Re: root shell auditing

Tim Brown <[email protected]> Tue, 29 Jul 2008 10:07:32 +0100
Newsgroups gmane.comp.security.linux
Message-ID <[email protected]>
On Monday 28 July 2008 14:34:12 Mars Gobetti wrote:
> In an effort to comply with iso 27001, Webtrust and other security
> certifications I need to audit root shell usage on many linux servers:
> every bash command entered in the shell ,with timestamps, and possibly
> logging to a remote server. Which is the best (enterprise class) way to do
> that?
>
> Currently in our environment administrators get root shell access using
> sudo -i. Do I need to change this? I've seen around sudosh (wich do the job
> locally), then Enterprise Audit Shell, but it seems to me this projects are
> not active any more. Will Free IPA be an answer?
>
> Thank you,
>
> Mars Gobetti

I've deployed eTrust AC on large Unix estates for this purpose.  Like sudo but 
rules are enforced at the kernel level.  Auditing can be applied to many 
object classes including files, services, privileges etc.   Combine it with 
eTrust Audit and you can aggregate logs and perform correlation etc.  It is 
however quite expensive.

Cheers,
Tim
-- 
Tim Brown
<mailto:[email protected]>