Your message dated Mon, 7 Jul 2008 19:55:03 +0200
with message-id <[EMAIL PROTECTED]>
and subject line Re: Bug#444470: 
/etc/logcheck/violations.ignore.d/logcheck-ssh: Updated "authentication 
failure" rule
has caused the Debian Bug report #444470,
regarding /etc/logcheck/violations.ignore.d/logcheck-ssh: Updated 
"authentication failure" rule
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
444470: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=444470
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: logcheck-database
Version: 1.2.62
Severity: normal
File: /etc/logcheck/violations.ignore.d/logcheck-ssh

Here's an updated version of the ssh/pam_unix "authentication failure"
rule:

  ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ sshd\[[[:digit:]]+\]: 
pam_unix\(ssh:[[:alnum:]]+\): authentication failure; logname= uid=0 euid=0 
tty=ssh ruser= rhost=[^[:space:]]+([[:space:]]+user=[^[:space:]]+)?$


This reflects the change that occurred in pam_unix in September 2005,
where the logging went from "(pam_unix)" to "pam_unix(ssh:auth)".  This
was already done in the second auth.fail rule, but not in the first,
hence this report.


-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: i386 (i686)

Kernel: Linux 2.6.21-2-k7 (SMP w/1 CPU core)
Locale: LANG=en_CA.utf-8, LC_CTYPE=en_CA.utf-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

-- debconf information excluded



--- End Message ---
--- Begin Message ---
Version: 1.2.64

* Frédéric Brière <[EMAIL PROTECTED]> [2007-09-28 23:18:33 CEST]:
> Here's an updated version of the ssh/pam_unix "authentication failure"
> rule:
> 
>   ^\w{3} [ :[:digit:]]{11} [._[:alnum:]-]+ sshd\[[[:digit:]]+\]: 
> pam_unix\(ssh:[[:alnum:]]+\): authentication failure; logname= uid=0 euid=0 
> tty=ssh ruser= rhost=[^[:space:]]+([[:space:]]+user=[^[:space:]]+)?$

* Frédéric Brière <[EMAIL PROTECTED]> [2008-03-17 02:02:56 CET]:
> # Commit 037fed5fc268088bad1f17c885d9153ee800ec40
> tag 444470 pending

 That commit was part of the 1.2.64 release - thus closing the bug with
that version.

 So long,
Rhonda


--- End Message ---
_______________________________________________
Logcheck-devel mailing list
[email protected]
http://lists.alioth.debian.org/mailman/listinfo/logcheck-devel

Reply via email to