Date: Sun, 10 Mar 2002 16:15:43 -0500 (EST) From: Robert Watson <rwatson@FreeBSD.org> To: Dag-Erling Smorgrav <des@ofug.org> Cc: cvs-committers@FreeBSD.org, cvs-all@FreeBSD.org Subject: Re: cvs commit: src/etc syslog.conf Message-ID: <Pine.NEB.3.96L.1020310161059.61696Z-100000@fledge.watson.org> In-Reply-To: <xzpelis88z7.fsf@flood.ping.uio.no>
next in thread | previous in thread | raw e-mail | index | archive | help
On 10 Mar 2002, Dag-Erling Smorgrav wrote:
> Robert Watson <rwatson@FreeBSD.org> writes:
> > Log:
> > /var/log/security gets almost no (if not no) activity on many FreeBSD
> > systems due to sshd not using the security log class.
>
> This can be arranged...
And probably should be. I don't have time to sit down and check to make
sure the right facility is used all over the place, but it might be a good
idea for someone to do so. There seem to be at least three relevant
facilities for this kind of thing (from syslog manpage):
LOG_AUTH The authorization system: login(1), su(1), getty(8), etc.
LOG_AUTHPRIV The same as LOG_AUTH, but logged to a file readable only by
selected individuals.
LOG_SECURITY Security subsystems, such as ipfw(4).
The current use of AUTH or AUTHPRIV is probably correct for authentication
messages coming from sshd, login, su, etc. Which to select is an
interesting question: in general, we haven't been using authpriv, I think.
SECURITY probably isn't generally appropriate for these mechanisms unless
a problem occurs. However, /var/log/security probably has a different
mandate than the facility of the same name, and potentially could contain
security-relevant messages, which might include authentication messages.
This suggests to me that we continue to use AUTH all over the place, and
redefine /var/log/security to have a broader mandate, and possibly trim
delivery of AUTH/SECURITY/AUTHPRIV from the other logs. I.e., move to:
security.*;auth.*;authpriv.* /var/log/security
Maybe .info instead of .*.
Robert N M Watson FreeBSD Core Team, TrustedBSD Project
robert@fledge.watson.org NAI Labs, Safeport Network Services
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe cvs-all" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.NEB.3.96L.1020310161059.61696Z-100000>
