Re: SSH session audit

2018-02-19 Thread David Christensen
On 02/19/18 04:51, m...@risca.eu wrote: Hi, I'm co-managing a server with a friend of mine offering ourself some basic service (like emails, file sharing, etc). At this time each of us can freely login on the server via ssh (we trust each others) for the daily administrative tasks. I would lik

Re: SSH session audit

2018-02-19 Thread Eero Volotinen
Well. It's normal way to stream logs to centralized log server via rsyslog or ossec.. Eero 19.2.2018 18.25 kirjoitti: > On 2018-02-19 16:52, john doe wrote: > >> Isn't pam enough?: >> https://linux.die.net/man/8/pam >> >> No need to install anything and it's quite versatile. >> > > Yes, this is

Re: SSH session audit

2018-02-19 Thread Roberto C . Sánchez
On Mon, Feb 19, 2018 at 05:21:13PM +0100, m...@risca.eu wrote: > On 2018-02-19 16:52, john doe wrote: > > Isn't pam enough?: > > https://linux.die.net/man/8/pam > > > > No need to install anything and it's quite versatile. > > Yes, this is in line with the other suggested options such as snoopy o

Re: SSH session audit

2018-02-19 Thread me
On 2018-02-19 16:52, john doe wrote: Isn't pam enough?: https://linux.die.net/man/8/pam No need to install anything and it's quite versatile. Yes, this is in line with the other suggested options such as snoopy or pam_tty_audit. It could work as audit system, but it seems to me as a solution

Re: SSH session audit

2018-02-19 Thread john doe
On 2/19/2018 1:51 PM, m...@risca.eu wrote: Hi, I'm co-managing a server with a friend of mine offering ourself some basic service (like emails, file sharing, etc). At this time each of us can freely login on the server via ssh (we trust each others) for the daily administrative tasks. I wou

Re: SSH session audit

2018-02-19 Thread Steve Kemp
> Do you know about that solution? Or could you suggest something similar? You could install "snoopy", which will log all command-executed to syslog. Then configure your syslog to forward logs to a remote host. It is not fool-proof, but requires no setup for a user.. Steve -- https://www.

Re: SSH session audit

2018-02-19 Thread Eero Volotinen
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/security_guide/sec-configuring_pam_for_auditing pam audit might work, test it :) -- Eero On Mon, Feb 19, 2018 at 3:29 PM, wrote: > On 2018-02-19 14:11, Eero Volotinen wrote: > >> Commercial solution: https://www.ssh.

Re: SSH session audit

2018-02-19 Thread me
On 2018-02-19 14:11, Eero Volotinen wrote: Commercial solution: https://www.ssh.com/products/cryptoauditor/ Thanks for the option and sorry if I hadn't specified in my previous: commercial solution are against the TOS of the project. We have the requirement, commitment and wish to be 100% fre

Re: SSH session audit

2018-02-19 Thread Eero Volotinen
Commercial solution: https://www.ssh.com/products/cryptoauditor/ Eero On Mon, Feb 19, 2018 at 2:51 PM, wrote: > Hi, > > I'm co-managing a server with a friend of mine offering ourself some basic > service (like emails, file sharing, etc). At this time each of us can > freely login on the server