=0 ses=1913 msg='op=display aging info id=0 exe="/usr/bin/chage" hostname=? addr=? terminal=? res=success'

Can anyone help explain to me what these audited events actually are, and if they are not significant security events (such as a user changing groups, or being deleted, etc), is there a way to filter them out? I would prefer it if aureport wouldn't alarm the user for something that is not of any considerable security significance.

**upate**
TIGER Cron jobs were checking the status of passwords using /usr/bin/chage -l. This is not altering an account; it's just a status inquiry. Bug was reported and fixed here https://www.redhat.com/archives/linu.../msg00123.html for redhat by updating passwd. Don't believe there is an update for Debian. Don't believe it is possible to filter this out without filtering out too much.

Thanks!

Last edited by chrisr710; 08-20-2018 at 09:53 PM.
 
Old 08-25-2018, 07:16 AM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Thanks for reporting that bug!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Does Linux have server roles and service accounts too? JockVSJock Linux - Newbie 1 04-26-2015 09:14 PM
Roles with administrative functions as groups... dksellou Linux - Newbie 5 11-04-2013 06:35 PM
user accounts and groups setup is_numeric Linux - Newbie 2 10-26-2009 12:43 PM
User Accounts and Groups in Linux dheroan Linux - Newbie 4 07-30-2006 10:02 PM
Backing up user accounts and groups. thekillerbean Linux - Newbie 1 12-25-2005 08:44 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:06 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration