Skip to content

logging root authorized_keys file manipulation #152

@borross

Description

@borross

for correct logging add pls under the section ## root ssh key tampering such value
-w /root/.ssh/authorized_keys -p wa -k rootkey

Commands for check:

ssh-keygen -t rsa -f test_key
cat test_key.pub >> /root/.ssh/authorized_keys

Log sample:

type=PATH msg=audit(1723720092.480:12186438): item=0 name="/root/.ssh/authorized_keys" nametype=UNKNOWN cap_fp=0 cap_fi=0 cap_fe=0 cap_fver=0 cap_frootid=0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions