OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: [suse-security] syslog.conf and tcpd?
From: John Ritchie (ritchiejsnakepit.ritchie.peak.org)
Date: Tue Apr 11 2000 - 15:29:32 CDT


On Tue, 11 Apr 2000, Steven T. Hatton wrote:

> Does anybody know how to configure syslog.conf to record all accesses
> using, for example, rexec?
>
> TIA,
>
> Steve

If we knew which facility and severity the SuSE-supplied version of tcpd
was using for syslog then it would be pretty easy to configure
syslog.conf. If you build tcpd from source the default (v7.6 anyway) is
mail.info but I'm pretty sure SuSE isn't using that. Is it documented
anywhere in SuSE 6.3? My RedHat 5.2 seems to be using the authpriv
facility (which makes more sense to me than "mail") but I'm not sure which
severity.

Does anyone know what syslog facility and severity the SuSE 6.3 tcpd is
logging to? Otherwise we're left doing trial and error with syslog to
find out.

John Ritchie

---------------------------------------------------------------------
To unsubscribe, e-mail: suse-security-unsubscribesuse.com
For additional commands, e-mail: suse-security-helpsuse.com