root shell auditing
"Mars Gobetti" <[email protected]> Mon, 28 Jul 2008 14:34:12 +0100
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Message-ID | <[email protected]> |
In an effort to comply with iso 27001, Webtrust and other security certif= ications I need to audit root shell usage on many linux servers: every ba= sh command entered in the shell ,with timestamps, and possibly logging to= a remote server. Which is the best (enterprise class) way to do that? Currently in our environment administrators get root shell access using s= udo -i. Do I need to change this? I've seen around sudosh (wich do the job locally), then Enterprise Audit = Shell, but it seems to me this projects are not active any more. Will Free IPA be an answer? Thank you, Mars Gobetti