LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 03-14-2011, 02:48 AM   #1
yitpong
LQ Newbie
 
Registered: Mar 2011
Posts: 3

Rep: Reputation: 0
Kernel audit msg flooding after yum update


selinux and psacct is disabled in this system (RHEL5.6 2.6.18-194.11.3.el5 SMP x86_64).

After performing a yum update, the syslog is flooded with kernel audit messages (related to PAM), even though audit service is turned off.

Is there a way to disable this verbosity?



[ Sample of /var/log/messages ]
Mar 14 14:49:32 svr10 kernel: type=1103 audit(1300085372.192:183805): user pid=24632 uid=0 auid=0 subj=kernel msg='PAM: setcred acct="root" : exe="/usr/sbin/sshd" (hostname=172.16.4.101, addr=172.16.4.101, terminal=ssh res=success)'
Mar 14 14:49:32 svr10 kernel: type=1006 audit(1300085372.200:183806): login pid=24632 uid=0 old auid=0 new auid=0 old ses=27923 new ses=29597
Mar 14 14:49:32 svr10 kernel: type=1105 audit(1300085372.200:183807): user pid=24632 uid=0 auid=0 subj=kernel msg='PAM: session open acct="root" : exe="/usr/sbin/sshd" (hostname=172.16.4.101, addr=172.16.4.101, terminal=ssh res=success)'
Mar 14 14:49:32 svr10 kernel: type=1112 audit(1300085372.204:183808): user pid=24634 uid=0 auid=0 subj=kernel msg='uid=0: exe="/usr/sbin/sshd" (hostname=172.16.4.101, addr=172.16.4.101, terminal=/dev/pts/0 res=success)'
Mar 14 14:49:32 svr10 kernel: type=1110 audit(1300085372.211:183809): user pid=24634 uid=0 auid=0 subj=kernel msg='PAM: setcred acct="root" : exe="/usr/sbin/sshd" (hostname=172.16.4.101, addr=172.16.4.101, terminal=ssh res=success)'
Mar 14 15:01:01 svr10 kernel: type=1006 audit(1300086061.131:183821): login pid=24748 uid=0 old auid=4294967295 new auid=0 old ses=4294967295 new ses=29600
Mar 14 15:01:01 svr10 kernel: type=1105 audit(1300086061.136:183822): user pid=24747 uid=0 auid=0 subj=kernel msg='PAM: session open acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)'
Mar 14 15:01:01 svr10 kernel: type=1105 audit(1300086061.138:183823): user pid=24748 uid=0 auid=0 subj=kernel msg='PAM: session open acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)'
Mar 14 15:01:01 svr10 kernel: type=1104 audit(1300086061.149:183824): user pid=24747 uid=0 auid=0 subj=kernel msg='PAM: setcred acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)'
Mar 14 15:01:01 svr10 kernel: type=1106 audit(1300086061.150:183825): user pid=24747 uid=0 auid=0 subj=kernel msg='PAM: session close acct="root" : exe="/usr/sbin/crond" (hostname=?, addr=?, terminal=cron res=success)'
 
Old 03-14-2011, 04:32 AM   #2
corp769
LQ Guru
 
Registered: Apr 2005
Location: /dev/null
Posts: 5,818

Rep: Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007Reputation: 1007
If you can, go through your /var/log/messages and post the packages that you updated prior to getting these messages, it will assist in troubleshooting.

Josh
 
Old 03-14-2011, 09:07 AM   #3
yitpong
LQ Newbie
 
Registered: Mar 2011
Posts: 3

Original Poster
Rep: Reputation: 0
I found the solution!

http://www.vickysguide.com/audit-sti...en-when-stoped
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
yum update everything but kernel exigent Red Hat 15 02-27-2014 07:52 PM
How can I read the audit time stamp? msg=audit(1213186256.105:20663) abefroman Linux - Software 3 04-21-2011 06:37 PM
Yum update stopped responding during kernel update install, now server load is high pulsorock Linux - Kernel 1 12-31-2008 01:55 AM
[SOLVED] yum update kernel unkie888 Linux - Software 3 08-02-2007 02:23 PM
Can yum update your kernel version.? wpg9210 Fedora 1 03-21-2006 10:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 07:16 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration