Re: PCI-DSS: Log every root actions/keystrokes but avoid passwords

2013-03-13 Thread Richard Guy Briggs
On Tue, Mar 12, 2013 at 05:09:15PM -0400, Steve Grubb wrote: On Tuesday, March 12, 2013 04:47:42 PM Richard Guy Briggs wrote: On Tue, Mar 12, 2013 at 07:06:59AM -0400, Miloslav Trmac wrote: - Original Message - I am resurrecting this old thread from last summer because I ran

Re: PCI-DSS: Log every root actions/keystrokes but avoid passwords

2013-03-13 Thread Steve Grubb
On Wednesday, March 13, 2013 10:55:29 AM Richard Guy Briggs wrote: On Tue, Mar 12, 2013 at 05:09:15PM -0400, Steve Grubb wrote: On Tuesday, March 12, 2013 04:47:42 PM Richard Guy Briggs wrote: On Tue, Mar 12, 2013 at 07:06:59AM -0400, Miloslav Trmac wrote: - Original Message -

Re: PCI-DSS: Log every root actions/keystrokes but avoid passwords

2013-03-13 Thread Miloslav Trmac
- Original Message - Please do post the patch here when you have it worked out as I am very likely to miss it in the flood of kernel patches when it goes to/from Linus. Here you go. Given Steve's good question, this control method may change. Isn't icanon _true_ when the data

Re: PCI-DSS: Log every root actions/keystrokes but avoid passwords

2013-03-13 Thread Richard Guy Briggs
On Wed, Mar 13, 2013 at 12:43:58PM -0400, Miloslav Trmac wrote: - Original Message - Please do post the patch here when you have it worked out as I am very likely to miss it in the flood of kernel patches when it goes to/from Linus. Here you go. Given Steve's good

Re: PCI-DSS: Log every root actions/keystrokes but avoid passwords

2013-03-13 Thread Miloslav Trmac
- Original Message - On Wed, Mar 13, 2013 at 12:43:58PM -0400, Miloslav Trmac wrote: - Original Message - Please do post the patch here when you have it worked out as I am very likely to miss it in the flood of kernel patches when it goes to/from Linus.

Re: PCI-DSS: Log every root actions/keystrokes but avoid passwords

2013-03-13 Thread Tracy Reed
On Wed, Mar 13, 2013 at 07:55:29AM PDT, Richard Guy Briggs spake thusly: I haven't seen a lot of requests for this feature yet, but it sounds like there could be a lot of interest, so it may be worth doing correctly, rather than as a quick fix. As people become more security-aware and