On Thursday, July 8, 2021 6:53:12 PM EDT warron.french wrote: > Please, can you tell me what audit rule you are using that generates such > records about root's (*or any other account's) password change?*
In this case its hardwired into pam. -Stev -- Linux-audit mailing list [email protected] https://listman.redhat.com/mailman/listinfo/linux-audit
